CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-1433

    Last Modified: 12 Apr 2025

    Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.

    Published: 18 Sept 2016
    3.3
    Low

    CVE-2016-4620

    Last Modified: 12 Apr 2025

    The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.

    Published: 18 Sept 2016
    7.8
    High

    CVE-2016-4704

    Last Modified: 12 Apr 2025

    otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705.

    Published: 18 Sept 2016
    7.8
    High

    CVE-2016-4705

    Last Modified: 12 Apr 2025

    otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704.

    Published: 18 Sept 2016
    5.5
    Medium

    CVE-2016-4719

    Last Modified: 12 Apr 2025

    The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.

    Published: 18 Sept 2016
    5.3
    Medium

    CVE-2016-4746

    Last Modified: 12 Apr 2025

    The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.

    Published: 18 Sept 2016
    2.9
    Low

    CVE-2016-4740

    Last Modified: 12 Apr 2025

    Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.

    Published: 18 Sept 2016
    5.9
    Medium

    CVE-2016-4741

    Last Modified: 12 Apr 2025

    The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.

    Published: 18 Sept 2016
    3.3
    Low

    CVE-2016-4749

    Last Modified: 12 Apr 2025

    Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.

    Published: 18 Sept 2016
    5.9
    Medium

    CVE-2016-6403

    Last Modified: 12 Apr 2025

    The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.

    Published: 18 Sept 2016
    6.1
    Medium

    CVE-2016-6404

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy19854.

    Published: 18 Sept 2016
    6.5
    Medium

    CVE-2016-6405

    Last Modified: 12 Apr 2025

    Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368.

    Published: 18 Sept 2016
    6.1
    Medium

    CVE-2016-0926

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.

    Published: 18 Sept 2016
    6.1
    Medium

    CVE-2016-0927

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2016
    7.5
    High

    CVE-2016-0929

    Last Modified: 12 Apr 2025

    The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.

    Published: 18 Sept 2016
    6.1
    Medium

    CVE-2016-6642

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to hijack the authentication of administrators for requests that upload files.

    Published: 18 Sept 2016
    6.1
    Medium

    CVE-2016-6643

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2016
    7.3
    High

    CVE-2016-0896

    Last Modified: 12 Apr 2025

    Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address.

    Published: 18 Sept 2016
    9.8
    Critical

    CVE-2016-0897

    Last Modified: 12 Apr 2025

    Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.17 and 1.7.x before 1.7.8, when vCloud or vSphere is used, does not properly enable SSH access for operators, which has unspecified impact and remote attack vectors.

    Published: 18 Sept 2016
    7.4
    High

    CVE-2016-0928

    Last Modified: 12 Apr 2025

    Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 18 Sept 2016
    9.8
    Critical

    CVE-2016-0883

    Last Modified: 12 Apr 2025

    Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.

    Published: 18 Sept 2016
    9.8
    Critical

    CVE-2016-0922

    Last Modified: 12 Apr 2025

    EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force guessing attack.

    Published: 18 Sept 2016
    7.5
    High

    CVE-2016-0923

    Last Modified: 12 Apr 2025

    The client in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.9 and 4.1.x before 4.1.5 places the weakest algorithms first in a signature-algorithm list transmitted to a server, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging server behavior in which the first algorithm is used.

    Published: 18 Sept 2016
    Unknown

    CVE-2016-0924

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2004-2761. Reason: This candidate is subsumed by CVE-2004-2761. Notes: All CVE users should reference CVE-2004-2761 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Sept 2016
    9.8
    Critical

    CVE-2016-0930

    Last Modified: 12 Apr 2025

    Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation VMs, which allows remote attackers to obtain SSH access by connecting within an installation-time period during which these VMs exist.

    Published: 18 Sept 2016
    7.6
    High

    CVE-2016-6641

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Sept 2016
    7.5
    High

    CVE-2016-6639

    Last Modified: 12 Apr 2025

    Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.

    Published: 18 Sept 2016
    5.5
    Medium

    CVE-2016-7511

    Last Modified: 20 Apr 2025

    Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 18 Sept 2016
    5.4
    Medium

    CVE-2016-7419

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server before 9.0.52 allows remote authenticated users to inject arbitrary web script or HTML via a crafted directory name.

    Published: 17 Sept 2016
    8.1
    High

    CVE-2016-1482

    Last Modified: 12 Apr 2025

    Cisco WebEx Meetings Server 2.6 allows remote attackers to execute arbitrary commands by injecting these commands into an application script, aka Bug ID CSCuy83130.

    Published: 17 Sept 2016
    5.3
    Medium

    CVE-2016-6644

    Last Modified: 12 Apr 2025

    EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of an r_object_id value.

    Published: 17 Sept 2016
    7.5
    High

    CVE-2016-6407

    Last Modified: 12 Apr 2025

    Cisco AsyncOS through 9.5.0-444 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (link saturation) by making many HTTP requests for overlapping byte ranges simultaneously, aka Bug ID CSCuz27219.

    Published: 17 Sept 2016
    9.4
    Critical

    CVE-2016-5843

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.

    Published: 17 Sept 2016
    5.3
    Medium

    CVE-2016-6401

    Last Modified: 12 Apr 2025

    Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494.

    Published: 17 Sept 2016
    9.8
    Critical

    CVE-2016-6937

    Last Modified: 12 Apr 2025

    Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4191, CVE-2016-4192, CVE-2016-4193, CVE-2016-4194, CVE-2016-4195, CVE-2016-4196, CVE-2016-4197, CVE-2016-4198, CVE-2016-4199, CVE-2016-4200, CVE-2016-4201, CVE-2016-4202, CVE-2016-4203, CVE-2016-4204, CVE-2016-4205, CVE-2016-4206, CVE-2016-4207, CVE-2016-4208, CVE-2016-4211, CVE-2016-4212, CVE-2016-4213, CVE-2016-4214, CVE-2016-4250, CVE-2016-4251, CVE-2016-4252, CVE-2016-4254, CVE-2016-4265, CVE-2016-4266, CVE-2016-4267, CVE-2016-4268, CVE-2016-4269, and CVE-2016-4270.

    Published: 17 Sept 2016
    9.8
    Critical

    CVE-2016-6938

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4255.

    Published: 17 Sept 2016
    6.5
    Medium

    CVE-2016-7510

    Last Modified: 20 Apr 2025

    The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.

    Published: 17 Sept 2016
    9.8
    Critical

    CVE-2016-4261

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, and CVE-2016-4262.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4262

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, and CVE-2016-4261.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4263

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4256

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4258

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4260

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4261, and CVE-2016-4262.

    Published: 16 Sept 2016
    7.5
    High

    CVE-2016-6936

    Last Modified: 12 Apr 2025

    Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attackers to obtain sensitive information by leveraging access to a network over which analytics data is sent.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4257

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

    Published: 16 Sept 2016
    9.8
    Critical

    CVE-2016-4259

    Last Modified: 12 Apr 2025

    Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.

    Published: 16 Sept 2016
    5.9
    Medium

    CVE-2016-7420

    Last Modified: 14 Nov 2025

    Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are unintended in production use, which might allow context-dependent attackers to obtain sensitive information by leveraging access to process memory after an assertion failure, as demonstrated by reading a core dump.

    Published: 16 Sept 2016
    8.4
    High

    CVE-2016-7543

    Last Modified: 20 Apr 2025

    Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

    Published: 16 Sept 2016
    8.8
    High

    CVE-2016-8677

    Last Modified: 20 Apr 2025

    The AcquireQuantumPixels function in MagickCore/quantum.c in ImageMagick before 7.0.3-1 allows remote attackers to have unspecified impact via a crafted image file, which triggers a memory allocation failure.

    Published: 16 Sept 2016
    7.8
    High

    CVE-2016-10044

    Last Modified: 20 Apr 2025

    The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users to bypass intended SELinux W^X policy restrictions, and consequently gain privileges, via an io_setup system call.

    Published: 16 Sept 2016