CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-1438

    Last Modified: 12 Apr 2025

    Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.

    Published: 23 Jun 2016
    6.1
    Medium

    CVE-2016-1439

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.

    Published: 23 Jun 2016
    8.8
    High

    CVE-2016-5766

    Last Modified: 12 Apr 2025

    Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimensions in an image.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5768

    Last Modified: 12 Apr 2025

    Double free vulnerability in the _php_mb_regex_ereg_replace_exec function in php_mbregex.c in the mbstring extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by leveraging a callback exception.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5771

    Last Modified: 12 Apr 2025

    spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5773

    Last Modified: 12 Apr 2025

    php_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) via crafted serialized data containing a ZipArchive object.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5772

    Last Modified: 12 Apr 2025

    Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a wddx_deserialize call.

    Published: 23 Jun 2016
    8.8
    High

    CVE-2016-5767

    Last Modified: 12 Apr 2025

    Integer overflow in the gdImageCreate function in gd.c in the GD Graphics Library (aka libgd) before 2.0.34RC1, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted image dimensions.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5770

    Last Modified: 12 Apr 2025

    Integer overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer argument, a related issue to CVE-2016-5096.

    Published: 23 Jun 2016
    9.8
    Critical

    CVE-2016-5841

    Last Modified: 12 Apr 2025

    Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable.

    Published: 22 Jun 2016
    7.5
    High

    CVE-2016-5842

    Last Modified: 12 Apr 2025

    MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

    Published: 22 Jun 2016
    5.3
    Medium

    CVE-2016-4995

    Last Modified: 12 Apr 2025

    Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated users with permission to view some hosts to obtain sensitive host configuration information via a URL with a hostname.

    Published: 22 Jun 2016
    7
    High

    CVE-2016-4996

    Last Modified: 20 Apr 2025

    discovery-debug in Foreman before 6.2 when the ssh service has been enabled on discovered nodes displays the root password in plaintext in the system journal when used to log in, which allows local users with access to the system journal to obtain the root password by reading the system journal, or by clicking Logs on the console.

    Published: 22 Jun 2016
    3.7
    Low

    CVE-2016-4323

    Last Modified: 20 Apr 2025

    A directory traversal exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an overwrite of files. A malicious server or someone with access to the network traffic can provide an invalid filename for a splash image triggering the vulnerability.

    Published: 21 Jun 2016
    9.8
    Critical

    CVE-2016-10541

    Last Modified: 21 Nov 2024

    The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2365

    Last Modified: 20 Apr 2025

    A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a null pointer dereference. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2367

    Last Modified: 20 Apr 2025

    An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle can send an invalid size for an avatar which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the avatar is sent to another user.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2368

    Last Modified: 20 Apr 2025

    Multiple memory corruption vulnerabilities exist in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could result in multiple buffer overflows, potentially resulting in code execution or memory disclosure.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2372

    Last Modified: 20 Apr 2025

    An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious user, server, or man-in-the-middle attacker can send an invalid size for a file transfer which will trigger an out-of-bounds read vulnerability. This could result in a denial of service or copy data from memory to the file, resulting in an information leak if the file is sent to another user.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2374

    Last Modified: 20 Apr 2025

    An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via the server can result in an out-of-bounds write leading to memory disclosure and code execution.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2376

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in arbitrary code execution. A malicious server or an attacker who intercepts the network traffic can send an invalid size for a packet which will trigger a buffer overflow.

    Published: 21 Jun 2016
    3.1
    Low

    CVE-2016-2380

    Last Modified: 20 Apr 2025

    An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent to the server could potentially result in an out-of-bounds read. A user could be convinced to enter a particular string which would then get converted incorrectly and could lead to a potential out-of-bounds read.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2369

    Last Modified: 20 Apr 2025

    A NULL pointer dereference vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in a denial of service vulnerability. A malicious server can send a packet starting with a NULL byte triggering the vulnerability.

    Published: 21 Jun 2016
    5.3
    Medium

    CVE-2016-2375

    Last Modified: 20 Apr 2025

    An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact information sent from the server can result in memory disclosure.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2378

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability exists in the handling of the MXIT protocol Pidgin. Specially crafted data sent via the server could potentially result in a buffer overflow, potentially resulting in memory corruption. A malicious server or an unfiltered malicious user can send negative length values to trigger this vulnerability.

    Published: 21 Jun 2016
    7.5
    High

    CVE-2016-3092

    Last Modified: 12 Apr 2025

    The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

    Published: 21 Jun 2016
    7.5
    High

    CVE-2016-4985

    Last Modified: 12 Apr 2025

    The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the v1/drivers/$DRIVER_NAME/vendor_passthru resource.

    Published: 21 Jun 2016
    9.8
    Critical

    CVE-2016-1000030

    Last Modified: 21 Nov 2024

    Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This vulnerability appears to have been fixed in 2.11.0.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2366

    Last Modified: 20 Apr 2025

    A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or an attacker who intercepts the network traffic can send invalid data to trigger this vulnerability and cause a crash.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2370

    Last Modified: 20 Apr 2025

    A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent from the server could potentially result in an out-of-bounds read. A malicious server or man-in-the-middle attacker can send invalid data to trigger this vulnerability.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2371

    Last Modified: 20 Apr 2025

    An out-of-bounds write vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could cause memory corruption resulting in code execution.

    Published: 21 Jun 2016
    5.9
    Medium

    CVE-2016-2373

    Last Modified: 20 Apr 2025

    A denial of service vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result in an out-of-bounds read. A malicious server or user can send an invalid mood to trigger this vulnerability.

    Published: 21 Jun 2016
    8.1
    High

    CVE-2016-2377

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent by the server could potentially result in an out-of-bounds write of one byte. A malicious server can send a negative content-length in response to a HTTP request triggering the vulnerability.

    Published: 21 Jun 2016
    8.8
    High

    CVE-2016-2379

    Last Modified: 20 Apr 2025

    The Mxit protocol uses weak encryption when encrypting user passwords, which might allow attackers to (1) decrypt hashed passwords by leveraging knowledge of client registration codes or (2) gain login access by eavesdropping on login messages and re-using the hashed passwords.

    Published: 21 Jun 2016
    7
    High

    CVE-2016-4444

    Last Modified: 20 Apr 2025

    The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function.

    Published: 21 Jun 2016
    7
    High

    CVE-2016-4445

    Last Modified: 20 Apr 2025

    The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.

    Published: 21 Jun 2016
    7
    High

    CVE-2016-4446

    Last Modified: 20 Apr 2025

    The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function.

    Published: 21 Jun 2016
    9.8
    Critical

    CVE-2016-4473

    Last Modified: 20 Apr 2025

    /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833.

    Published: 21 Jun 2016
    7
    High

    CVE-2016-4989

    Last Modified: 20 Apr 2025

    setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3) analysis_id field in a crafted XML document to the run_fix function in SetroubleshootFixit.py, related to the subprocess.check_output and commands.getstatusoutput functions, a different vulnerability than CVE-2016-4445.

    Published: 21 Jun 2016
    9.8
    Critical

    CVE-2016-2362

    Last Modified: 12 Apr 2025

    Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.

    Published: 20 Jun 2016
    5.9
    Medium

    CVE-2015-8288

    Last Modified: 12 Apr 2025

    NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 20 Jun 2016
    7.5
    High

    CVE-2015-8289

    Last Modified: 12 Apr 2025

    The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code.

    Published: 20 Jun 2016
    7.8
    High

    CVE-2016-2363

    Last Modified: 12 Apr 2025

    Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.

    Published: 20 Jun 2016
    7.5
    High

    CVE-2016-2364

    Last Modified: 12 Apr 2025

    The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 20 Jun 2016
    7.5
    High

    CVE-2016-6489

    Last Modified: 20 Apr 2025

    The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack.

    Published: 20 Jun 2016
    5.3
    Medium

    CVE-2016-1000023

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10540. Reason: This candidate is a reservation duplicate of CVE-2016-10540. Notes: All CVE users should reference CVE-2016-10540 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Jun 2016
    6.5
    Medium

    CVE-2016-3189

    Last Modified: 9 Jun 2025

    Use-after-free vulnerability in bzip2recover in bzip2 1.0.6 allows remote attackers to cause a denial of service (crash) via a crafted bzip2 file, related to block ends set to before the start of the block.

    Published: 20 Jun 2016
    7.8
    High

    CVE-2016-4994

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the xcf_load_image function in app/xcf/xcf-load.c in GIMP allows remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted XCF file.

    Published: 20 Jun 2016
    4.4
    Medium

    CVE-2015-7462

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.

    Published: 19 Jun 2016
    8.2
    High

    CVE-2016-0911

    Last Modified: 12 Apr 2025

    EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 has a default no_root_squash option for NFS exports, which makes it easier for remote attackers to obtain filesystem access by leveraging client root privileges.

    Published: 19 Jun 2016