CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2016-6510

    Last Modified: 12 Apr 2025

    Off-by-one error in epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6511

    Last Modified: 12 Apr 2025

    epan/proto.c in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (OpenFlow dissector large loop) via a crafted packet.

    Published: 27 Jul 2016
    4.4
    Medium

    CVE-2016-6490

    Last Modified: 12 Apr 2025

    The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a zero length for the descriptor buffer.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6505

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6506

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wsp.c in the WSP dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6507

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-mmse.c in the MMSE dissector in Wireshark 1.12.x before 1.12.13 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6508

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-rlc.c in the RLC dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6512

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors.

    Published: 27 Jul 2016
    5.9
    Medium

    CVE-2016-6513

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 2.x before 2.0.5 does not restrict the recursion depth, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 27 Jul 2016
    5.5
    Medium

    CVE-2016-5403

    Last Modified: 12 Apr 2025

    The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.

    Published: 27 Jul 2016
    7.5
    High

    CVE-2015-5738

    Last Modified: 12 Apr 2025

    The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perfect Forward Secrecy (PFS), makes it easier for remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

    Published: 26 Jul 2016
    6.2
    Medium

    CVE-2016-3992

    Last Modified: 12 Apr 2025

    cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.

    Published: 26 Jul 2016
    8.8
    High

    CVE-2016-6151

    Last Modified: 12 Apr 2025

    CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

    Published: 26 Jul 2016
    8.8
    High

    CVE-2016-6152

    Last Modified: 12 Apr 2025

    CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.

    Published: 26 Jul 2016
    8.8
    High

    CVE-2016-5406

    Last Modified: 12 Apr 2025

    The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.

    Published: 26 Jul 2016
    9.1
    Critical

    CVE-2016-6254

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.

    Published: 26 Jul 2016
    8.8
    High

    CVE-2016-6258

    Last Modified: 12 Apr 2025

    The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveraging fast-paths for updating pagetable entries.

    Published: 26 Jul 2016
    6.2
    Medium

    CVE-2016-6259

    Last Modified: 12 Apr 2025

    Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety check.

    Published: 26 Jul 2016
    7.8
    High

    CVE-2016-1238

    Last Modified: 12 Apr 2025

    (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan/IO-Compress/bin/zipdetails, (13) cpan/JSON-PP/bin/json_pp, (14) cpan/Test-Harness/bin/prove, (15) dist/ExtUtils-ParseXS/lib/ExtUtils/xsubpp, (16) dist/Module-CoreList/corelist, (17) ext/Pod-Html/bin/pod2html, (18) utils/c2ph.PL, (19) utils/h2ph.PL, (20) utils/h2xs.PL, (21) utils/libnetcfg.PL, (22) utils/perlbug.PL, (23) utils/perldoc.PL, (24) utils/perlivp.PL, and (25) utils/splain.PL in Perl 5.x before 5.22.3-RC2 and 5.24 before 5.24.1-RC2 do not properly remove . (period) characters from the end of the includes directory array, which might allow local users to gain privileges via a Trojan horse module under the current working directory.

    Published: 25 Jul 2016
    7.5
    High

    CVE-2016-5744

    Last Modified: 12 Apr 2025

    Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.

    Published: 22 Jul 2016
    7.5
    High

    CVE-2016-5874

    Last Modified: 12 Apr 2025

    Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.

    Published: 22 Jul 2016
    6.1
    Medium

    CVE-2016-6204

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the integrated web server in Siemens SINEMA Remote Connect Server before 1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 22 Jul 2016
    9.8
    Critical

    CVE-2016-5743

    Last Modified: 12 Apr 2025

    Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.1 Update 3 as distributed in SIMATIC PCS 7 through 8.1 SP1, SIMATIC OpenPCS 7 before 8.2 Update 1 as distributed in SIMATIC PCS 7 8.2, and SIMATIC WinCC Runtime Professional before 13 SP1 Update 9 allow remote attackers to execute arbitrary code via crafted packets.

    Published: 22 Jul 2016
    5.5
    Medium

    CVE-2016-1865

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4586

    Last Modified: 12 Apr 2025

    WebKit in Apple Safari before 9.1.2 and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4594

    Last Modified: 12 Apr 2025

    The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access the process list via a crafted app that makes an API call.

    Published: 22 Jul 2016
    9.8
    Critical

    CVE-2016-4614

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4615, CVE-2016-4616, and CVE-2016-4619.

    Published: 22 Jul 2016
    9.8
    Critical

    CVE-2016-4615

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4616, and CVE-2016-4619.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4622

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.

    Published: 22 Jul 2016
    9.8
    Critical

    CVE-2016-4629

    Last Modified: 12 Apr 2025

    ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted xStride and yStride values in an EXR image.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-4646

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read) via a crafted audio file.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-4587

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3 and tvOS before 9.2.2 allows remote attackers to obtain sensitive information from uninitialized process memory via a crafted web site.

    Published: 22 Jul 2016
    4.6
    Medium

    CVE-2016-4595

    Last Modified: 12 Apr 2025

    Safari Login AutoFill in Apple OS X before 10.11.6 allows physically proximate attackers to discover passwords by reading the screen during the login procedure.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4596

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4597, CVE-2016-4600, and CVE-2016-4602.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4602

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4597, and CVE-2016-4600.

    Published: 22 Jul 2016
    4.3
    Medium

    CVE-2016-4603

    Last Modified: 12 Apr 2025

    Web Media in Apple iOS before 9.3.3 allows attackers to bypass the Private Browsing protection mechanism and obtain sensitive video URL information by leveraging Safari View Controller misbehavior.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-4605

    Last Modified: 12 Apr 2025

    Calendar in Apple iOS before 9.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted invitation.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2014-9862

    Last Modified: 12 Apr 2025

    Integer signedness error in bspatch.c in bspatch in bsdiff, as used in Apple OS X before 10.11.6 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted patch file.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-1863

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4582

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4653.

    Published: 22 Jul 2016
    3.1
    Low

    CVE-2016-4583

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4584

    Last Modified: 12 Apr 2025

    The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 22 Jul 2016
    6.1
    Medium

    CVE-2016-4585

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to inject arbitrary web script or HTML via an HTTP response specifying redirection that is mishandled by Safari.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4588

    Last Modified: 12 Apr 2025

    WebKit in Apple tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4589

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4622, CVE-2016-4623, and CVE-2016-4624.

    Published: 22 Jul 2016
    5.4
    Medium

    CVE-2016-4590

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 22 Jul 2016
    7.5
    High

    CVE-2016-4591

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to access the local filesystem via unspecified vectors.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-4592

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to cause a denial of service (memory consumption) via a crafted web site.

    Published: 22 Jul 2016
    2.4
    Low

    CVE-2016-4593

    Last Modified: 12 Apr 2025

    The Siri Contacts component in Apple iOS before 9.3.3 allows physically proximate attackers to read arbitrary Contact card information via unspecified vectors.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4597

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4600, and CVE-2016-4602.

    Published: 22 Jul 2016