CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-8680

    Last Modified: 20 Apr 2025

    The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.

    Published: 4 Oct 2016
    8.8
    High

    CVE-2016-7040

    Last Modified: 12 Apr 2025

    Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.

    Published: 4 Oct 2016
    4.9
    Medium

    CVE-2015-8085

    Last Modified: 12 Apr 2025

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for remote authenticated administrators to obtain and decrypt passwords by leveraging selection of a reversible encryption algorithm.

    Published: 3 Oct 2016
    9.8
    Critical

    CVE-2016-8276

    Last Modified: 12 Apr 2025

    Buffer overflow in the Point-to-Point Protocol over Ethernet (PPPoE) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600, when CHAP authentication is configured on the server, allows remote attackers to cause a denial of service (server restart) or execute arbitrary code via crafted packets sent during authentication.

    Published: 3 Oct 2016
    4.9
    Medium

    CVE-2015-8086

    Last Modified: 12 Apr 2025

    Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for remote authenticated administrators to obtain encryption keys and ciphertext passwords via vectors related to key storage.

    Published: 3 Oct 2016
    6.5
    Medium

    CVE-2016-8277

    Last Modified: 12 Apr 2025

    Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a denial of service (device restart) via an unspecified command parameter.

    Published: 3 Oct 2016
    7.5
    High

    CVE-2016-8278

    Last Modified: 12 Apr 2025

    Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attackers to cause a denial of service (device restart) via an unspecified URL.

    Published: 3 Oct 2016
    6.5
    Medium

    CVE-2016-8280

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Huawei eSight before V300R003C20SPC005 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 3 Oct 2016
    5.5
    Medium

    CVE-2016-1371

    Last Modified: 12 Apr 2025

    ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.

    Published: 3 Oct 2016
    4.3
    Medium

    CVE-2016-7570

    Last Modified: 12 Apr 2025

    Drupal 8.x before 8.1.10 does not properly check for "Administer comments" permission, which allows remote authenticated users to set the visibility of comments for arbitrary nodes by leveraging rights to edit those nodes.

    Published: 3 Oct 2016
    4.3
    Medium

    CVE-2016-7572

    Last Modified: 12 Apr 2025

    The system.temporary route in Drupal 8.x before 8.1.10 does not properly check for "Export configuration" permission, which allows remote authenticated users to bypass intended access restrictions and read a full config export via unspecified vectors.

    Published: 3 Oct 2016
    5.5
    Medium

    CVE-2016-1372

    Last Modified: 12 Apr 2025

    ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.

    Published: 3 Oct 2016
    9.8
    Critical

    CVE-2016-7405

    Last Modified: 12 Apr 2025

    The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.

    Published: 3 Oct 2016
    6.1
    Medium

    CVE-2016-7571

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Drupal 8.x before 8.1.10 allows remote attackers to inject arbitrary web script or HTML via vectors involving an HTTP exception.

    Published: 3 Oct 2016
    9.8
    Critical

    CVE-2016-5019

    Last Modified: 12 Apr 2025

    CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

    Published: 3 Oct 2016
    4.4
    Medium

    CVE-2016-7397

    Last Modified: 12 Apr 2025

    The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.

    Published: 3 Oct 2016
    7.5
    High

    CVE-2016-7445

    Last Modified: 12 Apr 2025

    convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.

    Published: 3 Oct 2016
    4.4
    Medium

    CVE-2016-7442

    Last Modified: 12 Apr 2025

    The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configuration tab.

    Published: 3 Oct 2016
    9.8
    Critical

    CVE-2016-5700

    Last Modified: 12 Apr 2025

    Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile, allow remote attackers to modify the system configuration, read system files, and possibly execute arbitrary code via unspecified vectors.

    Published: 3 Oct 2016
    9.8
    Critical

    CVE-2016-1243

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.

    Published: 3 Oct 2016
    7.5
    High

    CVE-2016-1246

    Last Modified: 12 Apr 2025

    Buffer overflow in the DBD::mysql module before 4.037 for Perl allows context-dependent attackers to cause a denial of service (crash) via vectors related to an error message.

    Published: 3 Oct 2016
    5.5
    Medium

    CVE-2016-9189

    Last Modified: 12 Apr 2025

    Pillow before 3.3.2 allows context-dependent attackers to obtain sensitive information by using the "crafted image file" approach, related to an "Integer Overflow" issue affecting the Image.core.map_buffer in map.c component.

    Published: 3 Oct 2016
    7.8
    High

    CVE-2016-9190

    Last Modified: 12 Apr 2025

    Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.

    Published: 3 Oct 2016
    8.8
    High

    CVE-2016-9429

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

    Published: 3 Oct 2016
    8.8
    High

    CVE-2016-1244

    Last Modified: 12 Apr 2025

    The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.

    Published: 3 Oct 2016
    6.5
    Medium

    CVE-2016-9443

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 2 Oct 2016
    7.3
    High

    CVE-2016-5995

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.

    Published: 1 Oct 2016
    7.5
    High

    CVE-2016-5986

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2016
    5.4
    Medium

    CVE-2016-3042

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.

    Published: 1 Oct 2016
    9.8
    Critical

    CVE-2016-7978

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in Ghostscript 9.20 might allow remote attackers to execute arbitrary code via vectors related to a reference leak in .setdevice.

    Published: 30 Sept 2016
    4.4
    Medium

    CVE-2016-7909

    Last Modified: 12 Apr 2025

    The pcnet_rdra_addr function in hw/net/pcnet.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by setting the (1) receive or (2) transmit descriptor ring length to 0.

    Published: 30 Sept 2016
    8.8
    High

    CVE-2016-7976

    Last Modified: 20 Apr 2025

    The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

    Published: 30 Sept 2016
    9.8
    Critical

    CVE-2016-8339

    Last Modified: 12 Apr 2025

    A buffer overflow in Redis 3.2.x prior to 3.2.4 causes arbitrary code execution when a crafted command is sent. An out of bounds write vulnerability exists in the handling of the client-output-buffer-limit option during the CONFIG SET command for the Redis data structure store. A crafted CONFIG SET command can lead to an out of bounds write potentially resulting in code execution.

    Published: 30 Sept 2016
    5.3
    Medium

    CVE-2016-6636

    Last Modified: 12 Apr 2025

    The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.1; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 mishandles redirect_uri subdomains, which allows remote attackers to obtain implicit access tokens via a modified subdomain.

    Published: 30 Sept 2016
    5.4
    Medium

    CVE-2016-6647

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Sept 2016
    8.8
    High

    CVE-2016-6651

    Last Modified: 12 Apr 2025

    The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH before 11.7 and 12.x before 12.6; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allows remote authenticated users to gain privileges by leveraging possession of a token.

    Published: 30 Sept 2016
    6.5
    Medium

    CVE-2016-7799

    Last Modified: 20 Apr 2025

    MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 30 Sept 2016
    5.5
    Medium

    CVE-2016-7906

    Last Modified: 20 Apr 2025

    magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.

    Published: 30 Sept 2016
    9.6
    Critical

    CVE-2016-6637

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4; UAA BOSH before 11.5 and 12.x before 12.5; Elastic Runtime before 1.6.40, 1.7.x before 1.7.21, and 1.8.x before 1.8.2; and Ops Manager 1.7.x before 1.7.13 and 1.8.x before 1.8.1 allow remote attackers to hijack the authentication of unspecified victims for requests that approve or deny a scope via a profile or authorize approval page.

    Published: 30 Sept 2016
    7.3
    High

    CVE-2016-4385

    Last Modified: 12 Apr 2025

    The RMI service in HP Network Automation Software 9.1x, 9.2x, 10.0x before 10.00.02.01, and 10.1x before 10.11.00.01 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) and Commons BeanUtils libraries.

    Published: 29 Sept 2016
    7.8
    High

    CVE-2016-4386

    Last Modified: 12 Apr 2025

    HPE Network Automation Software 10.10 allows local users to write to arbitrary files via unspecified vectors.

    Published: 29 Sept 2016
    9.8
    Critical

    CVE-2016-5062

    Last Modified: 12 Apr 2025

    The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.

    Published: 29 Sept 2016
    4
    Medium

    CVE-2016-7090

    Last Modified: 12 Apr 2025

    The integrated web server on Siemens SCALANCE M-800 and S615 modules with firmware before 4.02 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 29 Sept 2016
    6.1
    Medium

    CVE-2016-5061

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web server in Aternity before 9.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) HTTPAgent, (2) MacAgent, (3) getExternalURL, or (4) retrieveTrustedUrl page.

    Published: 29 Sept 2016
    8.8
    High

    CVE-2016-5177

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.

    Published: 29 Sept 2016
    9.8
    Critical

    CVE-2016-5180

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

    Published: 29 Sept 2016
    9.8
    Critical

    CVE-2016-5178

    Last Modified: 20 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 29 Sept 2016
    6.5
    Medium

    CVE-2016-5176

    Last Modified: 12 Apr 2025

    Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.

    Published: 29 Sept 2016
    7.5
    High

    CVE-2016-8332

    Last Modified: 12 Apr 2025

    A buffer overflow in OpenJPEG 2.1.1 causes arbitrary code execution when parsing a crafted image. An exploitable code execution vulnerability exists in the jpeg2000 image file format parser as implemented in the OpenJpeg library. A specially crafted jpeg2000 file can cause an out of bound heap write resulting in heap corruption leading to arbitrary code execution. For a successful attack, the target user needs to open a malicious jpeg2000 file. The jpeg2000 image file format is mostly used for embedding images inside PDF documents and the OpenJpeg library is used by a number of popular PDF renderers making PDF documents a likely attack vector.

    Published: 29 Sept 2016
    9.8
    Critical

    CVE-2016-9843

    Last Modified: 20 Apr 2025

    The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation.

    Published: 29 Sept 2016