CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-2839

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a crafted video.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5259

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.

    Published: 2 Aug 2016
    6.1
    Medium

    CVE-2016-5262

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5263

    Last Modified: 12 Apr 2025

    The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5264

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an SVG element that is mishandled during effect application.

    Published: 2 Aug 2016
    4.3
    Medium

    CVE-2016-2830

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-2835

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 2 Aug 2016
    6.3
    Medium

    CVE-2016-2837

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5252

    Last Modified: 12 Apr 2025

    Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled during clipping-region calculations.

    Published: 2 Aug 2016
    8.8
    High

    CVE-2016-5258

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.

    Published: 2 Aug 2016
    6.5
    Medium

    CVE-2016-5260

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.

    Published: 2 Aug 2016
    5.5
    Medium

    CVE-2016-5265

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML document and a crafted shortcut file in the same local directory.

    Published: 2 Aug 2016
    8.1
    High

    CVE-2016-5266

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.

    Published: 2 Aug 2016
    4.3
    Medium

    CVE-2016-5268

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

    Published: 2 Aug 2016
    7.5
    High

    CVE-2016-5417

    Last Modified: 20 Apr 2025

    Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.

    Published: 2 Aug 2016
    9.8
    Critical

    CVE-2016-5254

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.

    Published: 2 Aug 2016
    5.4
    Medium

    CVE-2016-1609

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attribute of an IMG element in the phone field of a user profile.

    Published: 1 Aug 2016
    9.8
    Critical

    CVE-2016-4373

    Last Modified: 12 Apr 2025

    The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 1 Aug 2016
    7.5
    High

    CVE-2016-1461

    Last Modified: 12 Apr 2025

    Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.

    Published: 1 Aug 2016
    8.8
    High

    CVE-2016-5138

    Last Modified: 12 Apr 2025

    Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffer overflow and use-after-free) by leveraging an unrestricted multiplication.

    Published: 1 Aug 2016
    7.5
    High

    CVE-2016-1610

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a .. (dot dot) in a blob name.

    Published: 1 Aug 2016
    6.5
    Medium

    CVE-2016-1605

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.

    Published: 1 Aug 2016
    7.2
    High

    CVE-2016-1607

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring time settings via a vaconfig/time request.

    Published: 1 Aug 2016
    8.8
    High

    CVE-2016-1608

    Last Modified: 12 Apr 2025

    vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.

    Published: 1 Aug 2016
    7.8
    High

    CVE-2016-1611

    Last Modified: 12 Apr 2025

    Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.

    Published: 1 Aug 2016
    9.8
    Critical

    CVE-2016-4837

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Aug 2016
    8.1
    High

    CVE-2016-4834

    Last Modified: 12 Apr 2025

    modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.

    Published: 1 Aug 2016
    8.1
    High

    CVE-2016-5672

    Last Modified: 12 Apr 2025

    Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to spoof SSL servers and obtain sensitive information via a crafted certificate.

    Published: 1 Aug 2016
    5.5
    Medium

    CVE-2016-6494

    Last Modified: 12 Apr 2025

    The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.

    Published: 1 Aug 2016
    9.1
    Critical

    CVE-2016-6520

    Last Modified: 12 Apr 2025

    Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.

    Published: 1 Aug 2016
    5.1
    Medium

    CVE-2016-6480

    Last Modified: 12 Apr 2025

    Race condition in the ioctl_send_fib function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (out-of-bounds access or system crash) by changing a certain size value, aka a "double fetch" vulnerability.

    Published: 1 Aug 2016
    4.7
    Medium

    CVE-2017-0605

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 1 Aug 2016
    7.4
    High

    CVE-2016-6516

    Last Modified: 12 Apr 2025

    Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.

    Published: 31 Jul 2016
    7.8
    High

    CVE-2016-6492

    Last Modified: 20 Apr 2025

    The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted application that makes an MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL call.

    Published: 30 Jul 2016
    6.5
    Medium

    CVE-2016-6595

    Last Modified: 12 Apr 2025

    The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequence of join and quit actions. NOTE: the vendor disputes this issue, stating that this sequence is not "removing the state that is left by old nodes. At some point the manager obviously stops being able to accept new nodes, since it runs out of memory. Given that both for Docker swarm and for Docker Swarmkit nodes are *required* to provide a secret token (it's actually the only mode of operation), this means that no adversary can simply join nodes and exhaust manager resources. We can't do anything about a manager running out of memory and not being able to add new legitimate nodes to the system. This is merely a resource provisioning issue, and definitely not a CVE worthy vulnerability.

    Published: 29 Jul 2016
    8.8
    High

    CVE-2016-4469

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add new repository proxy connectors via the token parameter to admin/addProxyConnector_commit.action, (2) new repositories via the token parameter to admin/addRepository_commit.action, (3) edit existing repositories via the token parameter to admin/editRepository_commit.action, (4) add legacy artifact paths via the token parameter to admin/addLegacyArtifactPath_commit.action, (5) change the organizational appearance via the token parameter to admin/saveAppearance.action, or (6) upload new artifacts via the token parameter to upload_submit.action.

    Published: 28 Jul 2016
    4.8
    Medium

    CVE-2016-5005

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter to admin/addProxyConnector_commit.action.

    Published: 28 Jul 2016
    6.5
    Medium

    CVE-2016-1460

    Last Modified: 12 Apr 2025

    Cisco Wireless LAN Controller (WLC) devices 7.4(121.0) and 8.0(0.30220.385) allow remote attackers to cause a denial of service via crafted wireless management frames, aka Bug ID CSCun92979.

    Published: 28 Jul 2016
    8.8
    High

    CVE-2016-1374

    Last Modified: 12 Apr 2025

    The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrary commands via crafted parameters in a GET request, aka Bug ID CSCuy07827.

    Published: 28 Jul 2016
    6.1
    Medium

    CVE-2016-1462

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Prime Service Catalog (PSC) 11.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuz63795.

    Published: 28 Jul 2016
    7.5
    High

    CVE-2016-1463

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the header of an HTTP packet, aka Bug ID CSCuz20737.

    Published: 28 Jul 2016
    6.5
    Medium

    CVE-2016-1465

    Last Modified: 12 Apr 2025

    Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory access, aka Bug ID CSCuw57985.

    Published: 28 Jul 2016
    6.5
    Medium

    CVE-2016-1467

    Last Modified: 12 Apr 2025

    Cisco Videoscape Session Resource Manager (VSRM) allows remote attackers to cause a denial of service (device restart) by sending a traffic flood to upstream devices, aka Bug ID CSCva01813.

    Published: 28 Jul 2016
    9.8
    Critical

    CVE-2016-4522

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Jul 2016
    7.3
    High

    CVE-2016-4531

    Last Modified: 12 Apr 2025

    Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 28 Jul 2016
    3.3
    Low

    CVE-2013-7458

    Last Modified: 12 Apr 2025

    linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.

    Published: 28 Jul 2016
    6.5
    Medium

    CVE-2016-5412

    Last Modified: 12 Apr 2025

    arch/powerpc/kvm/book3s_hv_rmhandlers.S in the Linux kernel through 4.7 on PowerPC platforms, when CONFIG_KVM_BOOK3S_64_HV is enabled, allows guest OS users to cause a denial of service (host OS infinite loop) by making a H_CEDE hypercall during the existence of a suspended transaction.

    Published: 28 Jul 2016
    8.8
    High

    CVE-2016-6491

    Last Modified: 12 Apr 2025

    Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.

    Published: 28 Jul 2016
    3.3
    Low

    CVE-2016-6349

    Last Modified: 20 Apr 2025

    The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6509

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 27 Jul 2016