CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-4367

    Last Modified: 12 Apr 2025

    The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 8 Jun 2016
    8.8
    High

    CVE-2016-2819

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

    Published: 8 Jun 2016
    8.8
    High

    CVE-2016-2828

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-2821

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor.

    Published: 8 Jun 2016
    8.8
    High

    CVE-2016-2818

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 8 Jun 2016
    6.5
    Medium

    CVE-2016-2822

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.

    Published: 8 Jun 2016
    7.5
    High

    CVE-2016-4545

    Last Modified: 12 Apr 2025

    Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Traffic Management Microkernel restart) via an SSL alert during the handshake.

    Published: 7 Jun 2016
    7.8
    High

    CVE-2015-5723

    Last Modified: 12 Apr 2025

    Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute arbitrary PHP code with additional privileges by leveraging an application with the umask set to 0 and that executes cache entries as code.

    Published: 7 Jun 2016
    8.1
    High

    CVE-2015-7611

    Last Modified: 12 Apr 2025

    Apache James Server 2.3.2, when configured with file-based user repositories, allows attackers to execute arbitrary system commands via unspecified vectors.

    Published: 7 Jun 2016
    9.8
    Critical

    CVE-2015-7695

    Last Modified: 12 Apr 2025

    The PDO adapters in Zend Framework before 1.12.16 do not filer null bytes in SQL statements, which allows remote attackers to execute arbitrary SQL commands via a crafted query.

    Published: 7 Jun 2016
    8.8
    High

    CVE-2016-2335

    Last Modified: 12 Apr 2025

    The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or execute arbitrary code via the PartitionRef field in the Long Allocation Descriptor in a UDF file.

    Published: 7 Jun 2016
    8.8
    High

    CVE-2016-2815

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 7 Jun 2016
    4.3
    Medium

    CVE-2016-2832

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.

    Published: 7 Jun 2016
    8.8
    High

    CVE-2016-2834

    Last Modified: 12 Apr 2025

    Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5355

    Last Modified: 12 Apr 2025

    wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 7 Jun 2016
    6.1
    Medium

    CVE-2016-2833

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

    Published: 7 Jun 2016
    7.5
    High

    CVE-2016-4970

    Last Modified: 20 Apr 2025

    handler/ssl/OpenSslEngine.java in Netty 4.0.x before 4.0.37.Final and 4.1.x before 4.1.1.Final allows remote attackers to cause a denial of service (infinite loop).

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5356

    Last Modified: 12 Apr 2025

    wiretap/cosine.c in the CoSine file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 7 Jun 2016
    8.1
    High

    CVE-2016-1181

    Last Modified: 12 Apr 2025

    ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.

    Published: 7 Jun 2016
    8.2
    High

    CVE-2016-1182

    Last Modified: 12 Apr 2025

    ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.

    Published: 7 Jun 2016
    6.5
    Medium

    CVE-2016-2825

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

    Published: 7 Jun 2016
    6.5
    Medium

    CVE-2016-2829

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or the geolocation permission.

    Published: 7 Jun 2016
    5.5
    Medium

    CVE-2016-5337

    Last Modified: 12 Apr 2025

    The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information.

    Published: 7 Jun 2016
    7.5
    High

    CVE-2016-5350

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-dcerpc-spoolss.c in the SPOOLS component in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles unexpected offsets, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5351

    Last Modified: 12 Apr 2025

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5352

    Last Modified: 12 Apr 2025

    epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.4 mishandles certain length values, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5353

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5354

    Last Modified: 12 Apr 2025

    The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5357

    Last Modified: 12 Apr 2025

    wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5358

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2016
    5.9
    Medium

    CVE-2016-5359

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-wbxml.c in the WBXML dissector in Wireshark 1.12.x before 1.12.12 mishandles offsets, which allows remote attackers to cause a denial of service (integer overflow and infinite loop) via a crafted packet.

    Published: 7 Jun 2016
    9.8
    Critical

    CVE-2016-0749

    Last Modified: 12 Apr 2025

    The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow.

    Published: 6 Jun 2016
    7.1
    High

    CVE-2016-2150

    Last Modified: 12 Apr 2025

    SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to CVE-2015-5261.

    Published: 6 Jun 2016
    7.8
    High

    CVE-2016-2061

    Last Modified: 12 Apr 2025

    Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overflow and memory corruption) via a crafted application that triggers an msm_isp_axi_create_stream call.

    Published: 6 Jun 2016
    7.5
    High

    CVE-2016-4456

    Last Modified: 20 Apr 2025

    The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.

    Published: 6 Jun 2016
    5.4
    Medium

    CVE-2016-1229

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HumHub 0.20.0-beta.1 through 0.20.1 and 1.0.0-beta before 1.0.0-beta.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2016
    2.7
    Low

    CVE-2016-1212

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in futomi MP Form Mail CGI Professional Edition 3.2.3 and earlier allows remote authenticated administrators to read arbitrary files via unspecified vectors.

    Published: 5 Jun 2016
    6.1
    Medium

    CVE-2016-1222

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Kobe Beauty php-contact-form before 2016-05-18 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.

    Published: 5 Jun 2016
    6.1
    Medium

    CVE-2016-1230

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in NTT PC Communications WebARENA Service formmail before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Jun 2016
    7.8
    High

    CVE-2016-10050

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.9.4-8 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.

    Published: 5 Jun 2016
    6.1
    Medium

    CVE-2016-4812

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Markdown on Save Improved plugin before 2.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2016
    6.1
    Medium

    CVE-2016-1211

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Epoch Web Mailing List 0.31 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Jun 2016
    7.8
    High

    CVE-2016-1403

    Last Modified: 12 Apr 2025

    CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug ID CSCuz03005.

    Published: 4 Jun 2016
    6.7
    Medium

    CVE-2016-0908

    Last Modified: 12 Apr 2025

    EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leveraging administrative privileges.

    Published: 4 Jun 2016
    7.8
    High

    CVE-2016-1390

    Last Modified: 12 Apr 2025

    Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow local users to obtain root access via crafted CLI input, aka Bug ID CSCuy21892.

    Published: 4 Jun 2016
    8.8
    High

    CVE-2016-1391

    Last Modified: 12 Apr 2025

    Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) allow remote authenticated users to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuy21889.

    Published: 4 Jun 2016
    8.8
    High

    CVE-2016-4563

    Last Modified: 12 Apr 2025

    The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the BezierQuantum value and certain strokes data, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 4 Jun 2016
    8.8
    High

    CVE-2016-4562

    Last Modified: 12 Apr 2025

    The DrawDashPolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles calculations of certain vertices integer data, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 4 Jun 2016
    6.5
    Medium

    CVE-2016-10060

    Last Modified: 20 Apr 2025

    The ConcatenateImages function in MagickWand/magick-cli.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 4 Jun 2016
    6.5
    Medium

    CVE-2016-10061

    Last Modified: 20 Apr 2025

    The ReadGROUP4Image function in coders/tiff.c in ImageMagick before 7.0.1-10 does not check the return value of the fputc function, which allows remote attackers to cause a denial of service (crash) via a crafted image file.

    Published: 4 Jun 2016