CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-4494

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allows remote attackers to hijack the authentication of unspecified victims for requests that disclose the contents of a configuration file.

    Published: 10 Jun 2016
    5.3
    Medium

    CVE-2016-4495

    Last Modified: 12 Apr 2025

    KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration file via unspecified vectors.

    Published: 10 Jun 2016
    3.3
    Low

    CVE-2016-4516

    Last Modified: 12 Apr 2025

    ABB PCM600 before 2.7 improperly stores the main application password after a password change, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 10 Jun 2016
    6.5
    Medium

    CVE-2016-4524

    Last Modified: 12 Apr 2025

    ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors.

    Published: 10 Jun 2016
    3.3
    Low

    CVE-2016-4527

    Last Modified: 12 Apr 2025

    ABB PCM600 before 2.7 improperly stores PCM600 authentication credentials, which allows local users to obtain sensitive information via unspecified vectors.

    Published: 10 Jun 2016
    7.8
    High

    CVE-2016-1583

    Last Modified: 12 Apr 2025

    The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling.

    Published: 10 Jun 2016
    5.5
    Medium

    CVE-2016-1581

    Last Modified: 12 Apr 2025

    LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and read data from arbitrary containers via unspecified vectors.

    Published: 9 Jun 2016
    5.5
    Medium

    CVE-2016-1582

    Last Modified: 12 Apr 2025

    LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access arbitrary world readable paths in the container directory via unspecified vectors.

    Published: 9 Jun 2016
    7.5
    High

    CVE-2016-4523

    Last Modified: 22 Apr 2026

    The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

    Published: 9 Jun 2016
    9.1
    Critical

    CVE-2016-4510

    Last Modified: 12 Apr 2025

    The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors.

    Published: 9 Jun 2016
    Unknown

    CVE-2015-1797

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 9 Jun 2016
    9.8
    Critical

    CVE-2016-2310

    Last Modified: 12 Apr 2025

    General Electric (GE) Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware before 5.5.0 and ML810, ML3000, and ML3100 switches with firmware before 5.5.0k have hardcoded credentials, which allows remote attackers to modify configuration settings via the web interface.

    Published: 9 Jun 2016
    8.8
    High

    CVE-2016-4370

    Last Modified: 12 Apr 2025

    HPE Project and Portfolio Management Center (PPM) 9.2x and 9.3x before 9.32.0002 allows remote authenticated users to execute arbitrary commands or obtain sensitive information via unspecified vectors.

    Published: 9 Jun 2016
    9.1
    Critical

    CVE-2016-4532

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.

    Published: 9 Jun 2016
    8.8
    High

    CVE-2016-2831

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site.

    Published: 9 Jun 2016
    8.8
    High

    CVE-2016-4971

    Last Modified: 12 Apr 2025

    GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

    Published: 9 Jun 2016
    7.5
    High

    CVE-2016-5360

    Last Modified: 12 Apr 2025

    HAproxy 1.6.x before 1.6.6, when a deny comes from a reqdeny rule, allows remote attackers to cause a denial of service (uninitialized memory access and crash) or possibly have unspecified other impact via unknown vectors.

    Published: 9 Jun 2016
    6.1
    Medium

    CVE-2016-6209

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Nagios.

    Published: 9 Jun 2016
    8.1
    High

    CVE-2016-2020

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

    Published: 8 Jun 2016
    9.1
    Critical

    CVE-2016-2029

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358.

    Published: 8 Jun 2016
    8
    High

    CVE-2015-8798

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 8 Jun 2016
    7.3
    High

    CVE-2015-8800

    Last Modified: 12 Apr 2025

    Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allow remote authenticated users to conduct argument-injection attacks by leveraging certain named-pipe access.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2019

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-2027

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2028

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4357.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-4357

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028.

    Published: 8 Jun 2016
    8.8
    High

    CVE-2015-8157

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 8 Jun 2016
    7.6
    High

    CVE-2015-8799

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and 6.6 before MP1, and Data Center Security: Server Advanced Server and Agents (DCS:SA) through 6.6 MP1 allows remote authenticated users to write update-package data to arbitrary agent locations via unspecified vectors.

    Published: 8 Jun 2016
    8.4
    High

    CVE-2016-4364

    Last Modified: 12 Apr 2025

    HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-4365

    Last Modified: 12 Apr 2025

    HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-1405

    Last Modified: 12 Apr 2025

    libclamav in ClamAV (aka Clam AntiVirus), as used in Advanced Malware Protection (AMP) on Cisco Email Security Appliance (ESA) devices before 9.7.0-125 and Web Security Appliance (WSA) devices before 9.0.1-135 and 9.1.x before 9.1.1-041, allows remote attackers to cause a denial of service (AMP process restart) via a crafted document, aka Bug IDs CSCuv78533 and CSCuw60503.

    Published: 8 Jun 2016
    7.8
    High

    CVE-2016-1418

    Last Modified: 12 Apr 2025

    Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root access via crafted CLI command parameters, aka Bug ID CSCuy64037.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2017

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030.

    Published: 8 Jun 2016
    9.1
    Critical

    CVE-2016-2018

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2021

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2022, and CVE-2016-2030.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2022

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2030.

    Published: 8 Jun 2016
    9.8
    Critical

    CVE-2016-2024

    Last Modified: 12 Apr 2025

    HPE Insight Control before 7.5.1 allow remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-2026

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-2030

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2022.

    Published: 8 Jun 2016
    6.1
    Medium

    CVE-2016-2078

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Client in VMware vCenter Server 5.1 before update 3d, 5.5 before update 3d, and 6.0 before update 2 on Windows allows remote attackers to inject arbitrary web script or HTML via the flashvars parameter.

    Published: 8 Jun 2016
    9.8
    Critical

    CVE-2016-4359

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-4361

    Last Modified: 12 Apr 2025

    HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allow remote attackers to cause a denial of service via unspecified vectors.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-4362

    Last Modified: 12 Apr 2025

    HPE Insight Control server deployment allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.

    Published: 8 Jun 2016
    6.1
    Medium

    CVE-2016-4363

    Last Modified: 12 Apr 2025

    HPE Insight Control server deployment allows remote attackers to modify data via unspecified vectors.

    Published: 8 Jun 2016
    9.8
    Critical

    CVE-2016-4368

    Last Modified: 12 Apr 2025

    HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 8 Jun 2016
    8.8
    High

    CVE-2016-4369

    Last Modified: 12 Apr 2025

    HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 8 Jun 2016
    9.8
    Critical

    CVE-2016-5108

    Last Modified: 12 Apr 2025

    Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.

    Published: 8 Jun 2016
    8.1
    High

    CVE-2016-4358

    Last Modified: 12 Apr 2025

    HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2029.

    Published: 8 Jun 2016
    9.1
    Critical

    CVE-2016-4360

    Last Modified: 12 Apr 2025

    web/admin/data.js in the Performance Center Virtual Table Server (VTS) component in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 do not restrict file paths sent to an unlink call, which allows remote attackers to delete arbitrary files via the path parameter to data/import_csv, aka ZDI-CAN-3555.

    Published: 8 Jun 2016
    9.8
    Critical

    CVE-2016-4366

    Last Modified: 12 Apr 2025

    HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.

    Published: 8 Jun 2016