CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-5306

    Last Modified: 12 Apr 2025

    Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445.

    Published: 30 Jun 2016
    8.8
    High

    CVE-2016-5020

    Last Modified: 12 Apr 2025

    F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and gain privilege via a crafted external Extended Application Verification (EAV) monitor script.

    Published: 30 Jun 2016
    7.5
    High

    CVE-2016-4309

    Last Modified: 12 Apr 2025

    Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Published: 30 Jun 2016
    7.5
    High

    CVE-2016-4803

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the send email functionality in dotCMS before 3.3.2 allows remote attackers to inject arbitrary email headers via CRLF sequences in the subject.

    Published: 30 Jun 2016
    7.5
    High

    CVE-2016-5301

    Last Modified: 12 Apr 2025

    The parse_chunk_header function in libtorrent before 1.1.1 allows remote attackers to cause a denial of service (crash) via a crafted (1) HTTP response or possibly a (2) UPnP broadcast.

    Published: 30 Jun 2016
    5.3
    Medium

    CVE-2016-4086

    Last Modified: 12 Apr 2025

    Huawei HiSuite (In China) before 4.0.4.301 and (Out of China) before 4.0.4.204_ove allows remote attackers to install arbitrary apps on a connected phone via unspecified vectors.

    Published: 30 Jun 2016
    5.5
    Medium

    CVE-2016-5248

    Last Modified: 12 Apr 2025

    The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via the PID argument.

    Published: 30 Jun 2016
    7.8
    High

    CVE-2016-5249

    Last Modified: 12 Apr 2025

    Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Services.SystemService StartProxy command with a named pipe created in advance and crafted .NET assembly.

    Published: 30 Jun 2016
    8.2
    High

    CVE-2016-5729

    Last Modified: 12 Apr 2025

    Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.

    Published: 30 Jun 2016
    6.5
    Medium

    CVE-2016-4057

    Last Modified: 12 Apr 2025

    Huawei FusionCompute before V100R005C10SPC700 allows remote authenticated users to cause a denial of service (resource consumption) via a large number of crafted packets.

    Published: 30 Jun 2016
    8.8
    High

    CVE-2016-5230

    Last Modified: 12 Apr 2025

    Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and control partial module functions via a crafted app.

    Published: 30 Jun 2016
    7.8
    High

    CVE-2016-5231

    Last Modified: 12 Apr 2025

    Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to bypass permission checks and delete user data via a crafted app.

    Published: 30 Jun 2016
    5.5
    Medium

    CVE-2016-5232

    Last Modified: 12 Apr 2025

    Buffer overflow in Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (system crash) via a crafted app.

    Published: 30 Jun 2016
    7.5
    High

    CVE-2016-5368

    Last Modified: 12 Apr 2025

    Memory leak in Huawei AR3200 before V200R007C00SPC900 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted Multiprotocol Label Switching (MPLS) packets.

    Published: 30 Jun 2016
    7.2
    High

    CVE-2016-5840

    Last Modified: 12 Apr 2025

    hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header.

    Published: 30 Jun 2016
    6.5
    Medium

    CVE-2016-0349

    Last Modified: 12 Apr 2025

    IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restrictions and update process-instance variables via a REST API call.

    Published: 30 Jun 2016
    5.4
    Medium

    CVE-2016-0322

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Connections 4.0 through CR4, 4.5 through CR5, 5.0 through CR4, and 5.5 before CR1 allows remote authenticated users to inject arbitrary web script or HTML by uploading an HTML document.

    Published: 30 Jun 2016
    7.5
    High

    CVE-2016-2179

    Last Modified: 12 Apr 2025

    The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many crafted DTLS sessions simultaneously, related to d1_lib.c, statem_dtls.c, statem_lib.c, and statem_srvr.c.

    Published: 30 Jun 2016
    7.8
    High

    CVE-2016-6185

    Last Modified: 12 Apr 2025

    The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.

    Published: 30 Jun 2016
    6.5
    Medium

    CVE-2016-6132

    Last Modified: 12 Apr 2025

    The gdImageCreateFromTgaCtx function in the GD Graphics Library (aka libgd) before 2.2.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TGA file.

    Published: 30 Jun 2016
    8.8
    High

    CVE-2016-6297

    Last Modified: 12 Apr 2025

    Integer overflow in the php_stream_zip_opener function in ext/zip/zip_stream.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted zip:// URL.

    Published: 30 Jun 2016
    6.1
    Medium

    CVE-2016-5833

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5834.

    Published: 29 Jun 2016
    6.1
    Medium

    CVE-2016-5834

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment name, a different vulnerability than CVE-2016-5833.

    Published: 29 Jun 2016
    8.8
    High

    CVE-2016-5101

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-mail message.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5832

    Last Modified: 12 Apr 2025

    The customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5835

    Last Modified: 12 Apr 2025

    WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to wp-admin/includes/ajax-actions.php and wp-admin/revision.php.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5836

    Last Modified: 12 Apr 2025

    The oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5837

    Last Modified: 12 Apr 2025

    WordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via unspecified vectors.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5838

    Last Modified: 12 Apr 2025

    WordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-5839

    Last Modified: 12 Apr 2025

    WordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.

    Published: 29 Jun 2016
    7.1
    High

    CVE-2015-8698

    Last Modified: 12 Apr 2025

    CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allows remote attackers to read arbitrary files or cause a denial of service via a request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-0260

    Last Modified: 12 Apr 2025

    Memory leak in queue-manager agents in IBM WebSphere MQ 8.x before 8.0.0.5 allows remote attackers to cause a denial of service (heap memory consumption) by triggering many errors.

    Published: 29 Jun 2016
    7.7
    High

    CVE-2016-0267

    Last Modified: 12 Apr 2025

    IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive cleartext secure-property information via (1) the server UI or (2) a database request.

    Published: 29 Jun 2016
    6.1
    Medium

    CVE-2015-8699

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.1.0-1026 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Jun 2016
    8.1
    High

    CVE-2016-0304

    Last Modified: 12 Apr 2025

    The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pathnames is used, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, aka SPR KLYHA7MM3J. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-0920.

    Published: 29 Jun 2016
    7
    High

    CVE-2016-0263

    Last Modified: 12 Apr 2025

    IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privileges or cause a denial of service via a crafted mmapplypolicy command.

    Published: 29 Jun 2016
    6.5
    Medium

    CVE-2016-0298

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arbitrary files via a crafted URL.

    Published: 29 Jun 2016
    7.8
    High

    CVE-2016-6289

    Last Modified: 12 Apr 2025

    Integer overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a crafted extract operation on a ZIP archive.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-6131

    Last Modified: 20 Apr 2025

    The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.

    Published: 29 Jun 2016
    7.5
    High

    CVE-2016-4463

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

    Published: 29 Jun 2016
    8.8
    High

    CVE-2016-0233

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Jun 2016
    9.8
    Critical

    CVE-2016-0224

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in IBM Marketing Platform 8.5.x, 8.6.x, and 9.x before 9.1.2.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 28 Jun 2016
    6.1
    Medium

    CVE-2016-0229

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 8.6.x and 9.x before 9.1.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 28 Jun 2016
    7.8
    High

    CVE-2016-4324

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.

    Published: 28 Jun 2016
    7.5
    High

    CVE-2016-3949

    Last Modified: 12 Apr 2025

    Siemens SIMATIC S7-300 Profinet-enabled CPU devices with firmware before 3.2.12 and SIMATIC S7-300 Profinet-disabled CPU devices with firmware before 3.3.12 allow remote attackers to cause a denial of service (defect-mode transition) via crafted (1) ISO-TSAP or (2) Profibus packets.

    Published: 27 Jun 2016
    7.5
    High

    CVE-2016-6128

    Last Modified: 12 Apr 2025

    The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attackers to cause a denial of service (application crash) via an invalid color index.

    Published: 27 Jun 2016
    6.1
    Medium

    CVE-2016-10735

    Last Modified: 21 Nov 2024

    In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

    Published: 27 Jun 2016
    2.5
    Low

    CVE-2015-7473

    Last Modified: 12 Apr 2025

    runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass intended queue-manager command access restrictions by leveraging authority for +connect and +dsp.

    Published: 26 Jun 2016
    2.5
    Low

    CVE-2016-0259

    Last Modified: 12 Apr 2025

    runmqsc in IBM WebSphere MQ 8.x before 8.0.0.5 allows local users to bypass an intended +dsp authority requirement and obtain sensitive information via unspecified display commands.

    Published: 26 Jun 2016
    7.8
    High

    CVE-2016-0279

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to execute arbitrary code via a crafted PDF document, a different vulnerability than CVE-2016-0277, CVE-2016-0278, and CVE-2016-0301.

    Published: 26 Jun 2016