CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-4598

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4599

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop document.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4600

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix bitmap image, a different vulnerability than CVE-2016-4596, CVE-2016-4597, and CVE-2016-4602.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4601

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted SGI image.

    Published: 22 Jul 2016
    5.4
    Medium

    CVE-2016-4604

    Last Modified: 12 Apr 2025

    Safari in Apple iOS before 9.3.3 allows remote attackers to spoof the displayed URL via an HTTP response specifying redirection to an invalid TCP port number.

    Published: 22 Jul 2016
    Unknown

    CVE-2016-4612

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1683. Reason: This candidate is a reservation duplicate of CVE-2016-1683. Notes: All CVE users should reference CVE-2016-1683 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jul 2016
    Unknown

    CVE-2016-4619

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8317. Reason: This candidate is a reservation duplicate of CVE-2015-8317. Notes: All CVE users should reference CVE-2015-8317 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4621

    Last Modified: 12 Apr 2025

    libc++abi in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4623

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4624.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4624

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4622, and CVE-2016-4623.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4625

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4626

    Last Modified: 12 Apr 2025

    IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4627

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 22 Jul 2016
    5.5
    Medium

    CVE-2016-4628

    Last Modified: 12 Apr 2025

    IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 22 Jul 2016
    3.3
    Low

    CVE-2016-4645

    Last Modified: 12 Apr 2025

    CFNetwork in Apple OS X before 10.11.6 uses weak permissions for web-browser cookies, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4631

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF file.

    Published: 22 Jul 2016
    7.5
    High

    CVE-2016-4632

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4633

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4634

    Last Modified: 12 Apr 2025

    The Graphics Drivers subsystem in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 22 Jul 2016
    5.3
    Medium

    CVE-2016-4635

    Last Modified: 12 Apr 2025

    FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive audio information in opportunistic circumstances, via unspecified vectors.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4640

    Last Modified: 12 Apr 2025

    Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context, obtain sensitive user information, or cause a denial of service (memory corruption) via a crafted app.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4647

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.6 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted file.

    Published: 22 Jul 2016
    5.5
    Medium

    CVE-2016-4648

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 22 Jul 2016
    5.5
    Medium

    CVE-2016-4649

    Last Modified: 12 Apr 2025

    Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

    Published: 22 Jul 2016
    6.1
    Medium

    CVE-2016-4651

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WebKit JavaScript bindings in Apple iOS before 9.3.3 and Safari before 9.1.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTTP/0.9 response, related to a "cross-protocol cross-site scripting (XPXSS)" vulnerability.

    Published: 22 Jul 2016
    6.3
    Medium

    CVE-2016-4652

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple OS X before 10.11.6 allows local users to obtain sensitive information from kernel memory and consequently gain privileges, or cause a denial of service (out-of-bounds read), via unspecified vectors.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4653

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1863 and CVE-2016-4582.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-4638

    Last Modified: 12 Apr 2025

    Login Window in Apple OS X before 10.11.6 allows attackers to gain privileges via a crafted app that leverages a "type confusion."

    Published: 22 Jul 2016
    7
    High

    CVE-2016-4639

    Last Modified: 12 Apr 2025

    Login Window in Apple OS X before 10.11.6 does not properly initialize memory, which allows local users to cause a denial of service via unspecified vectors.

    Published: 22 Jul 2016
    7.3
    High

    CVE-2016-4641

    Last Modified: 12 Apr 2025

    Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via a crafted app that leverages a "type confusion."

    Published: 22 Jul 2016
    9.8
    Critical

    CVE-2016-4616

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4614, CVE-2016-4615, and CVE-2016-4619.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4630

    Last Modified: 12 Apr 2025

    ImageIO in Apple OS X before 10.11.6 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted EXR image with B44 compression.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-4637

    Last Modified: 12 Apr 2025

    CoreGraphics in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted BMP image.

    Published: 22 Jul 2016
    5.3
    Medium

    CVE-2016-1000232

    Last Modified: 21 Nov 2024

    NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerability appears to have been fixed in 2.3.0.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-9313

    Last Modified: 12 Apr 2025

    security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.

    Published: 22 Jul 2016
    8.8
    High

    CVE-2016-10377

    Last Modified: 20 Apr 2025

    In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list enforced by the switch.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-3044

    Last Modified: 12 Apr 2025

    The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host OS infinite loop and hang) via unspecified vectors.

    Published: 22 Jul 2016
    5.5
    Medium

    CVE-2016-5000

    Last Modified: 12 Apr 2025

    The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 22 Jul 2016
    7.8
    High

    CVE-2016-5759

    Last Modified: 20 Apr 2025

    The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

    Published: 22 Jul 2016
    6.5
    Medium

    CVE-2016-5448

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect integrity and availability via vectors related to SNMP.

    Published: 21 Jul 2016
    7.5
    High

    CVE-2016-5449

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect availability via vectors related to Console Redirection.

    Published: 21 Jul 2016
    9.8
    Critical

    CVE-2016-5453

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to IPMI.

    Published: 21 Jul 2016
    6.4
    Medium

    CVE-2016-5454

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Verified Boot.

    Published: 21 Jul 2016
    5.3
    Medium

    CVE-2016-5455

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Communications Messaging Server component in Oracle Communications Applications 6.3, 7.0, and 8.0 allows remote attackers to affect confidentiality via vectors related to Multiplexor.

    Published: 21 Jul 2016
    5.3
    Medium

    CVE-2016-5456

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Services.

    Published: 21 Jul 2016
    8.8
    High

    CVE-2016-5457

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the ILOM component in Oracle Sun Systems Products Suite 3.0, 3.1, and 3.2 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to LUMAIN.

    Published: 21 Jul 2016
    6.5
    Medium

    CVE-2016-5461

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Object Manager.

    Published: 21 Jul 2016
    2.7
    Low

    CVE-2016-5462

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel Core - Server Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote administrators to affect confidentiality via vectors related to Workspaces.

    Published: 21 Jul 2016
    4.1
    Medium

    CVE-2016-5463

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5464.

    Published: 21 Jul 2016
    4.1
    Medium

    CVE-2016-5464

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect integrity via vectors related to SWSE Server, a different vulnerability than CVE-2016-5463.

    Published: 21 Jul 2016