CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2015-8919

    Last Modified: 12 Apr 2025

    The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2015-8921

    Last Modified: 12 Apr 2025

    The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8922

    Last Modified: 12 Apr 2025

    The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8926

    Last Modified: 12 Apr 2025

    The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8927

    Last Modified: 12 Apr 2025

    The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8933

    Last Modified: 12 Apr 2025

    Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.

    Published: 17 Jun 2016
    6.5
    Medium

    CVE-2015-8916

    Last Modified: 12 Apr 2025

    bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2015-8917

    Last Modified: 12 Apr 2025

    bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2015-8918

    Last Modified: 12 Apr 2025

    The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy."

    Published: 17 Jun 2016
    6.5
    Medium

    CVE-2015-8923

    Last Modified: 12 Apr 2025

    The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8924

    Last Modified: 12 Apr 2025

    The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8925

    Last Modified: 12 Apr 2025

    The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8928

    Last Modified: 12 Apr 2025

    The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8929

    Last Modified: 12 Apr 2025

    Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2015-8930

    Last Modified: 12 Apr 2025

    bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself.

    Published: 17 Jun 2016
    5.5
    Medium

    CVE-2015-8934

    Last Modified: 12 Apr 2025

    The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.

    Published: 17 Jun 2016
    8.4
    High

    CVE-2016-4383

    Last Modified: 20 Apr 2025

    The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated users to cause other users to boot into a modified image without notification of the change.

    Published: 17 Jun 2016
    8.8
    High

    CVE-2016-4430

    Last Modified: 12 Apr 2025

    Apache Struts 2 2.3.20 through 2.3.28.1 mishandles token validation, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via unspecified vectors.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2016-4431

    Last Modified: 12 Apr 2025

    Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks by leveraging a default method.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2016-4433

    Last Modified: 12 Apr 2025

    Apache Struts 2 2.3.20 through 2.3.28.1 allows remote attackers to bypass intended access restrictions and conduct redirection attacks via a crafted request.

    Published: 17 Jun 2016
    9.8
    Critical

    CVE-2016-4438

    Last Modified: 12 Apr 2025

    The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

    Published: 17 Jun 2016
    5.3
    Medium

    CVE-2016-4465

    Last Modified: 12 Apr 2025

    The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field.

    Published: 17 Jun 2016
    9.8
    Critical

    CVE-2016-4436

    Last Modified: 12 Apr 2025

    Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.

    Published: 17 Jun 2016
    7.5
    High

    CVE-2016-4992

    Last Modified: 20 Apr 2025

    389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to infer the existence of RDN component objects.

    Published: 17 Jun 2016
    5.3
    Medium

    CVE-2016-3687

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a base64-encoded URL in the SSO_ORIG_URI parameter.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3062

    Last Modified: 12 Apr 2025

    The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.

    Published: 16 Jun 2016
    9.8
    Critical

    CVE-2016-4165

    Last Modified: 12 Apr 2025

    The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input.

    Published: 16 Jun 2016
    7.3
    High

    CVE-2016-4158

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

    Published: 16 Jun 2016
    6.1
    Medium

    CVE-2016-4159

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-4126

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 16 Jun 2016
    7.3
    High

    CVE-2016-4157

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the installer in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse resource in an unspecified directory.

    Published: 16 Jun 2016
    6.1
    Medium

    CVE-2016-4164

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Brackets before 1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jun 2016
    9.8
    Critical

    CVE-2016-4167

    Last Modified: 12 Apr 2025

    Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3228

    Last Modified: 12 Apr 2025

    Microsoft Windows Server 2008 SP2 and R2 SP1 and Windows Server 2012 Gold and R2 allow remote authenticated users to execute arbitrary code via a crafted NetLogon request, aka "Windows Netlogon Memory Corruption Remote Code Execution Vulnerability."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3221

    Last Modified: 12 Apr 2025

    The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3218.

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3220

    Last Modified: 12 Apr 2025

    atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "ATMFD.dll Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-0200

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0199 and CVE-2016-3211.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3199

    Last Modified: 12 Apr 2025

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3214.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3213

    Last Modified: 12 Apr 2025

    The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 9 through 11 has an improper fallback mechanism, which allows remote attackers to gain privileges via NetBIOS name responses, aka "WPAD Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3218

    Last Modified: 12 Apr 2025

    The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-3221.

    Published: 16 Jun 2016
    8.1
    High

    CVE-2016-3223

    Last Modified: 12 Apr 2025

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandle LDAP authentication, which allows man-in-the-middle attackers to gain privileges by modifying group-policy update data within a domain-controller data stream, aka "Group Policy Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    9.8
    Critical

    CVE-2016-3227

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the DNS Server component in Microsoft Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted requests, aka "Windows DNS Server Use After Free Vulnerability."

    Published: 16 Jun 2016
    5
    Medium

    CVE-2016-3230

    Last Modified: 12 Apr 2025

    The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to cause a denial of service (performance degradation) via a crafted application, aka "Windows Search Component Denial of Service Vulnerability."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3231

    Last Modified: 12 Apr 2025

    The Standard Collector service in Windows Diagnostics Hub mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    5
    Medium

    CVE-2016-3232

    Last Modified: 12 Apr 2025

    The Virtual PCI (VPCI) virtual service provider in Microsoft Windows Server 2012 Gold and R2 allows local users to obtain sensitive information from uninitialized memory locations via a crafted application, aka "Windows Virtual PCI Information Disclosure Vulnerability."

    Published: 16 Jun 2016
    6.5
    Medium

    CVE-2016-3201

    Last Modified: 12 Apr 2025

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3215.

    Published: 16 Jun 2016
    7.5
    High

    CVE-2016-3202

    Last Modified: 12 Apr 2025

    The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

    Published: 16 Jun 2016
    7.5
    High

    CVE-2016-3206

    Last Modified: 12 Apr 2025

    The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3207.

    Published: 16 Jun 2016
    7.5
    High

    CVE-2016-3207

    Last Modified: 12 Apr 2025

    The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3205 and CVE-2016-3206.

    Published: 16 Jun 2016
    5.5
    Medium

    CVE-2016-3234

    Last Modified: 12 Apr 2025

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to obtain sensitive information from process memory via a crafted Office document, aka "Microsoft Office Information Disclosure Vulnerability."

    Published: 16 Jun 2016