CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-1887

    Last Modified: 12 Apr 2025

    Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.

    Published: 25 May 2016
    6.1
    Medium

    CVE-2016-4575

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the email APP in Huawei PLK smartphones with software AL10C00 before AL10C00B211 and AL10C92 before AL10C92B211; ATH smartphones with software AL00C00 before AL00C00B361, CL00C92 before CL00C92B361, TL00HC01 before TL00HC01B361, and UL00C00 before UL00C00B361; CherryPlus smartphones with software TL00C00 before TL00C00B553, UL00C00 before UL00C00B553, and TL00MC01 before TL00MC01B553; and RIO smartphones with software AL00C00 before AL00C00B360 allows remote attackers to inject arbitrary web script or HTML via an email message.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1380

    Last Modified: 12 Apr 2025

    Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1381

    Last Modified: 12 Apr 2025

    Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an HTTP file-range request for cached content, aka Bug ID CSCuw97270.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1400

    Last Modified: 12 Apr 2025

    Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1407

    Last Modified: 12 Apr 2025

    Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1383

    Last Modified: 12 Apr 2025

    Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consumption) via an unspecified HTTP status code, aka Bug ID CSCur28305.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1382

    Last Modified: 12 Apr 2025

    Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu02529.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1406

    Last Modified: 12 Apr 2025

    The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticated users to bypass intended RBAC restrictions and obtain sensitive information, and consequently gain privileges, via crafted JSON data, aka Bug ID CSCuy12409.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1675

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1679

    Last Modified: 12 Apr 2025

    The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1685

    Last Modified: 12 Apr 2025

    core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1688

    Last Modified: 12 Apr 2025

    The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) via crafted JavaScript code.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1695

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 51.0.2704.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1672

    Last Modified: 12 Apr 2025

    The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1676

    Last Modified: 12 Apr 2025

    extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1677

    Last Modified: 12 Apr 2025

    uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1680

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1681

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1686

    Last Modified: 12 Apr 2025

    The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PDF document.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1689

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1690

    Last Modified: 12 Apr 2025

    The Autofill implementation in Google Chrome before 51.0.2704.63 mishandles the interaction between field updates and JavaScript code that triggers a frame deletion, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site, a different vulnerability than CVE-2016-1701.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1691

    Last Modified: 12 Apr 2025

    Skia, as used in Google Chrome before 51.0.2704.63, mishandles coincidence runs, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted curves, related to SkOpCoincidence.cpp and SkPathOpsCommon.cpp.

    Published: 25 May 2016
    4.4
    Medium

    CVE-2016-5105

    Last Modified: 12 Apr 2025

    The megasas_dcmd_cfg_read function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, uses an uninitialized variable, which allows local guest administrators to read host memory via vectors involving a MegaRAID Firmware Interface (MFI) command.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1673

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1674

    Last Modified: 12 Apr 2025

    The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 25 May 2016
    8.8
    High

    CVE-2016-1678

    Last Modified: 12 Apr 2025

    objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 25 May 2016
    6.1
    Medium

    CVE-2016-1682

    Last Modified: 12 Apr 2025

    The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a ServiceWorker registration.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1683

    Last Modified: 12 Apr 2025

    numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles namespace nodes, which allows remote attackers to cause a denial of service (out-of-bounds heap memory access) or possibly have unspecified other impact via a crafted document.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-1684

    Last Modified: 12 Apr 2025

    numbers.c in libxslt before 1.1.29, as used in Google Chrome before 51.0.2704.63, mishandles the i format token for xsl:number data, which allows remote attackers to cause a denial of service (integer overflow or resource consumption) or possibly have unspecified other impact via a crafted document.

    Published: 25 May 2016
    6.5
    Medium

    CVE-2016-1687

    Last Modified: 12 Apr 2025

    The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors related to extensions.

    Published: 25 May 2016
    5.3
    Medium

    CVE-2016-1692

    Last Modified: 12 Apr 2025

    WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets by a ServiceWorker even when the stylesheet download has an incorrect MIME type, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 25 May 2016
    5.3
    Medium

    CVE-2016-1693

    Last Modified: 12 Apr 2025

    browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Software Removal Tool, which allows remote attackers to spoof the chrome_cleanup_tool.exe (aka CCT) file via a man-in-the-middle attack on an HTTP session.

    Published: 25 May 2016
    5.3
    Medium

    CVE-2016-1694

    Last Modified: 12 Apr 2025

    browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier for remote attackers to spoof web sites via a valid certificate from an arbitrary recognized Certification Authority.

    Published: 25 May 2016
    5
    Medium

    CVE-2016-4451

    Last Modified: 12 Apr 2025

    The (1) Organization and (2) Locations APIs in Foreman before 1.11.3 and 1.12.x before 1.12.0-RC1 allow remote authenticated users with unlimited filters to bypass organization and location restrictions and read or modify data for an arbitrary organization by leveraging knowledge of the id of that organization.

    Published: 25 May 2016
    6
    Medium

    CVE-2016-5106

    Last Modified: 12 Apr 2025

    The megasas_dcmd_set_properties function in hw/scsi/megasas.c in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest administrators to cause a denial of service (out-of-bounds write access) via vectors involving a MegaRAID Firmware Interface (MFI) command.

    Published: 25 May 2016
    6
    Medium

    CVE-2016-5107

    Last Modified: 12 Apr 2025

    The megasas_lookup_frame function in QEMU, when built with MegaRAID SAS 8708EM2 Host Bus Adapter emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds read and crash) via unspecified vectors.

    Published: 25 May 2016
    3.3
    Low

    CVE-2016-4455

    Last Modified: 20 Apr 2025

    The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories.

    Published: 25 May 2016
    7.5
    High

    CVE-2016-5416

    Last Modified: 20 Apr 2025

    389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server 6 through 7, and Red Hat Enterprise Linux Workstation 6 through 7 allows remote attackers to read the default Access Control Instructions.

    Published: 25 May 2016
    6
    Medium

    CVE-2016-4964

    Last Modified: 12 Apr 2025

    The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consumption or QEMU process crash) via vectors involving s->state.

    Published: 24 May 2016
    9.8
    Critical

    CVE-2016-3088

    Last Modified: 21 Apr 2026

    The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

    Published: 24 May 2016
    6.5
    Medium

    CVE-2016-5004

    Last Modified: 20 Apr 2025

    The Content-Encoding HTTP header feature in ws-xmlrpc 3.1.3 as used in Apache Archiva allows remote attackers to cause a denial of service (resource consumption) by decompressing a large file containing zeroes.

    Published: 24 May 2016
    5.5
    Medium

    CVE-2016-5027

    Last Modified: 20 Apr 2025

    dwarf_form.c in libdwarf 20160115 allows remote attackers to cause a denial of service (crash) via a crafted elf file.

    Published: 24 May 2016
    7.8
    High

    CVE-2016-5126

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.

    Published: 24 May 2016
    5.5
    Medium

    CVE-2016-5824

    Last Modified: 20 Apr 2025

    libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.

    Published: 24 May 2016
    4.4
    Medium

    CVE-2016-7091

    Last Modified: 12 Apr 2025

    sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from specially formatted files with elevated privileges provided by sudo.

    Published: 24 May 2016
    7.8
    High

    CVE-2016-5002

    Last Modified: 20 Apr 2025

    XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted DTD.

    Published: 24 May 2016
    9.8
    Critical

    CVE-2016-5003

    Last Modified: 20 Apr 2025

    The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.

    Published: 24 May 2016
    8.1
    High

    CVE-2016-4087

    Last Modified: 12 Apr 2025

    Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enabled, allows remote attackers to cause a denial of service or execute arbitrary code via crafted DNS packets.

    Published: 23 May 2016
    8.8
    High

    CVE-2016-4782

    Last Modified: 12 Apr 2025

    Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent scheme URL attack."

    Published: 23 May 2016