CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-1191

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Files function in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to modify settings via unspecified vectors.

    Published: 19 Jun 2016
    4.3
    Medium

    CVE-2016-1196

    Last Modified: 12 Apr 2025

    Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended access restrictions and obtain sensitive Address Book information via an API call, a different vulnerability than CVE-2015-7776.

    Published: 19 Jun 2016
    4.3
    Medium

    CVE-2016-1864

    Last Modified: 12 Apr 2025

    The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.

    Published: 19 Jun 2016
    4.3
    Medium

    CVE-2016-1192

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the logging implementation in Cybozu Garoon 3.7 through 4.2 allows remote authenticated users to read a log file via unspecified vectors.

    Published: 19 Jun 2016
    9.8
    Critical

    CVE-2016-0912

    Last Modified: 12 Apr 2025

    EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging access to (1) a different account with the same role as a target account or (2) an account's session at an unattended workstation.

    Published: 19 Jun 2016
    4.3
    Medium

    CVE-2015-7776

    Last Modified: 12 Apr 2025

    Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.

    Published: 19 Jun 2016
    8.4
    High

    CVE-2016-0392

    Last Modified: 12 Apr 2025

    IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, and 4.x before 4.0.3, as distributed in Spectrum Scale RAID, allows local users to gain privileges via a crafted parameter to a setuid program.

    Published: 19 Jun 2016
    3.3
    Low

    CVE-2016-1860

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1862.

    Published: 19 Jun 2016
    7.8
    High

    CVE-2016-1861

    Last Modified: 12 Apr 2025

    The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.

    Published: 19 Jun 2016
    3.3
    Low

    CVE-2016-1862

    Last Modified: 12 Apr 2025

    Intel Graphics Driver in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information via a crafted app, a different vulnerability than CVE-2016-1860.

    Published: 19 Jun 2016
    7.7
    High

    CVE-2016-4514

    Last Modified: 12 Apr 2025

    Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-4518

    Last Modified: 12 Apr 2025

    OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-4530

    Last Modified: 12 Apr 2025

    OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message.

    Published: 19 Jun 2016
    5.6
    Medium

    CVE-2016-4811

    Last Modified: 12 Apr 2025

    The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.

    Published: 19 Jun 2016
    5.4
    Medium

    CVE-2015-7775

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.

    Published: 19 Jun 2016
    7.4
    High

    CVE-2016-1195

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

    Published: 19 Jun 2016
    6.1
    Medium

    CVE-2016-1197

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7775.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-1225

    Last Modified: 12 Apr 2025

    Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Jun 2016
    6.1
    Medium

    CVE-2016-1226

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Jun 2016
    3.7
    Low

    CVE-2016-1183

    Last Modified: 12 Apr 2025

    NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitrary files, via a crafted pathname.

    Published: 19 Jun 2016
    5.3
    Medium

    CVE-2016-1223

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Jun 2016
    9.8
    Critical

    CVE-2016-1395

    Last Modified: 12 Apr 2025

    The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted HTTP request, aka Bug ID CSCux82428.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-1424

    Last Modified: 12 Apr 2025

    Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132.

    Published: 19 Jun 2016
    8
    High

    CVE-2016-4371

    Last Modified: 12 Apr 2025

    HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the Server, Web Client, Windows Client, and Service Request components.

    Published: 19 Jun 2016
    6.1
    Medium

    CVE-2016-1396

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux82583.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-1397

    Last Modified: 12 Apr 2025

    Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote authenticated users to cause a denial of service (device reload) via crafted configuration commands in an HTTP request, aka Bug ID CSCux82523.

    Published: 19 Jun 2016
    6.1
    Medium

    CVE-2016-1224

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-4816

    Last Modified: 12 Apr 2025

    BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.

    Published: 19 Jun 2016
    7.5
    High

    CVE-2016-4814

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Jun 2016
    7.5
    High

    CVE-2016-4817

    Last Modified: 12 Apr 2025

    lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.

    Published: 19 Jun 2016
    5.3
    Medium

    CVE-2016-4821

    Last Modified: 12 Apr 2025

    I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified vectors.

    Published: 19 Jun 2016
    8.8
    High

    CVE-2016-4813

    Last Modified: 12 Apr 2025

    NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

    Published: 19 Jun 2016
    7.5
    High

    CVE-2016-4815

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Jun 2016
    9.8
    Critical

    CVE-2016-4819

    Last Modified: 12 Apr 2025

    The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f through 3.16b, and DX Library for Visual C++ 3.13f through 3.16b allows remote attackers to execute arbitrary code via a crafted string.

    Published: 19 Jun 2016
    8.8
    High

    CVE-2016-4820

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users.

    Published: 19 Jun 2016
    9.8
    Critical

    CVE-2016-10253

    Last Modified: 20 Apr 2025

    An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

    Published: 19 Jun 2016
    7.8
    High

    CVE-2016-4300

    Last Modified: 12 Apr 2025

    Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.

    Published: 19 Jun 2016
    7.8
    High

    CVE-2016-4301

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.

    Published: 19 Jun 2016
    7.8
    High

    CVE-2016-4302

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-7540

    Last Modified: 20 Apr 2025

    coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.

    Published: 19 Jun 2016
    6.5
    Medium

    CVE-2016-1432

    Last Modified: 12 Apr 2025

    Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated users to cause a denial of service (NULL pointer dereference and card restart) via a crafted SNMP request, aka Bug ID CSCuu68862.

    Published: 18 Jun 2016
    7.5
    High

    CVE-2016-1427

    Last Modified: 12 Apr 2025

    The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages, aka Bug ID CSCuv35694.

    Published: 18 Jun 2016
    6.1
    Medium

    CVE-2016-1431

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.

    Published: 18 Jun 2016
    7.8
    High

    CVE-2016-3643

    Last Modified: 21 Apr 2026

    SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."

    Published: 17 Jun 2016
    6.1
    Medium

    CVE-2016-5433

    Last Modified: 12 Apr 2025

    Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.

    Published: 17 Jun 2016
    9.8
    Critical

    CVE-2016-3642

    Last Modified: 12 Apr 2025

    The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8920

    Last Modified: 12 Apr 2025

    The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.

    Published: 17 Jun 2016
    7.8
    High

    CVE-2015-8931

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8932

    Last Modified: 12 Apr 2025

    The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift.

    Published: 17 Jun 2016
    5.4
    Medium

    CVE-2016-4428

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.

    Published: 17 Jun 2016