CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-5407

    Last Modified: 12 Apr 2025

    The (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXv before 1.0.11 allow remote X servers to trigger out-of-bounds memory access operations via vectors involving length specifications in received data.

    Published: 25 Sept 2016
    4.3
    Medium

    CVE-2016-0918

    Last Modified: 12 Apr 2025

    EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-6531

    Last Modified: 12 Apr 2025

    Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ... is factually false ... there is indeed a default blank password, but it can be changed ... We recommend that users change it, each customer receives direction.

    Published: 24 Sept 2016
    8.8
    High

    CVE-2016-5793

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-6532

    Last Modified: 12 Apr 2025

    DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.

    Published: 24 Sept 2016
    8.8
    High

    CVE-2016-4845

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.

    Published: 24 Sept 2016
    7.5
    High

    CVE-2016-6408

    Last Modified: 12 Apr 2025

    Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.

    Published: 24 Sept 2016
    7.5
    High

    CVE-2016-6409

    Last Modified: 12 Apr 2025

    The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.

    Published: 24 Sept 2016
    6.5
    Medium

    CVE-2016-6410

    Last Modified: 12 Apr 2025

    The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.

    Published: 24 Sept 2016
    7.5
    High

    CVE-2016-6411

    Last Modified: 12 Apr 2025

    Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.

    Published: 24 Sept 2016
    6.5
    Medium

    CVE-2016-6412

    Last Modified: 12 Apr 2025

    The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.

    Published: 24 Sept 2016
    7.8
    High

    CVE-2016-6413

    Last Modified: 12 Apr 2025

    The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-9534

    Last Modified: 12 Apr 2025

    tif_write.c in libtiff 4.0.6 has an issue in the error code path of TIFFFlushData1() that didn't reset the tif_rawcc and tif_rawcp members. Reported as MSVR 35095, aka "TIFFFlushData1 heap-buffer-overflow."

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-9537

    Last Modified: 12 Apr 2025

    tools/tiffcrop.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in buffers. Reported as MSVR 35093, MSVR 35096, and MSVR 35097.

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-9533

    Last Modified: 12 Apr 2025

    tif_pixarlog.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers. Reported as MSVR 35094, aka "PixarLog horizontalDifference heap-buffer-overflow."

    Published: 24 Sept 2016
    9.8
    Critical

    CVE-2016-9536

    Last Modified: 12 Apr 2025

    tools/tiff2pdf.c in libtiff 4.0.6 has out-of-bounds write vulnerabilities in heap allocated buffers in t2p_process_jpeg_strip(). Reported as MSVR 35098, aka "t2p_process_jpeg_strip heap-buffer-overflow."

    Published: 24 Sept 2016
    7.2
    High

    CVE-2016-4978

    Last Modified: 15 Jun 2026

    The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 might allow remote authenticated users with permission to send messages to the Artemis broker to deserialize arbitrary objects and execute arbitrary code by leveraging gadget classes being present on the Artemis classpath.

    Published: 23 Sept 2016
    9.8
    Critical

    CVE-2016-7050

    Last Modified: 20 Apr 2025

    SerializableProvider in RESTEasy in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to execute arbitrary code.

    Published: 23 Sept 2016
    9.8
    Critical

    CVE-2016-7161

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the .receive callback of xlnx.xps-ethernetlite in QEMU (aka Quick Emulator) allows attackers to execute arbitrary code on the QEMU host via a large ethlite packet.

    Published: 23 Sept 2016
    9.8
    Critical

    CVE-2016-9137

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data that is mishandled during __wakeup processing.

    Published: 23 Sept 2016
    9.8
    Critical

    CVE-2016-6406

    Last Modified: 12 Apr 2025

    Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root access via a connection to the testing/debugging interface, aka Bug ID CSCvb26017.

    Published: 22 Sept 2016
    7.8
    High

    CVE-2016-6414

    Last Modified: 12 Apr 2025

    iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.

    Published: 22 Sept 2016
    9.8
    Critical

    CVE-2016-6374

    Last Modified: 12 Apr 2025

    Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.

    Published: 22 Sept 2016
    7.2
    High

    CVE-2016-6373

    Last Modified: 12 Apr 2025

    The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.

    Published: 22 Sept 2016
    6.5
    Medium

    CVE-2014-2146

    Last Modified: 12 Apr 2025

    The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoofed traffic that matches one of these sessions, aka Bug IDs CSCun94946 and CSCun96847.

    Published: 22 Sept 2016
    7.5
    High

    CVE-2016-6669

    Last Modified: 12 Apr 2025

    Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitrary code by sending a crafted EAP packet.

    Published: 22 Sept 2016
    5.5
    Medium

    CVE-2016-6265

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

    Published: 22 Sept 2016
    9.8
    Critical

    CVE-2016-6525

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.

    Published: 22 Sept 2016
    6.5
    Medium

    CVE-2016-6824

    Last Modified: 12 Apr 2025

    Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP packets.

    Published: 22 Sept 2016
    7.8
    High

    CVE-2016-5247

    Last Modified: 12 Apr 2025

    The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.

    Published: 22 Sept 2016
    8.8
    High

    CVE-2016-7545

    Last Modified: 20 Apr 2025

    SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.

    Published: 22 Sept 2016
    8.1
    High

    CVE-2016-7048

    Last Modified: 21 Nov 2024

    The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.

    Published: 22 Sept 2016
    3.3
    Low

    CVE-2016-7553

    Last Modified: 20 Apr 2025

    The buf.pl script before 2.20 in Irssi before 0.8.20 uses weak permissions for the scrollbuffer dump file created between upgrades, which might allow local users to obtain sensitive information from private chat conversations by reading the file.

    Published: 22 Sept 2016
    7.5
    High

    CVE-2016-6304

    Last Modified: 12 Apr 2025

    Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

    Published: 22 Sept 2016
    7.5
    High

    CVE-2016-6305

    Last Modified: 12 Apr 2025

    The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

    Published: 22 Sept 2016
    8.8
    High

    CVE-2016-9840

    Last Modified: 20 Apr 2025

    inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    Published: 22 Sept 2016
    9.8
    Critical

    CVE-2016-9841

    Last Modified: 20 Apr 2025

    inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.

    Published: 22 Sept 2016
    9.8
    Critical

    CVE-2016-4464

    Last Modified: 12 Apr 2025

    The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

    Published: 21 Sept 2016
    7.5
    High

    CVE-2016-5427

    Last Modified: 12 Apr 2025

    PowerDNS (aka pdns) Authoritative Server before 3.4.10 does not properly handle a . (dot) inside labels, which allows remote attackers to cause a denial of service (backend CPU consumption) via a crafted DNS query.

    Published: 21 Sept 2016
    6.1
    Medium

    CVE-2016-6158

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allow remote attackers to hijack the authentication of administrators for requests that (1) restore factory settings or (2) reboot the device via unspecified vectors.

    Published: 21 Sept 2016
    7.5
    High

    CVE-2016-6159

    Last Modified: 12 Apr 2025

    The management interface of Huawei WS331a routers with software before WS331a-10 V100R001C01B112 allows remote attackers to bypass authentication and obtain administrative access by sending "special packages" to the LAN interface.

    Published: 21 Sept 2016
    8.1
    High

    CVE-2016-7143

    Last Modified: 12 Apr 2025

    The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

    Published: 21 Sept 2016
    6.5
    Medium

    CVE-2016-4966

    Last Modified: 12 Apr 2025

    The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to download PCAP files via vectors related to the UserName GET parameter.

    Published: 21 Sept 2016
    6.5
    Medium

    CVE-2016-4967

    Last Modified: 12 Apr 2025

    Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the device configuration via script/cfg_show.php or (2) PCAP files via script/system/tcpdump.php.

    Published: 21 Sept 2016
    6.5
    Medium

    CVE-2016-4968

    Last Modified: 12 Apr 2025

    The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administrator cookies via a GET request.

    Published: 21 Sept 2016
    6.1
    Medium

    CVE-2016-4969

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.

    Published: 21 Sept 2016
    8.8
    High

    CVE-2016-4965

    Last Modified: 12 Apr 2025

    Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access to the nslookup functionality to execute arbitrary commands with root privileges via the graph parameter to diagnosis_control.php.

    Published: 21 Sept 2016
    7.5
    High

    CVE-2016-5426

    Last Modified: 12 Apr 2025

    PowerDNS (aka pdns) Authoritative Server before 3.4.10 allows remote attackers to cause a denial of service (backend CPU consumption) via a long qname.

    Published: 21 Sept 2016
    8.8
    High

    CVE-2016-6801

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.

    Published: 21 Sept 2016
    9.1
    Critical

    CVE-2016-0903

    Last Modified: 12 Apr 2025

    Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remote attackers to spoof clients and read backup data via a modified client agent.

    Published: 21 Sept 2016