CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-6990

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, and CVE-2016-6989.

    Published: 11 Oct 2016
    9.8
    Critical

    CVE-2016-8606

    Last Modified: 20 Apr 2025

    The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.

    Published: 11 Oct 2016
    8.8
    High

    CVE-2016-4273

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, and CVE-2016-6990.

    Published: 11 Oct 2016
    8.8
    High

    CVE-2016-6982

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, and CVE-2016-6990.

    Published: 11 Oct 2016
    8.8
    High

    CVE-2016-6983

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4273, CVE-2016-6982, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, and CVE-2016-6990.

    Published: 11 Oct 2016
    8.8
    High

    CVE-2016-6987

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-6981.

    Published: 11 Oct 2016
    8.8
    High

    CVE-2016-6992

    Last Modified: 12 Apr 2025

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code by leveraging an unspecified "type confusion."

    Published: 11 Oct 2016
    5.9
    Medium

    CVE-2016-7055

    Last Modified: 20 Apr 2025

    There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bits. Analysis suggests that attacks against RSA, DSA and DH private keys are impossible. This is because the subroutine in question is not used in operations with the private key itself and an input of the attacker's direct choice. Otherwise the bug can manifest itself as transient authentication and key negotiation failures or reproducible erroneous outcome of public-key operations with specially crafted input. Among EC algorithms only Brainpool P-512 curves are affected and one presumably can attack ECDH key negotiation. Impact was not analyzed in detail, because pre-requisites for attack are considered unlikely. Namely multiple clients have to choose the curve in question and the server has to share the private key among them, neither of which is default behaviour. Even then only clients that chose the curve will be affected.

    Published: 11 Oct 2016
    6.1
    Medium

    CVE-2016-1000153

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin tidio-gallery v1.1

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000128

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin anti-plagiarism v3.60

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000129

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin defa-online-image-protector v3.3

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000130

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin e-search v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000131

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin e-search v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000139

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin infusionsoft v1.5.11

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000140

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin new-year-firework v1.1.9

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000141

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin page-layout-builder v1.9.3

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000142

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin parsi-font v4.2.5

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000144

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin photoxhibit v2.1.8

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000145

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin pondol-carousel v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000146

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin pondol-formmail v1.1

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000151

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin tera-charts v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000127

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin ajax-random-post v2.00

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000132

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin enhanced-tooltipglossary v3.2.8

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000133

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin forget-about-shortcode-buttons v1.1.1

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000134

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin hdw-tube v1.2

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000135

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin hdw-tube v1.2

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000136

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin heat-trackr v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000138

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin indexisto v1.0.5

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000143

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin photoxhibit v2.1.8

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000147

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin recipes-writer v1.0.4

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000148

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin s3-video v0.983

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000149

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin simpel-reserveren v3.5.2

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000150

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin simplified-content v1.0.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000152

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin tidio-form v1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000154

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin whizz v1.0.7

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000155

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin wpsolr-search-engine v7.6

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000137

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin hero-maps-pro v2.1.0

    Published: 10 Oct 2016
    6.1
    Medium

    CVE-2016-1000126

    Last Modified: 12 Apr 2025

    Reflected XSS in wordpress plugin admin-font-editor v1.8

    Published: 10 Oct 2016
    8.8
    High

    CVE-2016-1000216

    Last Modified: 12 Apr 2025

    Ruckus Wireless H500 web management interface authenticated command injection

    Published: 10 Oct 2016
    7.8
    High

    CVE-2016-8101

    Last Modified: 12 Apr 2025

    The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors.

    Published: 10 Oct 2016
    5.5
    Medium

    CVE-2016-8100

    Last Modified: 12 Apr 2025

    Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.

    Published: 10 Oct 2016
    6.5
    Medium

    CVE-2016-3882

    Last Modified: 12 Apr 2025

    Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attackers to cause a denial of service (reboot) via an access point that provides a crafted (1) Venue Group or (2) Venue Type value, aka internal bug 29464811.

    Published: 10 Oct 2016
    7.8
    High

    CVE-2016-3911

    Last Modified: 12 Apr 2025

    core/java/android/os/Process.java in Zygote in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 30143607.

    Published: 10 Oct 2016
    5.5
    Medium

    CVE-2016-3918

    Last Modified: 12 Apr 2025

    email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 does not ensure that certain values are integers, which allows attackers to read arbitrary attachments via a crafted application that provides a pathname value, aka internal bug 30745403.

    Published: 10 Oct 2016
    9.8
    Critical

    CVE-2016-3927

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in a Qualcomm component in Android before 2016-10-05 on Nexus 5X and 6P devices has unknown impact and attack vectors, aka internal bug 28823244.

    Published: 10 Oct 2016
    7.8
    High

    CVE-2016-3935

    Last Modified: 12 Apr 2025

    Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507.

    Published: 10 Oct 2016
    5.9
    Medium

    CVE-2016-5348

    Last Modified: 12 Apr 2025

    The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.

    Published: 10 Oct 2016
    7.8
    High

    CVE-2016-6675

    Last Modified: 12 Apr 2025

    Off-by-one error in CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to gain privileges or cause a denial of service (buffer overflow) via a crafted application that makes a linkspeed ioctl call, aka Android internal bug 30873776 and Qualcomm internal bug CR 1000861.

    Published: 10 Oct 2016
    5.5
    Medium

    CVE-2016-6682

    Last Modified: 12 Apr 2025

    drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does not initialize certain data structures, which allows attackers to obtain sensitive information via a crafted application, aka Android internal bug 30152501 and Qualcomm internal bug CR 1049615.

    Published: 10 Oct 2016
    5.5
    Medium

    CVE-2016-6690

    Last Modified: 12 Apr 2025

    The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cause a denial of service (reboot) via a crafted application, aka internal bug 28838221.

    Published: 10 Oct 2016