CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-4785

    Last Modified: 12 Apr 2025

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module : All versions < V1.03; Firmware variant IEC 104 for EN100 Ethernet module : All versions < V1.21; EN100 Ethernet module included in SIPROTEC Merging Unit 6MU80 : All versions < 1.02.02. The integrated web server (port 80/tcp) of the affected devices could allow remote attackers to obtain a limited amount of device memory content if network access was obtained. This vulnerability only affects EN100 Ethernet module included in SIPROTEC4 and SIPROTEC Compact devices.

    Published: 31 May 2016
    9.8
    Critical

    CVE-2016-3087

    Last Modified: 12 Apr 2025

    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via vectors related to an ! (exclamation mark) operator to the REST Plugin.

    Published: 31 May 2016
    5.3
    Medium

    CVE-2016-3093

    Last Modified: 12 Apr 2025

    Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to cause a denial of service (block access to a web site) via unspecified vectors.

    Published: 31 May 2016
    8.6
    High

    CVE-2016-1951

    Last Modified: 12 Apr 2025

    Multiple integer overflows in io/prprf.c in Mozilla Netscape Portable Runtime (NSPR) before 4.12 allow remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long string to a PR_*printf function.

    Published: 31 May 2016
    7.5
    High

    CVE-2016-4450

    Last Modified: 12 Apr 2025

    os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.

    Published: 31 May 2016
    7.5
    High

    CVE-2016-4457

    Last Modified: 20 Apr 2025

    CloudForms Management Engine before 5.8 includes a default SSL/TLS certificate.

    Published: 31 May 2016
    4.4
    Medium

    CVE-2016-5238

    Last Modified: 12 Apr 2025

    The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from the information transfer buffer in non-DMA mode.

    Published: 31 May 2016
    5.9
    Medium

    CVE-2016-0907

    Last Modified: 12 Apr 2025

    EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS 8.0.x before 8.0.0.1, does not require SMB signing within a DCERPC session over ncacn_np, which allows man-in-the-middle attackers to spoof SMB clients by modifying the client-server data stream, a similar issue to CVE-2016-2115.

    Published: 30 May 2016
    9.8
    Critical

    CVE-2016-1999

    Last Modified: 12 Apr 2025

    The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 30 May 2016
    5.5
    Medium

    CVE-2016-2023

    Last Modified: 12 Apr 2025

    HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.

    Published: 30 May 2016
    7.5
    High

    CVE-2016-2025

    Last Modified: 12 Apr 2025

    HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components.

    Published: 30 May 2016
    6.5
    Medium

    CVE-2016-2311

    Last Modified: 12 Apr 2025

    Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks ServSensor Contact with firmware before SP473 allow remote authenticated users to discover administrator and user passwords via unspecified vectors.

    Published: 30 May 2016
    7.2
    High

    CVE-2016-2309

    Last Modified: 12 Apr 2025

    iRZ RUH2 before 2b does not validate firmware patches, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

    Published: 30 May 2016
    7.8
    High

    CVE-2016-4118

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors.

    Published: 30 May 2016
    8.1
    High

    CVE-2016-7412

    Last Modified: 12 Apr 2025

    ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allows remote MySQL servers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted field metadata.

    Published: 30 May 2016
    7.8
    High

    CVE-2016-5338

    Last Modified: 12 Apr 2025

    The (1) esp_reg_read and (2) esp_reg_write functions in hw/scsi/esp.c in QEMU allow local guest OS administrators to cause a denial of service (QEMU process crash) or execute arbitrary code on the QEMU host via vectors related to the information transfer buffer.

    Published: 30 May 2016
    9.8
    Critical

    CVE-2016-4800

    Last Modified: 20 Apr 2025

    The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints via a URL with certain escaped characters, related to backslashes.

    Published: 30 May 2016
    5.5
    Medium

    CVE-2016-5102

    Last Modified: 20 Apr 2025

    Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (segmentation fault) via a crafted gif file.

    Published: 30 May 2016
    4.4
    Medium

    CVE-2016-4453

    Last Modified: 12 Apr 2025

    The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command.

    Published: 30 May 2016
    6
    Medium

    CVE-2016-4454

    Last Modified: 12 Apr 2025

    The vmsvga_fifo_read_raw function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to obtain sensitive host memory information or cause a denial of service (QEMU process crash) by changing FIFO registers and issuing a VGA command, which triggers an out-of-bounds read.

    Published: 30 May 2016
    7.5
    High

    CVE-2016-1404

    Last Modified: 12 Apr 2025

    Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by sniffing network traffic to an Autosupport server and leveraging knowledge of this key from another installation, aka Bug ID CSCur85504.

    Published: 29 May 2016
    7.5
    High

    CVE-2016-1409

    Last Modified: 12 Apr 2025

    The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows remote attackers to cause a denial of service (packet-processing outage) via crafted ND messages, aka Bug ID CSCuz66542, as exploited in the wild in May 2016.

    Published: 29 May 2016
    9.8
    Critical

    CVE-2016-5118

    Last Modified: 12 Apr 2025

    The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.

    Published: 29 May 2016
    8.6
    High

    CVE-2016-6250

    Last Modified: 12 Apr 2025

    Integer overflow in the ISO9660 writer in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via vectors related to verifying filename lengths when writing an ISO9660 archive, which trigger a buffer overflow.

    Published: 29 May 2016
    9.1
    Critical

    CVE-2016-5116

    Last Modified: 12 Apr 2025

    gd_xbm.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in certain custom PHP 5.5.x configurations, allows context-dependent attackers to obtain sensitive information from process memory or cause a denial of service (stack-based buffer under-read and application crash) via a long name.

    Published: 29 May 2016
    5.5
    Medium

    CVE-2016-10066

    Last Modified: 20 Apr 2025

    Buffer overflow in the ReadVIFFImage function in coders/viff.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a crafted file.

    Published: 29 May 2016
    5.5
    Medium

    CVE-2016-10069

    Last Modified: 20 Apr 2025

    coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.

    Published: 29 May 2016
    7.5
    High

    CVE-2016-10067

    Last Modified: 20 Apr 2025

    magick/memory.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via vectors involving "too many exceptions," which trigger a buffer overflow.

    Published: 29 May 2016
    6.5
    Medium

    CVE-2016-1379

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 9.0 through 9.5.1 mishandles IPsec error processing, which allows remote authenticated users to cause a denial of service (memory consumption) via crafted (1) LAN-to-LAN or (2) Remote Access VPN tunnel packets, aka Bug ID CSCuv70576.

    Published: 28 May 2016
    7.5
    High

    CVE-2016-1410

    Last Modified: 12 Apr 2025

    Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or (2) hosting a meeting, aka Bug ID CSCux84312.

    Published: 28 May 2016
    6.5
    Medium

    CVE-2016-1413

    Last Modified: 12 Apr 2025

    The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517.

    Published: 28 May 2016
    7.8
    High

    CVE-2016-2175

    Last Modified: 12 Apr 2025

    Apache PDFBox before 1.8.12 and 2.x before 2.0.1 does not properly initialize the XML parsers, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted PDF.

    Published: 27 May 2016
    5.9
    Medium

    CVE-2016-3094

    Last Modified: 12 Apr 2025

    PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a denial of service (broker termination) via a crafted authentication attempt, which triggers an uncaught exception.

    Published: 27 May 2016
    9.1
    Critical

    CVE-2016-4432

    Last Modified: 12 Apr 2025

    The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.

    Published: 27 May 2016
    7.8
    High

    CVE-2016-3680

    Last Modified: 12 Apr 2025

    Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (crash) or possibly gain privileges via a crafted application, aka HWPSIRT-2016-03020.

    Published: 26 May 2016
    7.8
    High

    CVE-2016-3681

    Last Modified: 12 Apr 2025

    Buffer overflow in the Wi-Fi driver in Huawei Mate 8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows attackers to cause a denial of service (crash) or possibly gain privileges via a crafted application, aka HWPSIRT-2016-03021.

    Published: 26 May 2016
    6.1
    Medium

    CVE-2015-7360

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreatingReport parameter to csearch/report/export/; the (3) id parameter to analysis/detail/download/screenshot; or vectors related to (4) "Fortiview threats by users search filtered by vdom" or (5) "PCAP file download generated by the VM scan feature."

    Published: 26 May 2016
    6.5
    Medium

    CVE-2016-1385

    Last Modified: 12 Apr 2025

    The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by leveraging (1) administrative access or (2) Clientless SSL VPN access to provide a crafted XML document, aka Bug ID CSCut14209.

    Published: 26 May 2016
    10
    Critical

    CVE-2016-4787

    Last Modified: 12 Apr 2025

    Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.

    Published: 26 May 2016
    6.1
    Medium

    CVE-2016-4789

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 May 2016
    7.5
    High

    CVE-2016-4021

    Last Modified: 12 Apr 2025

    The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.

    Published: 26 May 2016
    4.7
    Medium

    CVE-2016-2784

    Last Modified: 12 Apr 2025

    CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

    Published: 26 May 2016
    7.5
    High

    CVE-2016-4786

    Last Modified: 12 Apr 2025

    Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

    Published: 26 May 2016
    5.5
    Medium

    CVE-2016-4790

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 May 2016
    8.6
    High

    CVE-2016-4791

    Last Modified: 12 Apr 2025

    The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.

    Published: 26 May 2016
    5.3
    Medium

    CVE-2016-4792

    Last Modified: 12 Apr 2025

    Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.

    Published: 26 May 2016
    5.8
    Medium

    CVE-2016-4788

    Last Modified: 12 Apr 2025

    Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.

    Published: 26 May 2016
    4.4
    Medium

    CVE-2016-7097

    Last Modified: 12 Apr 2025

    The filesystem implementation in the Linux kernel through 4.8.2 preserves the setgid bit during a setxattr call, which allows local users to gain group privileges by leveraging the existence of a setgid program with restrictions on execute permissions.

    Published: 26 May 2016
    7.8
    High

    CVE-2016-4434

    Last Modified: 20 Apr 2025

    Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External Entity (XXE) attacks via vectors involving (1) spreadsheets in OOXML files and (2) XMP metadata in PDF and other file formats, a related issue to CVE-2016-2175.

    Published: 26 May 2016
    7.8
    High

    CVE-2016-1886

    Last Modified: 12 Apr 2025

    Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."

    Published: 25 May 2016