CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2015-8960

    Last Modified: 12 Apr 2025

    The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which makes it easier for man-in-the-middle attackers to spoof TLS servers by leveraging knowledge of the secret key for an arbitrary installed client X.509 certificate, aka the "Key Compromise Impersonation (KCI)" issue.

    Published: 21 Sept 2016
    8.6
    High

    CVE-2016-0904

    Last Modified: 12 Apr 2025

    Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive client-server traffic information by leveraging knowledge of this key from another installation.

    Published: 21 Sept 2016
    6.7
    Medium

    CVE-2016-0905

    Last Modified: 12 Apr 2025

    Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leveraging admin access and entering a sudo command.

    Published: 21 Sept 2016
    9.8
    Critical

    CVE-2016-0917

    Last Modified: 12 Apr 2025

    The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638), VNX1 File OE before 7.1.80.3, VNX2 File OE before 8.1.9.155, and Celerra (all supported versions) does not prevent duplicate NTLM challenge-response nonces, which makes it easier for remote attackers to execute arbitrary code, or read or write to files, via a series of authentication requests, a related issue to CVE-2010-0231.

    Published: 21 Sept 2016
    7.8
    High

    CVE-2016-0920

    Last Modified: 12 Apr 2025

    Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root access via a crafted parameter to a command that is available in the sudo configuration.

    Published: 21 Sept 2016
    6.5
    Medium

    CVE-2016-0921

    Last Modified: 12 Apr 2025

    Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, which allows local users to obtain root access by replacing a script with a Trojan horse program.

    Published: 21 Sept 2016
    5.4
    Medium

    CVE-2016-0925

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Case Management application in EMC RSA Adaptive Authentication (On-Premise) before 6.0.2.1.SP3.P4 HF210, 7.0.x and 7.1.x before 7.1.0.0.SP0.P6 HF50, and 7.2.x before 7.2.0.0.SP0.P0 HF20 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Sept 2016
    8.3
    High

    CVE-2016-4382

    Last Modified: 12 Apr 2025

    HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user validation failure" issue.

    Published: 21 Sept 2016
    8.6
    High

    CVE-2016-4384

    Last Modified: 12 Apr 2025

    HPE Performance Center before 12.50 and LoadRunner before 12.50 allow remote attackers to cause a denial of service via unspecified vectors.

    Published: 21 Sept 2016
    9.8
    Critical

    CVE-2016-6530

    Last Modified: 12 Apr 2025

    Dentsply Sirona (formerly Schick) CDR Dicom 5 and earlier has default passwords for the sa and cdr accounts, which allows remote attackers to obtain administrative access by leveraging knowledge of these passwords.

    Published: 21 Sept 2016
    4.4
    Medium

    CVE-2016-7908

    Last Modified: 12 Apr 2025

    The mcf_fec_do_tx function in hw/net/mcf_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.

    Published: 21 Sept 2016
    6.5
    Medium

    CVE-2016-7498

    Last Modified: 12 Apr 2025

    OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.

    Published: 21 Sept 2016
    4.4
    Medium

    CVE-2016-7907

    Last Modified: 12 Apr 2025

    The imx_fec_do_tx function in hw/net/imx_fec.c in QEMU (aka Quick Emulator) does not properly limit the buffer descriptor count when transmitting packets, which allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via vectors involving a buffer descriptor with a length of 0 and crafted values in bd.flags.

    Published: 21 Sept 2016
    5.9
    Medium

    CVE-2016-6307

    Last Modified: 12 Apr 2025

    The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.

    Published: 21 Sept 2016
    5.9
    Medium

    CVE-2016-6308

    Last Modified: 12 Apr 2025

    statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.

    Published: 21 Sept 2016
    7.5
    High

    CVE-2016-7044

    Last Modified: 12 Apr 2025

    The unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote attackers to cause a denial of service (heap corruption and crash) via an incomplete 24bit color code.

    Published: 21 Sept 2016
    5.9
    Medium

    CVE-2016-6306

    Last Modified: 12 Apr 2025

    The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

    Published: 21 Sept 2016
    7.5
    High

    CVE-2016-7045

    Last Modified: 12 Apr 2025

    The format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service (heap corruption and crash) via vectors involving the length of a string.

    Published: 21 Sept 2016
    9.8
    Critical

    CVE-2016-5270

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conversion.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5276

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.

    Published: 20 Sept 2016
    8.8
    High

    CVE-2016-5283

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

    Published: 20 Sept 2016
    7.4
    High

    CVE-2016-5284

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.

    Published: 20 Sept 2016
    6.5
    Medium

    CVE-2016-2827

    Last Modified: 12 Apr 2025

    The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

    Published: 20 Sept 2016
    6.5
    Medium

    CVE-2016-5271

    Last Modified: 12 Apr 2025

    The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5274

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5277

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

    Published: 20 Sept 2016
    8.8
    High

    CVE-2016-5272

    Last Modified: 12 Apr 2025

    The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 20 Sept 2016
    8.8
    High

    CVE-2016-5273

    Last Modified: 12 Apr 2025

    The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 20 Sept 2016
    8.8
    High

    CVE-2016-5275

    Last Modified: 12 Apr 2025

    Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.

    Published: 20 Sept 2016
    6.5
    Medium

    CVE-2016-5282

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

    Published: 20 Sept 2016
    8.8
    High

    CVE-2016-5278

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.

    Published: 20 Sept 2016
    4.3
    Medium

    CVE-2016-5279

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5280

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5281

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5256

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 20 Sept 2016
    9.8
    Critical

    CVE-2016-5257

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 20 Sept 2016
    7.5
    High

    CVE-2016-6415

    Last Modified: 22 Apr 2026

    The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

    Published: 19 Sept 2016
    5.3
    Medium

    CVE-2016-0870

    Last Modified: 12 Apr 2025

    The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.

    Published: 19 Sept 2016
    7.5
    High

    CVE-2016-1483

    Last Modified: 12 Apr 2025

    Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.

    Published: 19 Sept 2016
    9.8
    Critical

    CVE-2016-6536

    Last Modified: 12 Apr 2025

    The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a handle parameter value.

    Published: 19 Sept 2016
    8.6
    High

    CVE-2016-5814

    Last Modified: 12 Apr 2025

    Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS project file.

    Published: 19 Sept 2016
    7.3
    High

    CVE-2016-4860

    Last Modified: 12 Apr 2025

    Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change value, or (3) modify application command.

    Published: 19 Sept 2016
    7.5
    High

    CVE-2016-6537

    Last Modified: 12 Apr 2025

    AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTTP Cookie headers, which allows context-dependent attacks to obtain sensitive information by reading these strings.

    Published: 19 Sept 2016
    7.5
    High

    CVE-2016-4526

    Last Modified: 12 Apr 2025

    ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.

    Published: 19 Sept 2016
    9.8
    Critical

    CVE-2016-6535

    Last Modified: 12 Apr 2025

    AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.

    Published: 19 Sept 2016
    7.5
    High

    CVE-2016-7798

    Last Modified: 20 Apr 2025

    The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

    Published: 19 Sept 2016
    6
    Medium

    CVE-2016-7994

    Last Modified: 12 Apr 2025

    Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_CREATE_2D commands.

    Published: 19 Sept 2016
    6.3
    Medium

    CVE-2017-15102

    Last Modified: 20 Apr 2025

    The tower_probe function in drivers/usb/misc/legousbtower.c in the Linux kernel before 4.8.1 allows local users (who are physically proximate for inserting a crafted USB device) to gain privileges by leveraging a write-what-where condition that occurs after a race condition and a NULL pointer dereference.

    Published: 19 Sept 2016
    3.7
    Low

    CVE-2016-4747

    Last Modified: 12 Apr 2025

    Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.

    Published: 18 Sept 2016
    7.8
    High

    CVE-2016-6402

    Last Modified: 12 Apr 2025

    UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.

    Published: 18 Sept 2016