CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-5267

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.

    Published: 5 Aug 2016
    4.3
    Medium

    CVE-2016-5250

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

    Published: 5 Aug 2016
    4.7
    Medium

    CVE-2016-5253

    Last Modified: 12 Apr 2025

    The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-5384

    Last Modified: 12 Apr 2025

    fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-10051

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in the ReadPWPImage function in coders/pwp.c in ImageMagick 6.9.5-5 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

    Published: 5 Aug 2016
    7.8
    High

    CVE-2016-3857

    Last Modified: 12 Apr 2025

    The kernel in Android before 2016-08-05 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 28522518.

    Published: 5 Aug 2016
    Unknown

    CVE-2016-6300

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 4 Aug 2016
    5.5
    Medium

    CVE-2016-10046

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.

    Published: 4 Aug 2016
    7.5
    High

    CVE-2016-6323

    Last Modified: 12 Apr 2025

    The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.

    Published: 4 Aug 2016
    7.8
    High

    CVE-2016-7910

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the disk_seqf_stop function in block/genhd.c in the Linux kernel before 4.7.1 allows local users to gain privileges by leveraging the execution of a certain stop operation even if the corresponding start operation had failed.

    Published: 4 Aug 2016
    6.5
    Medium

    CVE-2016-6312

    Last Modified: 20 Apr 2025

    The mod_dontdothat component of the mod_dav_svn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash). NOTE: Exists as a regression to CVE-2009-1955.

    Published: 4 Aug 2016
    7.5
    High

    CVE-2016-5639

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5669

    Last Modified: 12 Apr 2025

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 use a hardcoded 0xb9eed4d955a59eb3 X.509 certificate from an OpenSSL Test Certification Authority, which makes it easier for remote attackers to conduct man-in-the-middle attacks against HTTPS sessions by leveraging the certificate's trust relationship.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5670

    Last Modified: 12 Apr 2025

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 have a hardcoded password of admin for the admin account, which makes it easier for remote attackers to obtain access via the web management interface.

    Published: 3 Aug 2016
    6.1
    Medium

    CVE-2016-4833

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Nofollow Links plugin before 1.0.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5640

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the ATE_COMMAND parameter.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5666

    Last Modified: 12 Apr 2025

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 rely on the client to perform authentication, which allows remote attackers to obtain access by setting the value of objresp.authenabled to 1.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5667

    Last Modified: 12 Apr 2025

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication via a direct request to a page other than index.html.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5668

    Last Modified: 12 Apr 2025

    Crestron Electronics DM-TXRX-100-STR devices with firmware before 1.3039.00040 allow remote attackers to bypass authentication and change settings via a JSON API call.

    Published: 3 Aug 2016
    8.8
    High

    CVE-2016-5671

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on Crestron Electronics DM-TXRX-100-STR devices with firmware through 1.3039.00040 allow remote attackers to hijack the authentication of arbitrary users.

    Published: 3 Aug 2016
    7.5
    High

    CVE-2016-6301

    Last Modified: 4 Dec 2025

    The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP packet, which triggers a communication loop.

    Published: 3 Aug 2016
    7.5
    High

    CVE-2016-1000219

    Last Modified: 20 Apr 2025

    Kibana before 4.5.4 and 4.1.11 when a custom output is configured for logging in, cookies and authorization headers could be written to the log files. This information could be used to hijack sessions of other users when using Kibana behind some form of authentication such as Shield.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5143

    Last Modified: 12 Apr 2025

    The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5144.

    Published: 3 Aug 2016
    7.5
    High

    CVE-2016-5419

    Last Modified: 12 Apr 2025

    curl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has changed, which allows remote attackers to bypass intended restrictions by resuming a session.

    Published: 3 Aug 2016
    5.3
    Medium

    CVE-2016-7152

    Last Modified: 12 Apr 2025

    The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

    Published: 3 Aug 2016
    5.3
    Medium

    CVE-2016-7153

    Last Modified: 12 Apr 2025

    The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

    Published: 3 Aug 2016
    7.5
    High

    CVE-2016-5420

    Last Modified: 12 Apr 2025

    curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to hijack the authentication of the connection by leveraging a previously created connection with a different client certificate.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5144

    Last Modified: 12 Apr 2025

    The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase parameter, and remoteFrontendUrl parameter, which allows remote attackers to bypass intended access restrictions via a crafted URL, a different vulnerability than CVE-2016-5143.

    Published: 3 Aug 2016
    6.1
    Medium

    CVE-2016-1000220

    Last Modified: 20 Apr 2025

    Kibana before 4.5.4 and 4.1.11 are vulnerable to an XSS attack that would allow an attacker to execute arbitrary JavaScript in users' browsers.

    Published: 3 Aug 2016
    7.4
    High

    CVE-2016-10517

    Last Modified: 20 Apr 2025

    networking.c in Redis before 3.2.7 allows "Cross Protocol Scripting" because it lacks a check for POST and Host: strings, which are not valid in the Redis protocol (but commonly occur when an attack triggers an HTTP request to the Redis TCP port).

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5140

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the opj_j2k_read_SQcd_SQcc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JPEG 2000 data.

    Published: 3 Aug 2016
    7.5
    High

    CVE-2016-5141

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an initially empty document, related to FrameLoader.cpp and ScopedPageLoadDeferrer.cpp.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5142

    Last Modified: 12 Apr 2025

    The Web Cryptography API (aka WebCrypto) implementation in Blink, as used in Google Chrome before 52.0.2743.116, does not properly copy data buffers, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code, related to NormalizeAlgorithm.cpp and SubtleCrypto.cpp.

    Published: 3 Aug 2016
    7.6
    High

    CVE-2016-5139

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the opj_tcd_init_tile function in tcd.c in OpenJPEG, as used in PDFium in Google Chrome before 52.0.2743.116, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JPEG 2000 data.

    Published: 3 Aug 2016
    8.8
    High

    CVE-2016-5145

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 52.0.2743.116, does not ensure that a taint property is preserved after a structure-clone operation on an ImageBitmap object derived from a cross-origin image, which allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

    Published: 3 Aug 2016
    9.8
    Critical

    CVE-2016-5146

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.116 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 3 Aug 2016
    8.1
    High

    CVE-2016-5421

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.

    Published: 3 Aug 2016
    5.5
    Medium

    CVE-2016-6310

    Last Modified: 20 Apr 2025

    oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

    Published: 3 Aug 2016
    7.8
    High

    CVE-2016-6193

    Last Modified: 12 Apr 2025

    Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.

    Published: 2 Aug 2016
    7.8
    High

    CVE-2016-2408

    Last Modified: 12 Apr 2025

    Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.

    Published: 2 Aug 2016
    7.8
    High

    CVE-2016-1712

    Last Modified: 12 Apr 2025

    Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation.

    Published: 2 Aug 2016
    9.8
    Critical

    CVE-2016-5229

    Last Modified: 12 Apr 2025

    Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers to execute arbitrary code via vectors related to XStream Serialization.

    Published: 2 Aug 2016
    9.8
    Critical

    CVE-2016-6178

    Last Modified: 12 Apr 2025

    Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with software before V800R006SPH018; and CloudEngine devices 12800 with software before V100R003SPH010 and V100R005 before V100R005SPH006 allow remote attackers with control plane access to cause a denial of service or execute arbitrary code via a crafted packet.

    Published: 2 Aug 2016
    7.3
    High

    CVE-2016-6192

    Last Modified: 12 Apr 2025

    Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6193.

    Published: 2 Aug 2016
    7.5
    High

    CVE-2016-6232

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.

    Published: 2 Aug 2016
    6.5
    Medium

    CVE-2016-6257

    Last Modified: 12 Apr 2025

    The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject encrypted keyboard input into the system by leveraging proximity to the dongle, aka a "KeyJack injection attack."

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-2838

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.

    Published: 2 Aug 2016
    4.3
    Medium

    CVE-2016-5251

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 allows remote attackers to spoof the location bar via crafted characters in the media type of a data: URL.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5255

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-2836

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to Http2Session::Shutdown and SpdySession31::Shutdown, and other vectors.

    Published: 2 Aug 2016