CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-4146

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4147

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4150

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4151

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4154

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4155

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    6.5
    Medium

    CVE-2016-5009

    Last Modified: 12 Apr 2025

    The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph monitor crash) via an (1) empty or (2) crafted prefix.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-5687

    Last Modified: 12 Apr 2025

    The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read.

    Published: 14 Jun 2016
    8.1
    High

    CVE-2016-5688

    Last Modified: 12 Apr 2025

    The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-5689

    Last Modified: 12 Apr 2025

    The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL pointer checks.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-5690

    Last Modified: 12 Apr 2025

    The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table.

    Published: 14 Jun 2016
    9.8
    Critical

    CVE-2016-5691

    Last Modified: 12 Apr 2025

    The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.

    Published: 14 Jun 2016
    7.8
    High

    CVE-2016-7062

    Last Modified: 20 Apr 2025

    rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4122

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4123

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4124

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4128

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4129

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4132

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4133

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4136

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4137

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4140

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4141

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4144

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4145

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4149

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4152

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4153

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    8.8
    High

    CVE-2016-4156

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.

    Published: 14 Jun 2016
    7.5
    High

    CVE-2014-9773

    Last Modified: 12 Apr 2025

    modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.

    Published: 13 Jun 2016
    7.5
    High

    CVE-2016-4414

    Last Modified: 12 Apr 2025

    The onReadyRead function in core/coreauthhandler.cpp in Quassel before 0.12.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via invalid handshake data.

    Published: 13 Jun 2016
    7.5
    High

    CVE-2016-4478

    Last Modified: 12 Apr 2025

    Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.

    Published: 13 Jun 2016
    8.1
    High

    CVE-2016-5234

    Last Modified: 12 Apr 2025

    Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.

    Published: 13 Jun 2016
    7.5
    High

    CVE-2016-1542

    Last Modified: 12 Apr 2025

    The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and enumerate users by sending an action packet to xmlrpc after an authorization failure.

    Published: 13 Jun 2016
    7.5
    High

    CVE-2016-1543

    Last Modified: 12 Apr 2025

    The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers to bypass authorization and reset arbitrary user passwords by sending an action packet to xmlrpc after an authorization failure.

    Published: 13 Jun 2016
    7.2
    High

    CVE-2016-2174

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the policy admin tool in Apache Ranger before 0.5.3 allows remote authenticated administrators to execute arbitrary SQL commands via the eventTime parameter to service/plugins/policies/eventTime.

    Published: 13 Jun 2016
    6.1
    Medium

    CVE-2016-3670

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1 allows remote attackers to inject arbitrary web script or HTML via the FirstName field.

    Published: 13 Jun 2016
    6.5
    Medium

    CVE-2016-3677

    Last Modified: 12 Apr 2025

    The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.

    Published: 13 Jun 2016
    5.5
    Medium

    CVE-2016-4005

    Last Modified: 12 Apr 2025

    The Huawei Hilink App application before 3.19.2 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008.

    Published: 13 Jun 2016
    9.8
    Critical

    CVE-2016-5302

    Last Modified: 12 Apr 2025

    Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the management network to "compromise" a host by leveraging credentials for an Active Directory account.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2826

    Last Modified: 12 Apr 2025

    The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

    Published: 13 Jun 2016
    8.8
    High

    CVE-2016-2824

    Last Modified: 12 Apr 2025

    The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact by triggering use of a WebGL shader that writes to an array.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2484

    Last Modified: 12 Apr 2025

    libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not validate OMX buffer sizes for the GSM and G711 codecs, which allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 27793163.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2492

    Last Modified: 12 Apr 2025

    The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 28085410.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2494

    Last Modified: 12 Apr 2025

    Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28085658.

    Published: 13 Jun 2016
    5.5
    Medium

    CVE-2016-2500

    Last Modified: 12 Apr 2025

    Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a crafted application, aka internal bug 19285814.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2469

    Last Modified: 12 Apr 2025

    The Qualcomm sound driver in Android before 2016-06-01 on Nexus 5, 6, and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 27531992.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2470

    Last Modified: 12 Apr 2025

    The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27662174.

    Published: 13 Jun 2016
    7.8
    High

    CVE-2016-2475

    Last Modified: 12 Apr 2025

    The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allows attackers to gain privileges for certain system calls via a crafted application, aka internal bug 26425765.

    Published: 13 Jun 2016