CVE Feed

    Dashboard / CVE

    2.4
    Low

    CVE-2016-1852

    Last Modified: 12 Apr 2025

    Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1854

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1855, CVE-2016-1856, and CVE-2016-1857.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1855

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1856, and CVE-2016-1857.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1856

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1854, CVE-2016-1855, and CVE-2016-1857.

    Published: 20 May 2016
    8.8
    High

    CVE-2016-1859

    Last Modified: 12 Apr 2025

    The WebKit Canvas implementation in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 20 May 2016
    9.1
    Critical

    CVE-2016-2208

    Last Modified: 12 Apr 2025

    The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.

    Published: 19 May 2016
    5.3
    Medium

    CVE-2016-3703

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/proxy API for a specific pod, which allows remote attackers to access API credentials in the web browser localStorage via an access_token in the query parameter.

    Published: 19 May 2016
    8.6
    High

    CVE-2016-5093

    Last Modified: 12 Apr 2025

    The get_icu_value_internal function in ext/intl/locale/locale_methods.c in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7 does not ensure the presence of a '\0' character, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted locale_get_primary_language call.

    Published: 19 May 2016
    6.7
    Medium

    CVE-2016-4439

    Last Modified: 12 Apr 2025

    The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or potentially execute arbitrary code on the QEMU host via unspecified vectors.

    Published: 19 May 2016
    5.5
    Medium

    CVE-2016-10029

    Last Modified: 20 Apr 2025

    The virtio_gpu_set_scanout function in QEMU (aka Quick Emulator) built with Virtio GPU Device emulator support allows local guest OS users to cause a denial of service (out-of-bounds read and process crash) via a scanout id in a VIRTIO_GPU_CMD_SET_SCANOUT command larger than num_scanouts.

    Published: 19 May 2016
    5.3
    Medium

    CVE-2016-3106

    Last Modified: 20 Apr 2025

    Pulp before 2.8.3 creates a temporary directory during CA key generation in an insecure manner.

    Published: 19 May 2016
    8.8
    High

    CVE-2016-3738

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket and gain privileges via vectors related to build-pod.

    Published: 19 May 2016
    6
    Medium

    CVE-2016-4441

    Last Modified: 12 Apr 2025

    The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unspecified vectors, involving an SCSI command.

    Published: 19 May 2016
    Unknown

    CVE-2016-0719

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0718. Reason: This candidate is a reservation duplicate of CVE-2016-0718. Notes: All CVE users should reference CVE-2016-0718 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 May 2016
    9.8
    Critical

    CVE-2016-2077

    Last Modified: 12 Apr 2025

    VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users to gain host OS privileges via unspecified vectors.

    Published: 18 May 2016
    4.9
    Medium

    CVE-2016-0731

    Last Modified: 12 Apr 2025

    The File Browser View in Apache Ambari before 2.2.1 allows remote authenticated administrators to read arbitrary files via a file: URL in the WebHDFS URL configuration.

    Published: 18 May 2016
    3.3
    Low

    CVE-2016-0707

    Last Modified: 12 Apr 2025

    The agent in Apache Ambari before 2.1.2 uses weak permissions for the (1) /var/lib/ambari-agent/data and (2) /var/lib/ambari-agent/keys directories, which allows local users to obtain sensitive information by reading files in the directories.

    Published: 18 May 2016
    6.5
    Medium

    CVE-2016-5032

    Last Modified: 20 Apr 2025

    The dwarf_get_xu_hash_entry function in libdwarf before 20160923 allows remote attackers to cause a denial of service (crash) via a crafted file.

    Published: 18 May 2016
    5.3
    Medium

    CVE-2016-3739

    Last Modified: 12 Apr 2025

    The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote attackers to spoof servers via an arbitrary valid certificate.

    Published: 18 May 2016
    7.8
    High

    CVE-2016-4440

    Last Modified: 12 Apr 2025

    arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access on the host OS, and consequently cause a denial of service (host OS crash) or possibly execute arbitrary code on the host OS, via x2APIC mode.

    Published: 18 May 2016
    7.5
    High

    CVE-2016-4912

    Last Modified: 20 Apr 2025

    The _xrealloc function in xlsp_xmalloc.c in OpenSLP 2.0.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a large number of crafted packets, which triggers a memory allocation failure.

    Published: 18 May 2016
    5.5
    Medium

    CVE-2016-5031

    Last Modified: 20 Apr 2025

    The print_frame_inst_bytes function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 18 May 2016
    6.5
    Medium

    CVE-2016-5033

    Last Modified: 20 Apr 2025

    The print_exprloc_content function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 18 May 2016
    5.9
    Medium

    CVE-2016-4429

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.

    Published: 18 May 2016
    Unknown

    CVE-2016-3719

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 May 2016
    Unknown

    CVE-2016-2189

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-4565. Reason: This candidate is a reservation duplicate of CVE-2016-4565. Notes: All CVE users should reference CVE-2016-4565 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 May 2016
    6.5
    Medium

    CVE-2016-0323

    Last Modified: 12 Apr 2025

    The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.

    Published: 17 May 2016
    5.9
    Medium

    CVE-2016-0306

    Last Modified: 12 Apr 2025

    IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures TLS, which allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors.

    Published: 17 May 2016
    9.8
    Critical

    CVE-2016-0718

    Last Modified: 12 Apr 2025

    Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.

    Published: 17 May 2016
    4.3
    Medium

    CVE-2016-4911

    Last Modified: 12 Apr 2025

    The Fernet Token Provider in OpenStack Identity (Keystone) 9.0.x before 9.0.1 (mitaka) allows remote authenticated users to prevent revocation of a chain of tokens and bypass intended access restrictions by rescoping a token.

    Published: 17 May 2016
    7.8
    High

    CVE-2016-10049

    Last Modified: 20 Apr 2025

    Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.

    Published: 17 May 2016
    8.4
    High

    CVE-2016-4480

    Last Modified: 12 Apr 2025

    The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit at the L4 and L3 page table levels, which might allow local guest OS users to gain privileges via a crafted mapping of memory.

    Published: 17 May 2016
    6.5
    Medium

    CVE-2016-5034

    Last Modified: 20 Apr 2025

    dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file, related to relocation records.

    Published: 17 May 2016
    8.1
    High

    CVE-2016-3698

    Last Modified: 12 Apr 2025

    libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remote attackers to conduct man-in-the-middle attacks or cause a denial of service (network connectivity disruption) by advertising a node as a router from a non-local network.

    Published: 17 May 2016
    8.1
    High

    CVE-2016-3707

    Last Modified: 12 Apr 2025

    The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before 3.10.0-327.22.1 in Red Hat Enterprise Linux for Real Time 7 and other products, allows remote attackers to execute SysRq commands via crafted ICMP Echo Request packets, as demonstrated by a brute-force attack to discover a cookie, or an attack that occurs after reading the local icmp_echo_sysrq file.

    Published: 17 May 2016
    8.6
    High

    CVE-2016-5095

    Last Modified: 12 Apr 2025

    Integer overflow in the php_escape_html_entities_ex function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from a FILTER_SANITIZE_FULL_SPECIAL_CHARS filter_var call. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-5094.

    Published: 17 May 2016
    9.8
    Critical

    CVE-2015-4642

    Last Modified: 12 Apr 2025

    The escapeshellarg function in ext/standard/exec.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 on Windows allows remote attackers to execute arbitrary OS commands via a crafted string to an application that accepts command-line arguments for a call to the PHP system function.

    Published: 16 May 2016
    8.8
    High

    CVE-2016-3072

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in the scoped_search function in app/controllers/katello/api/v2/api_controller.rb in Katello allow remote authenticated users to execute arbitrary SQL commands via the (1) sort_by or (2) sort_order parameter.

    Published: 16 May 2016
    7.1
    High

    CVE-2016-3713

    Last Modified: 12 Apr 2025

    The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call.

    Published: 16 May 2016
    7.8
    High

    CVE-2016-4951

    Last Modified: 12 Apr 2025

    The tipc_nl_publ_dump function in net/tipc/socket.c in the Linux kernel through 4.6 does not verify socket existence, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a dumpit operation.

    Published: 16 May 2016
    5.4
    Medium

    CVE-2016-0390

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 15 May 2016
    7.5
    High

    CVE-2016-0341

    Last Modified: 12 Apr 2025

    IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.

    Published: 15 May 2016
    4.3
    Medium

    CVE-2016-0381

    Last Modified: 12 Apr 2025

    IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value.

    Published: 15 May 2016
    8.1
    High

    CVE-2016-4472

    Last Modified: 12 Apr 2025

    The overflow protection in Expat is removed by compilers with certain optimization settings, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted XML data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-1283 and CVE-2015-2716.

    Published: 15 May 2016
    7.8
    High

    CVE-2016-9806

    Last Modified: 12 Apr 2025

    Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that makes sendmsg system calls, leading to a free operation associated with a new dump that started earlier than anticipated.

    Published: 15 May 2016
    9.4
    Critical

    CVE-2016-2297

    Last Modified: 12 Apr 2025

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature."

    Published: 14 May 2016
    5.4
    Medium

    CVE-2016-1207

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 May 2016
    9.4
    Critical

    CVE-2016-2296

    Last Modified: 12 Apr 2025

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 14 May 2016
    4.3
    Medium

    CVE-2016-1206

    Last Modified: 12 Apr 2025

    The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack.

    Published: 14 May 2016
    9.8
    Critical

    CVE-2016-2298

    Last Modified: 12 Apr 2025

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.

    Published: 14 May 2016