CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2016-5945

    Last Modified: 12 Apr 2025

    IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to upload non-executable files via a crafted HTTP request.

    Published: 26 Sept 2016
    6.5
    Medium

    CVE-2016-5946

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.

    Published: 26 Sept 2016
    5.7
    Medium

    CVE-2016-5947

    Last Modified: 12 Apr 2025

    IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

    Published: 26 Sept 2016
    8.8
    High

    CVE-2016-5963

    Last Modified: 12 Apr 2025

    IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 26 Sept 2016
    7.1
    High

    CVE-2016-5971

    Last Modified: 12 Apr 2025

    IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 26 Sept 2016
    6.8
    Medium

    CVE-2016-5972

    Last Modified: 12 Apr 2025

    IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 26 Sept 2016
    5.4
    Medium

    CVE-2016-5974

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.

    Published: 26 Sept 2016
    5.4
    Medium

    CVE-2016-5975

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string, a different vulnerability than CVE-2016-5978.

    Published: 26 Sept 2016
    4.9
    Medium

    CVE-2016-5976

    Last Modified: 12 Apr 2025

    The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows remote authenticated users to discover component passwords via unspecified vectors.

    Published: 26 Sept 2016
    6.5
    Medium

    CVE-2016-5997

    Last Modified: 12 Apr 2025

    The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not apply password-quality rules to password changes, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 26 Sept 2016
    7.5
    High

    CVE-2016-7052

    Last Modified: 12 Apr 2025

    crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

    Published: 26 Sept 2016
    6.5
    Medium

    CVE-2016-7101

    Last Modified: 20 Apr 2025

    The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.

    Published: 26 Sept 2016
    7.5
    High

    CVE-2016-6823

    Last Modified: 20 Apr 2025

    Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.

    Published: 26 Sept 2016
    7.5
    High

    CVE-2016-7401

    Last Modified: 12 Apr 2025

    The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.

    Published: 26 Sept 2016
    6
    Medium

    CVE-2016-7995

    Last Modified: 12 Apr 2025

    Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of crafted buffer page select (PG) indexes.

    Published: 26 Sept 2016
    9.8
    Critical

    CVE-2016-9138

    Last Modified: 12 Apr 2025

    PHP through 5.6.27 and 7.x through 7.0.12 mishandles property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup.

    Published: 26 Sept 2016
    9.8
    Critical

    CVE-2016-6309

    Last Modified: 12 Apr 2025

    statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.

    Published: 26 Sept 2016
    7.8
    High

    CVE-2016-9675

    Last Modified: 12 Apr 2025

    openjpeg: A heap-based buffer overflow flaw was found in the patch for CVE-2013-6045. A crafted j2k image could cause the application to crash, or potentially execute arbitrary code.

    Published: 26 Sept 2016
    8.8
    High

    CVE-2016-5169

    Last Modified: 12 Apr 2025

    Format string vulnerability in Google Chrome OS before 53.0.2785.103 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4698

    Last Modified: 12 Apr 2025

    AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Published: 25 Sept 2016
    4
    Medium

    CVE-2016-4707

    Last Modified: 12 Apr 2025

    CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.

    Published: 25 Sept 2016
    3.3
    Low

    CVE-2016-4715

    Last Modified: 12 Apr 2025

    The Date & Time Pref Pane component in Apple OS X before 10.12 mishandles the .GlobalPreferences file, which allows attackers to discover a user's location via a crafted app.

    Published: 25 Sept 2016
    6.5
    Medium

    CVE-2016-4718

    Last Modified: 12 Apr 2025

    Buffer overflow in FontParser in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory via a crafted font file.

    Published: 25 Sept 2016
    5.9
    Medium

    CVE-2016-4722

    Last Modified: 12 Apr 2025

    The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attacks and cause a denial of service via unspecified vectors.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4723

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 25 Sept 2016
    8.1
    High

    CVE-2016-4725

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a crafted web site.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4730

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4738

    Last Modified: 12 Apr 2025

    libxslt in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 25 Sept 2016
    5.5
    Medium

    CVE-2016-4755

    Last Modified: 12 Apr 2025

    Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 25 Sept 2016
    6.8
    Medium

    CVE-2016-4763

    Last Modified: 12 Apr 2025

    WKWebView in WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly verify X.509 certificates from HTTPS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4766

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4767, and CVE-2016-4768.

    Published: 25 Sept 2016
    5.5
    Medium

    CVE-2016-4771

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathname.

    Published: 25 Sept 2016
    7.5
    High

    CVE-2016-4772

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to cause a denial of service (unintended lock) via unspecified vectors.

    Published: 25 Sept 2016
    7.1
    High

    CVE-2016-4774

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4776.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4775

    Last Modified: 12 Apr 2025

    The kernel in Apple OS X before 10.12, tvOS before 10, and watchOS before 3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4777

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (invalid pointer dereference) via a crafted app.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4699

    Last Modified: 12 Apr 2025

    AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4700.

    Published: 25 Sept 2016
    6.5
    Medium

    CVE-2016-4708

    Last Modified: 12 Apr 2025

    CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attackers to obtain sensitive information via a crafted HTTP response.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4716

    Last Modified: 12 Apr 2025

    diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4724

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 10 and OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4731

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10 and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4729.

    Published: 25 Sept 2016
    7.8
    High

    CVE-2016-4733

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4734, and CVE-2016-4735.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4735

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4611, CVE-2016-4730, CVE-2016-4733, and CVE-2016-4734.

    Published: 25 Sept 2016
    3.7
    Low

    CVE-2016-4739

    Last Modified: 12 Apr 2025

    mDNSResponder in Apple OS X before 10.12, when VMnet.framework is used, arranges for a DNS proxy to listen on all interfaces, which allows remote attackers to obtain sensitive information by sending a DNS query to an unintended interface.

    Published: 25 Sept 2016
    5.3
    Medium

    CVE-2016-4745

    Last Modified: 12 Apr 2025

    The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes it easier for remote attackers to enumerate user accounts via a timing side-channel attack.

    Published: 25 Sept 2016
    5.3
    Medium

    CVE-2016-4748

    Last Modified: 12 Apr 2025

    Perl in Apple OS X before 10.12 allows local users to bypass the taint-mode protection mechanism via a crafted environment variable.

    Published: 25 Sept 2016
    6.5
    Medium

    CVE-2016-4758

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, which allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4765

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4766, CVE-2016-4767, and CVE-2016-4768.

    Published: 25 Sept 2016
    7.1
    High

    CVE-2016-4776

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to obtain sensitive memory-layout information or cause a denial of service (out-of-bounds read) via a crafted app, a different vulnerability than CVE-2016-4773 and CVE-2016-4774.

    Published: 25 Sept 2016
    8.8
    High

    CVE-2016-4611

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.

    Published: 25 Sept 2016