CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-4608

    Last Modified: 12 Apr 2025

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

    Published: 21 Jul 2016
    9.8
    Critical

    CVE-2017-16042

    Last Modified: 21 Nov 2024

    Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.

    Published: 21 Jul 2016
    9.8
    Critical

    CVE-2016-4607

    Last Modified: 12 Apr 2025

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4608, CVE-2016-4609, CVE-2016-4610, and CVE-2016-4612.

    Published: 21 Jul 2016
    9.8
    Critical

    CVE-2016-4609

    Last Modified: 12 Apr 2025

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4608, CVE-2016-4610, and CVE-2016-4612.

    Published: 21 Jul 2016
    9.8
    Critical

    CVE-2016-4610

    Last Modified: 12 Apr 2025

    libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, and CVE-2016-4612.

    Published: 21 Jul 2016
    6.1
    Medium

    CVE-2016-7103

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.

    Published: 21 Jul 2016
    8.8
    High

    CVE-2016-5131

    Last Modified: 4 Dec 2025

    Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.

    Published: 20 Jul 2016
    9.6
    Critical

    CVE-2016-1706

    Last Modified: 12 Apr 2025

    The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should have come from the browser process, which allows remote attackers to bypass a sandbox protection mechanism via an unexpected message type, related to broker_process_dispatcher.cc, ppapi_plugin_process_host.cc, ppapi_thread.cc, and render_frame_message_filter.cc.

    Published: 20 Jul 2016
    3.7
    Low

    CVE-2016-3452

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Security: Encryption.

    Published: 20 Jul 2016
    7.5
    High

    CVE-2016-3471

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Option.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-3521

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: Types.

    Published: 20 Jul 2016
    5.3
    Medium

    CVE-2016-5133

    Last Modified: 12 Apr 2025

    Google Chrome before 52.0.2743.82 mishandles origin information during proxy authentication, which allows man-in-the-middle attackers to spoof a proxy-authentication login prompt or trigger incorrect credential storage by modifying the client-server data stream.

    Published: 20 Jul 2016
    4.3
    Medium

    CVE-2016-5400

    Last Modified: 12 Apr 2025

    Memory leak in the airspy_probe function in drivers/media/usb/airspy/airspy.c in the airspy USB driver in the Linux kernel before 4.7 allows local users to cause a denial of service (memory consumption) via a crafted USB device that emulates many VFL_TYPE_SDR or VFL_TYPE_SUBDEV devices and performs many connect and disconnect operations.

    Published: 20 Jul 2016
    3.7
    Low

    CVE-2016-5444

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related to Server: Connection.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-1707

    Last Modified: 12 Apr 2025

    ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about:blank URL, which allows remote attackers to spoof the URL display via a crafted web site.

    Published: 20 Jul 2016
    5.3
    Medium

    CVE-2016-3614

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Security: Encryption.

    Published: 20 Jul 2016
    4.3
    Medium

    CVE-2016-5137

    Last Modified: 12 Apr 2025

    The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 52.0.2743.82, does not apply http :80 policies to https :443 URLs and does not apply ws :80 policies to wss :443 URLs, which makes it easier for remote attackers to determine whether a specific HSTS web site has been visited by reading a CSP report. NOTE: this vulnerability is associated with a specification change after CVE-2016-1617 resolution.

    Published: 20 Jul 2016
    5.3
    Medium

    CVE-2016-3615

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote authenticated users to affect availability via vectors related to Server: DML.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-3459

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows remote administrators to affect availability via vectors related to Server: InnoDB.

    Published: 20 Jul 2016
    8.1
    High

    CVE-2016-3477

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Parser.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-3486

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-1705

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 52.0.2743.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-1708

    Last Modified: 12 Apr 2025

    The Chrome Web Store inline-installation implementation in the Extensions subsystem in Google Chrome before 52.0.2743.82 does not properly consider object lifetimes during progress observation, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-1709

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ByteArray::Get method in data/byte_array.cc in Google sfntly before 2016-06-10, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted SFNT font.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-1710

    Last Modified: 12 Apr 2025

    The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not prevent window creation by a deferred frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-1711

    Last Modified: 12 Apr 2025

    WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach operation on a DocumentLoader object, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-3424

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Optimizer.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-3501

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-3518

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.

    Published: 20 Jul 2016
    5.9
    Medium

    CVE-2016-3588

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote authenticated users to affect integrity and availability via vectors related to Server: InnoDB.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-5130

    Last Modified: 12 Apr 2025

    content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, which allows remote attackers to spoof the URL display via a crafted web site.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-5128

    Last Modified: 12 Apr 2025

    objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-5134

    Last Modified: 12 Apr 2025

    net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restricted to a scheme, host, and port, which allows remote attackers to discover credentials by operating a server with a PAC script, a related issue to CVE-2016-3763.

    Published: 20 Jul 2016
    6.5
    Medium

    CVE-2016-5135

    Last Modified: 12 Apr 2025

    WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy information inside an HTML document during a preload request, which allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted web site, as demonstrated by a "Content-Security-Policy: referrer origin-when-cross-origin" header that overrides a "<META name='referrer' content='no-referrer'>" element.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5437

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Log.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5436

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: InnoDB.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5441

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Replication.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5442

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Security: Encryption.

    Published: 20 Jul 2016
    4.7
    Medium

    CVE-2016-5443

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.12 and earlier allows local users to affect availability via vectors related to Server: Connection.

    Published: 20 Jul 2016
    7.5
    High

    CVE-2016-6261

    Last Modified: 12 Apr 2025

    The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.

    Published: 20 Jul 2016
    7.7
    High

    CVE-2016-3440

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows remote authenticated users to affect availability via vectors related to Server: Optimizer.

    Published: 20 Jul 2016
    7.5
    High

    CVE-2016-5127

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in WebKit/Source/core/editing/VisibleUnits.cpp in Blink, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code involving an @import at-rule in a Cascading Style Sheets (CSS) token sequence in conjunction with a rel=import attribute of a LINK element.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-5129

    Last Modified: 12 Apr 2025

    Google V8 before 5.2.361.32, as used in Google Chrome before 52.0.2743.82, does not properly process left-trimmed objects, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-5132

    Last Modified: 12 Apr 2025

    The Service Workers subsystem in Google Chrome before 52.0.2743.82 does not properly implement the Secure Contexts specification during decisions about whether to control a subframe, which allows remote attackers to bypass the Same Origin Policy via an https IFRAME element inside an http IFRAME element.

    Published: 20 Jul 2016
    8.8
    High

    CVE-2016-5136

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in extensions/renderer/user_script_injector.cc in the Extensions subsystem in Google Chrome before 52.0.2743.82 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to script deletion.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5439

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote administrators to affect availability via vectors related to Server: Privileges.

    Published: 20 Jul 2016
    4.9
    Medium

    CVE-2016-5440

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors related to Server: RBR.

    Published: 20 Jul 2016
    9.8
    Critical

    CVE-2016-5080

    Last Modified: 12 Apr 2025

    Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow), on a system running an application compiled by ASN1C, via crafted ASN.1 data.

    Published: 19 Jul 2016
    5.9
    Medium

    CVE-2016-5655

    Last Modified: 12 Apr 2025

    Misys FusionCapital Opics Plus does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate.

    Published: 19 Jul 2016
    7.5
    High

    CVE-2016-5654

    Last Modified: 12 Apr 2025

    Misys FusionCapital Opics Plus allows remote authenticated users to gain privileges via a man-in-the-middle attack that modifies the xmlMessageOut parameter.

    Published: 19 Jul 2016