CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2016-0028

    Last Modified: 12 Apr 2025

    Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, aka "Microsoft Exchange Information Disclosure Vulnerability."

    Published: 16 Jun 2016
    7.3
    High

    CVE-2016-0025

    Last Modified: 12 Apr 2025

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, Office Web Apps Server 2013 SP1, and Office Online Server allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-0199

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0200 and CVE-2016-3211.

    Published: 16 Jun 2016
    6.5
    Medium

    CVE-2016-3198

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3203

    Last Modified: 12 Apr 2025

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows PDF Remote Code Execution Vulnerability."

    Published: 16 Jun 2016
    7.5
    High

    CVE-2016-3205

    Last Modified: 12 Apr 2025

    The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3206 and CVE-2016-3207.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3210

    Last Modified: 12 Apr 2025

    The Microsoft (1) JScript and (2) VBScript engines, as used in Internet Explorer 11, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3211

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0199 and CVE-2016-0200.

    Published: 16 Jun 2016
    6.1
    Medium

    CVE-2016-3212

    Last Modified: 12 Apr 2025

    The XSS Filter in Microsoft Internet Explorer 9 through 11 does not properly identify JavaScript, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site, aka "Internet Explorer XSS Filter Vulnerability."

    Published: 16 Jun 2016
    5.5
    Medium

    CVE-2016-3215

    Last Modified: 12 Apr 2025

    Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF document, aka "Windows PDF Information Disclosure Vulnerability," a different vulnerability than CVE-2016-3201.

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3219

    Last Modified: 12 Apr 2025

    The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3222

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3225

    Last Modified: 12 Apr 2025

    The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application that forwards an authentication request to an unintended service, aka "Windows SMB Server Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    6.5
    Medium

    CVE-2016-3226

    Last Modified: 12 Apr 2025

    Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, aka "Active Directory Denial of Service Vulnerability."

    Published: 16 Jun 2016
    7.3
    High

    CVE-2016-3233

    Last Modified: 12 Apr 2025

    Microsoft Excel 2007 SP3, Excel 2010 SP2, and Office Compatibility Pack SP3 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 16 Jun 2016
    9.8
    Critical

    CVE-2016-3236

    Last Modified: 12 Apr 2025

    The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mishandles proxy discovery, which allows remote attackers to redirect network traffic via unspecified vectors, aka "Windows WPAD Proxy Discovery Elevation of Privilege Vulnerability."

    Published: 16 Jun 2016
    7.8
    High

    CVE-2016-3235

    Last Modified: 22 Apr 2026

    Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-3214

    Last Modified: 12 Apr 2025

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3199.

    Published: 16 Jun 2016
    4.3
    Medium

    CVE-2016-3216

    Last Modified: 12 Apr 2025

    GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to bypass the ASLR protection mechanism via unspecified vectors, aka "Windows Graphics Component Information Disclosure Vulnerability."

    Published: 16 Jun 2016
    4.3
    Medium

    CVE-2016-1000022

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10539. Reason: This candidate is a duplicate of CVE-2016-10539. Notes: All CVE users should reference CVE-2016-10539 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-1704

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.103 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 16 Jun 2016
    8.8
    High

    CVE-2016-5314

    Last Modified: 21 Nov 2024

    Buffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TIFF image, as demonstrated by overwriting the vgetparent function pointer with rgb2ycbcr.

    Published: 15 Jun 2016
    6.5
    Medium

    CVE-2016-5321

    Last Modified: 20 Apr 2025

    The DumpModeDecode function in libtiff 4.0.6 and earlier allows attackers to cause a denial of service (invalid read and crash) via a crafted tiff image.

    Published: 15 Jun 2016
    6.7
    Medium

    CVE-2016-6351

    Last Modified: 12 Apr 2025

    The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.

    Published: 15 Jun 2016
    6.5
    Medium

    CVE-2016-5316

    Last Modified: 20 Apr 2025

    Out-of-bounds read in the PixarLogCleanup function in tif_pixarlog.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application by sending a crafted TIFF image to the rgb2ycbcr tool.

    Published: 15 Jun 2016
    6.5
    Medium

    CVE-2016-5317

    Last Modified: 20 Apr 2025

    Buffer overflow in the PixarLogDecode function in libtiff.so in the PixarLogDecode function in libtiff 4.0.6 and earlier, as used in GNOME nautilus, allows attackers to cause a denial of service attack (crash) via a crafted TIFF file.

    Published: 15 Jun 2016
    6.3
    Medium

    CVE-2016-5320

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-5314. Reason: This candidate is a reservation duplicate of CVE-2016-5314. Notes: All CVE users should reference CVE-2016-5314 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 15 Jun 2016
    7.5
    High

    CVE-2016-5323

    Last Modified: 20 Apr 2025

    The _TIFFFax3fillruns function in libtiff before 4.0.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted Tiff image.

    Published: 15 Jun 2016
    5.5
    Medium

    CVE-2016-4470

    Last Modified: 12 Apr 2025

    The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.

    Published: 15 Jun 2016
    5.5
    Medium

    CVE-2016-5315

    Last Modified: 20 Apr 2025

    The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.

    Published: 15 Jun 2016
    5.5
    Medium

    CVE-2016-5322

    Last Modified: 20 Apr 2025

    The setByteArray function in tif_dir.c in libtiff 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tiff image.

    Published: 15 Jun 2016
    9.8
    Critical

    CVE-2016-5365

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands with root privileges via unspecified vectors, aka HWPSIRT-2016-05051.

    Published: 14 Jun 2016
    7.5
    High

    CVE-2016-5366

    Last Modified: 12 Apr 2025

    Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file injection vulnerability," aka HWPSIRT-2016-05052.

    Published: 14 Jun 2016
    7.5
    High

    CVE-2016-5367

    Last Modified: 12 Apr 2025

    Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWPSIRT-2016-05053.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-4171

    Last Modified: 21 Apr 2026

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4127

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4148

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4166

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-2336

    Last Modified: 20 Apr 2025

    Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-2337

    Last Modified: 20 Apr 2025

    Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval" argument can cause arbitrary code execution.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-2339

    Last Modified: 20 Apr 2025

    An exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In Fiddle::Function.new "initialize" heap buffer "arg_types" allocation is made based on args array length. Specially constructed object passed as element of args array can increase this array size after mentioned allocation and cause heap overflow.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4125

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4130

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4131

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4134

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4135

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-4138

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4139

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4142

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4143

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016