CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-4169

    Last Modified: 12 Apr 2025

    Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.

    Published: 9 Aug 2016
    6.1
    Medium

    CVE-2016-4170

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Aug 2016
    5.3
    Medium

    CVE-2016-4253

    Last Modified: 12 Apr 2025

    The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vectors.

    Published: 9 Aug 2016
    6
    Medium

    CVE-2016-6835

    Last Modified: 12 Apr 2025

    The vmxnet_tx_pkt_parse_headers function in hw/net/vmxnet_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (buffer over-read) by leveraging failure to check IP header length.

    Published: 9 Aug 2016
    6.1
    Medium

    CVE-2016-6319

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in app/helpers/form_helper.rb in Foreman before 1.12.2, as used by Remote Execution and possibly other plugins, allows remote attackers to inject arbitrary web script or HTML via the label parameter.

    Published: 9 Aug 2016
    9.8
    Critical

    CVE-2016-2788

    Last Modified: 20 Apr 2025

    MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the mco ping command.

    Published: 9 Aug 2016
    4.4
    Medium

    CVE-2016-6833

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU instance crash) by leveraging failure to check if the device is active.

    Published: 9 Aug 2016
    4.4
    Medium

    CVE-2016-6834

    Last Modified: 12 Apr 2025

    The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the current fragment length.

    Published: 9 Aug 2016
    4.4
    Medium

    CVE-2016-6888

    Last Modified: 12 Apr 2025

    Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.

    Published: 9 Aug 2016
    8.8
    High

    CVE-2016-2875

    Last Modified: 12 Apr 2025

    IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vectors.

    Published: 8 Aug 2016
    5.4
    Medium

    CVE-2016-2912

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 8 Aug 2016
    3.7
    Low

    CVE-2016-2960

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service via crafted SIP messages.

    Published: 8 Aug 2016
    6.1
    Medium

    CVE-2016-5331

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 8 Aug 2016
    5.4
    Medium

    CVE-2016-2914

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.

    Published: 8 Aug 2016
    5.4
    Medium

    CVE-2016-0280

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glossary 9.1 before 9.1.2.0, Information Server Framework and InfoSphere Information Governance Catalog 11.3 before 11.3.1.2, and Information Server Framework and InfoSphere Information Governance Catalog 11.5 before 11.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 8 Aug 2016
    3.7
    Low

    CVE-2016-0281

    Last Modified: 12 Apr 2025

    The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.

    Published: 8 Aug 2016
    6.5
    Medium

    CVE-2016-0361

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by discovering ADMIN passwords.

    Published: 8 Aug 2016
    3.3
    Low

    CVE-2016-0380

    Last Modified: 12 Apr 2025

    IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.

    Published: 8 Aug 2016
    3.7
    Low

    CVE-2016-0266

    Last Modified: 12 Apr 2025

    IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

    Published: 8 Aug 2016
    5.4
    Medium

    CVE-2016-2925

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 8 Aug 2016
    6.5
    Medium

    CVE-2016-2989

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 8 Aug 2016
    5.4
    Medium

    CVE-2016-3054

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.

    Published: 8 Aug 2016
    6.2
    Medium

    CVE-2016-3059

    Last Modified: 12 Apr 2025

    IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect Snapshot) 3.1 before 3.1.1.7 and 3.2 before 3.2.1.9 allow local users to discover a cleartext SQL Server password by reading the Task List in the MMC GUI.

    Published: 8 Aug 2016
    7.8
    High

    CVE-2016-5330

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before 8.1.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 8 Aug 2016
    6.8
    Medium

    CVE-2016-5878

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 8 Aug 2016
    8.8
    High

    CVE-2016-1468

    Last Modified: 12 Apr 2025

    The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.

    Published: 8 Aug 2016
    7.8
    High

    CVE-2015-6396

    Last Modified: 12 Apr 2025

    The CLI command parser on Cisco RV110W, RV130W, and RV215W devices allows local users to execute arbitrary shell commands as an administrator via crafted parameters, aka Bug IDs CSCuv90134, CSCux58161, and CSCux73567.

    Published: 8 Aug 2016
    8.8
    High

    CVE-2015-6397

    Last Modified: 12 Apr 2025

    Cisco RV110W, RV130W, and RV215W devices have an incorrect RBAC configuration for the default account, which allows remote authenticated users to obtain root access via a login session with that account, aka Bug IDs CSCuv90139, CSCux58175, and CSCux73557.

    Published: 8 Aug 2016
    7.5
    High

    CVE-2016-1429

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the web interface on Cisco RV180 and RV180W devices allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCuz43023.

    Published: 8 Aug 2016
    8.8
    High

    CVE-2016-1430

    Last Modified: 12 Apr 2025

    Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.

    Published: 8 Aug 2016
    7.5
    High

    CVE-2016-1466

    Last Modified: 12 Apr 2025

    Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP packet, aka Bug ID CSCva39072.

    Published: 8 Aug 2016
    4.3
    Medium

    CVE-2016-1474

    Last Modified: 12 Apr 2025

    Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuw65846, a different vulnerability than CVE-2015-6434.

    Published: 8 Aug 2016
    7.5
    High

    CVE-2016-1478

    Last Modified: 12 Apr 2025

    Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.

    Published: 8 Aug 2016
    9.8
    Critical

    CVE-2016-5792

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.

    Published: 8 Aug 2016
    7.7
    High

    CVE-2016-4374

    Last Modified: 12 Apr 2025

    HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors.

    Published: 8 Aug 2016
    7.8
    High

    CVE-2016-6486

    Last Modified: 12 Apr 2025

    Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via unspecified vectors.

    Published: 8 Aug 2016
    6.5
    Medium

    CVE-2016-9430

    Last Modified: 12 Apr 2025

    An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

    Published: 8 Aug 2016
    7.8
    High

    CVE-2016-2064

    Last Modified: 12 Apr 2025

    sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted application that makes an ioctl call specifying many commands.

    Published: 7 Aug 2016
    7.8
    High

    CVE-2016-5340

    Last Modified: 12 Apr 2025

    The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.

    Published: 7 Aug 2016
    7.5
    High

    CVE-2015-3854

    Last Modified: 12 Apr 2025

    packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission requirement via a broadcast intent with the PNW.stopSaver action, aka internal bug 20918350.

    Published: 7 Aug 2016
    7.8
    High

    CVE-2016-2065

    Last Modified: 12 Apr 2025

    sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (out-of-bounds write and memory corruption) or possibly have unspecified other impact via a crafted application that makes an ioctl call triggering incorrect use of a parameters pointer.

    Published: 7 Aug 2016
    6.1
    Medium

    CVE-2016-6634

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Aug 2016
    8.6
    High

    CVE-2016-4029

    Last Modified: 12 Apr 2025

    WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

    Published: 7 Aug 2016
    8.8
    High

    CVE-2016-6635

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in WordPress before 4.5 allows remote attackers to hijack the authentication of administrators for requests that change the script compression option.

    Published: 7 Aug 2016
    5.9
    Medium

    CVE-2016-6503

    Last Modified: 12 Apr 2025

    The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 6 Aug 2016
    5.9
    Medium

    CVE-2016-6504

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

    Published: 6 Aug 2016
    7.3
    High

    CVE-2016-3841

    Last Modified: 12 Apr 2025

    The IPv6 stack in the Linux kernel before 4.3.3 mishandles options data, which allows local users to gain privileges or cause a denial of service (use-after-free and system crash) via a crafted sendmsg system call.

    Published: 6 Aug 2016
    7.8
    High

    CVE-2014-9868

    Last Modified: 12 Apr 2025

    drivers/media/platform/msm/camera_v2/sensor/csiphy/msm_csiphy.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via an application that provides a crafted mask value, aka Android internal bug 28749721 and Qualcomm internal bug CR511976.

    Published: 6 Aug 2016
    7.8
    High

    CVE-2014-9870

    Last Modified: 12 Apr 2025

    The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044.

    Published: 6 Aug 2016
    7.8
    High

    CVE-2014-9877

    Last Modified: 12 Apr 2025

    drivers/media/platform/msm/camera_v2/sensor/actuator/msm_actuator.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices mishandles a user-space pointer, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28768281 and Qualcomm internal bug CR547231.

    Published: 6 Aug 2016