CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-6423

    Last Modified: 12 Apr 2025

    The IKEv2 client and initiator implementations in Cisco IOS 15.5(3)M and IOS XE allow remote IKEv2 servers to cause a denial of service (device reload) via crafted IKEv2 packets, aka Bug ID CSCux97540.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6378

    Last Modified: 12 Apr 2025

    Cisco IOS XE 3.1 through 3.17 and 16.1 through 16.2 allows remote attackers to cause a denial of service (device reload) via crafted ICMP packets that require NAT, aka Bug ID CSCuw85853.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6391

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 and 15.0 through 15.3 allows remote attackers to cause a denial of service (traffic-processing outage) via a crafted series of Common Industrial Protocol (CIP) requests, aka Bug ID CSCur69036.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6392

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 and 15.0 through 15.3 and IOS XE 3.1 through 3.9 allow remote attackers to cause a denial of service (device restart) via a crafted IPv4 Multicast Source Discovery Protocol (MSDP) Source-Active (SA) message, aka Bug ID CSCud36767.

    Published: 5 Oct 2016
    6.1
    Medium

    CVE-2016-6418

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6381

    Last Modified: 12 Apr 2025

    Cisco IOS 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.18 and 16.1 allow remote attackers to cause a denial of service (memory consumption or device reload) via fragmented IKEv1 packets, aka Bug ID CSCuy47382.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6382

    Last Modified: 12 Apr 2025

    Cisco IOS 15.2 through 15.6 and IOS XE 3.6 through 3.17 and 16.1 allow remote attackers to cause a denial of service (device restart) via a malformed IPv6 Protocol Independent Multicast (PIM) register packet, aka Bug ID CSCuy16399.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6384

    Last Modified: 12 Apr 2025

    Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device reload) via crafted fields in an H.323 message, aka Bug ID CSCux04257.

    Published: 5 Oct 2016
    5.9
    Medium

    CVE-2016-6416

    Last Modified: 12 Apr 2025

    The FTP service in Cisco AsyncOS on Email Security Appliance (ESA) devices 9.6.0-000 through 9.9.6-026, Web Security Appliance (WSA) devices 9.0.0-162 through 9.5.0-444, and Content Security Management Appliance (SMA) devices allows remote attackers to cause a denial of service via a flood of FTP traffic, aka Bug IDs CSCuz82907, CSCuz84330, and CSCuz86065.

    Published: 5 Oct 2016
    8.8
    High

    CVE-2016-6417

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco FireSIGHT System Software 4.10.2 through 6.1.0 and Firepower Management Center allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCva21636.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6386

    Last Modified: 12 Apr 2025

    Cisco IOS XE 3.1 through 3.17 and 16.1 on 64-bit platforms allows remote attackers to cause a denial of service (data-structure corruption and device reload) via fragmented IPv4 packets, aka Bug ID CSCux66005.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-7560

    Last Modified: 12 Apr 2025

    The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 has a hardcoded rsync account, which allows remote attackers to read or write to arbitrary files via unspecified vectors.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-5745

    Last Modified: 12 Apr 2025

    F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2 allow remote attackers to modify or extract system configuration files via vectors involving NAT64.

    Published: 5 Oct 2016
    5.6
    Medium

    CVE-2016-6652

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a repository that defines a String query using the @Query annotation, allows attackers to execute arbitrary JPQL commands via a sort instance with a function call.

    Published: 5 Oct 2016
    9.1
    Critical

    CVE-2016-7435

    Last Modified: 12 Apr 2025

    The (1) SCTC_REFRESH_EXPORT_TAB_COMP, (2) SCTC_REFRESH_CHECK_ENV, and (3) SCTC_TMS_MAINTAIN_ALOG functions in the SCTC subpackage in SAP Netweaver 7.40 SP 12 allow remote authenticated users with certain permissions to execute arbitrary commands via vectors involving a CALL 'SYSTEM' statement, aka SAP Security Note 2260344.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-4551

    Last Modified: 12 Apr 2025

    The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to the Security Audit Log via vectors related to the network landscape, aka SAP Security Note 2190621.

    Published: 5 Oct 2016
    7.2
    High

    CVE-2016-7561

    Last Modified: 12 Apr 2025

    Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-5686

    Last Modified: 12 Apr 2025

    Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-5084

    Last Modified: 12 Apr 2025

    Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.

    Published: 5 Oct 2016
    8.1
    High

    CVE-2016-4388

    Last Modified: 12 Apr 2025

    The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4389, and CVE-2016-4390.

    Published: 5 Oct 2016
    9.1
    Critical

    CVE-2014-5414

    Last Modified: 5 Nov 2025

    Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-2307

    Last Modified: 12 Apr 2025

    American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via unspecified vectors, as demonstrated by the configuration file.

    Published: 5 Oct 2016
    8.6
    High

    CVE-2016-2308

    Last Modified: 12 Apr 2025

    American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file.

    Published: 5 Oct 2016
    8.1
    High

    CVE-2016-4387

    Last Modified: 12 Apr 2025

    The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4388, CVE-2016-4389, and CVE-2016-4390.

    Published: 5 Oct 2016
    5.4
    Medium

    CVE-2016-5892

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM 10x, as used in Multi-Enterprise Integration Gateway 1.x through 1.0.0.1 and B2B Advanced Communications before 1.0.0.5_2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Oct 2016
    5.4
    Medium

    CVE-2016-5901

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in a test page in IBM Business Process Manager Advanced 8.5.6.0 through 8.5.7.0 before cumulative fix 2016.09 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Oct 2016
    9.1
    Critical

    CVE-2014-5415

    Last Modified: 5 Nov 2025

    Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3) TELNET service.

    Published: 5 Oct 2016
    8.1
    High

    CVE-2016-4389

    Last Modified: 12 Apr 2025

    The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4388, and CVE-2016-4390.

    Published: 5 Oct 2016
    8.1
    High

    CVE-2016-4390

    Last Modified: 12 Apr 2025

    The Filter SDK in HPE KeyView 10.18 through 10.24 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4387, CVE-2016-4388, and CVE-2016-4389.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-5085

    Last Modified: 12 Apr 2025

    Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-5086

    Last Modified: 12 Apr 2025

    Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-5983

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4 allows remote authenticated users to execute arbitrary Java code via a crafted serialized object.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-6419

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Cisco Firepower Management Center 4.10.3 through 5.4.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCur25485.

    Published: 5 Oct 2016
    6.5
    Medium

    CVE-2016-6420

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks and gain privileges via a crafted HTTP request, aka Bug ID CSCur25467.

    Published: 5 Oct 2016
    7.5
    High

    CVE-2016-8343

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 5 Oct 2016
    8.8
    High

    CVE-2016-6645

    Last Modified: 12 Apr 2025

    The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote authenticated users to execute arbitrary code via crafted input to the (1) GeneralCmdRequest, (2) PersistantDataRequest, or (3) GetCommandExecRequest class.

    Published: 5 Oct 2016
    5.4
    Medium

    CVE-2016-6550

    Last Modified: 12 Apr 2025

    The U by BB&T app 1.5.4 and earlier for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-0913

    Last Modified: 12 Apr 2025

    The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsoft 8.2.x before 8.2.3.6 allows remote RM servers to execute arbitrary commands by placing a crafted script in an SMB share.

    Published: 5 Oct 2016
    9.8
    Critical

    CVE-2016-6646

    Last Modified: 12 Apr 2025

    The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2) RemoteServiceHandler class.

    Published: 5 Oct 2016
    5.3
    Medium

    CVE-2018-11645

    Last Modified: 21 Nov 2024

    psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a similar issue to CVE-2016-7977.

    Published: 5 Oct 2016
    5.5
    Medium

    CVE-2016-9082

    Last Modified: 20 Apr 2025

    Integer overflow in the write_png function in cairo 1.14.6 allows remote attackers to cause a denial of service (invalid pointer dereference) via a large svg file.

    Published: 5 Oct 2016
    Unknown

    CVE-2016-4990

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Oct 2016
    7.3
    High

    CVE-2016-7966

    Last Modified: 12 Apr 2025

    Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

    Published: 4 Oct 2016
    9.8
    Critical

    CVE-2016-7979

    Last Modified: 20 Apr 2025

    Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently execute arbitrary code by leveraging type confusion in .initialize_dsc_parser.

    Published: 4 Oct 2016
    6.3
    Medium

    CVE-2016-7777

    Last Modified: 12 Apr 2025

    Xen 4.7.x and earlier does not properly honor CR0.TS and CR0.EM, which allows local x86 HVM guest OS users to read or modify FPU, MMX, or XMM register state information belonging to arbitrary tasks on the guest by modifying an instruction while the hypervisor is preparing to emulate it.

    Published: 4 Oct 2016
    7.5
    High

    CVE-2016-7958

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.

    Published: 4 Oct 2016
    6.5
    Medium

    CVE-2016-7968

    Last Modified: 12 Apr 2025

    KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.

    Published: 4 Oct 2016
    9.8
    Critical

    CVE-2016-7954

    Last Modified: 12 Apr 2025

    Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.

    Published: 4 Oct 2016
    7.5
    High

    CVE-2016-7957

    Last Modified: 20 Apr 2025

    In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-btl2cap.c by avoiding use of a seven-byte memcmp for potentially shorter strings.

    Published: 4 Oct 2016
    8.1
    High

    CVE-2016-7967

    Last Modified: 12 Apr 2025

    KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.

    Published: 4 Oct 2016