CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-4325

    Last Modified: 12 Apr 2025

    Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.

    Published: 14 May 2016
    5.5
    Medium

    CVE-2016-2016

    Last Modified: 12 Apr 2025

    Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.

    Published: 14 May 2016
    7.5
    High

    CVE-2016-1208

    Last Modified: 12 Apr 2025

    The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

    Published: 14 May 2016
    6.5
    Medium

    CVE-2015-8530

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows remote authenticated users to execute arbitrary code via a long argument.

    Published: 14 May 2016
    9.8
    Critical

    CVE-2016-1209

    Last Modified: 12 Apr 2025

    The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.

    Published: 14 May 2016
    7.1
    High

    CVE-2016-2015

    Last Modified: 12 Apr 2025

    HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

    Published: 14 May 2016
    7.8
    High

    CVE-2015-8156

    Last Modified: 12 Apr 2025

    Unquoted Windows search path vulnerability in EEDService in Symantec Endpoint Encryption (SEE) 11.x before 11.1.1 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory, as demonstrated by program.exe.

    Published: 14 May 2016
    7.5
    High

    CVE-2016-1399

    Last Modified: 12 Apr 2025

    The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allows remote attackers to cause a denial of service (packet data corruption) via crafted IPv4 ICMP packets, aka Bug ID CSCuy13431.

    Published: 14 May 2016
    6.2
    Medium

    CVE-2015-8872

    Last Modified: 12 Apr 2025

    The set_fat function in fat.c in dosfstools before 4.0 might allow attackers to corrupt a FAT12 filesystem or cause a denial of service (invalid memory read and crash) by writing an odd number of clusters to the third to last entry on a FAT12 filesystem, which triggers an "off-by-two error."

    Published: 14 May 2016
    6.2
    Medium

    CVE-2016-4804

    Last Modified: 12 Apr 2025

    The read_boot function in boot.c in dosfstools before 4.0 allows attackers to cause a denial of service (crash) via a crafted filesystem, which triggers a heap-based buffer overflow in the (1) read_fat function or an out-of-bounds heap read in (2) get_fat function.

    Published: 14 May 2016
    7.5
    High

    CVE-2014-9763

    Last Modified: 12 Apr 2025

    imlib2 before 1.4.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted PNM file.

    Published: 13 May 2016
    8.2
    High

    CVE-2016-3994

    Last Modified: 12 Apr 2025

    The GIF loader in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (application crash) or obtain sensitive information via a crafted image, which triggers an out-of-bounds read.

    Published: 13 May 2016
    7.5
    High

    CVE-2014-9762

    Last Modified: 12 Apr 2025

    imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.

    Published: 13 May 2016
    7.5
    High

    CVE-2014-9764

    Last Modified: 12 Apr 2025

    imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.

    Published: 13 May 2016
    7.5
    High

    CVE-2014-9771

    Last Modified: 12 Apr 2025

    Integer overflow in imlib2 before 1.4.7 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted image, which triggers an invalid read operation.

    Published: 13 May 2016
    5.9
    Medium

    CVE-2015-8099

    Last Modified: 12 Apr 2025

    F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP DNS 12.x before 12.0.0 HF1; BIG-IP Edge Gateway, WebAccelerator, and WOM 11.3.0; BIG-IP GTM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP PSM 11.3.x and 11.4.x before 11.4.1 HF10; Enterprise Manager 3.0.0 through 3.1.1; BIG-IQ Cloud and BIG-IQ Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 on the 3900, 6900, 8900, 8950, 11000, 11050, PB100 and PB200 platforms, when software SYN cookies are configured on virtual servers, allow remote attackers to cause a denial of service (High-Speed Bridge hang) via an invalid TCP segment.

    Published: 13 May 2016
    7.8
    High

    CVE-2015-8312

    Last Modified: 12 Apr 2025

    Off-by-one error in afs_pioctl.c in OpenAFS before 1.6.16 might allow local users to cause a denial of service (memory overwrite and system crash) via a pioctl with an input buffer size of 4096 bytes.

    Published: 13 May 2016
    6.5
    Medium

    CVE-2016-2860

    Last Modified: 12 Apr 2025

    The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups as administrators by leveraging mishandling of the creator ID.

    Published: 13 May 2016
    7.5
    High

    CVE-2016-3993

    Last Modified: 12 Apr 2025

    Off-by-one error in the __imlib_MergeUpdate function in lib/updates.c in imlib2 before 1.4.9 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted coordinates.

    Published: 13 May 2016
    9.8
    Critical

    CVE-2016-4024

    Last Modified: 12 Apr 2025

    Integer overflow in imlib2 before 1.4.9 on 32-bit platforms allows remote attackers to execute arbitrary code via large dimensions in an image, which triggers an out-of-bounds heap memory write operation.

    Published: 13 May 2016
    5.3
    Medium

    CVE-2016-4536

    Last Modified: 12 Apr 2025

    The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) ListAddrByAttributes structures, which might allow remote attackers to obtain sensitive memory information by leveraging access to RPC call traffic.

    Published: 13 May 2016
    7.5
    High

    CVE-2011-5326

    Last Modified: 12 Apr 2025

    imlib2 before 1.4.9 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) by drawing a 2x1 ellipse.

    Published: 13 May 2016
    7.5
    High

    CVE-2015-5726

    Last Modified: 12 Apr 2025

    The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via an empty BIT STRING in ASN.1 data.

    Published: 13 May 2016
    9.8
    Critical

    CVE-2016-1578

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.

    Published: 13 May 2016
    7.5
    High

    CVE-2016-2850

    Last Modified: 12 Apr 2025

    Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

    Published: 13 May 2016
    7.5
    High

    CVE-2015-5727

    Last Modified: 12 Apr 2025

    The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors, related to a length field.

    Published: 13 May 2016
    9.8
    Critical

    CVE-2016-1580

    Last Modified: 12 Apr 2025

    The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap with a name starting with "ubuntu-core."

    Published: 13 May 2016
    7.5
    High

    CVE-2014-9742

    Last Modified: 12 Apr 2025

    The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.

    Published: 13 May 2016
    7.5
    High

    CVE-2015-7827

    Last Modified: 12 Apr 2025

    Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.

    Published: 13 May 2016
    9.8
    Critical

    CVE-2016-2195

    Last Modified: 12 Apr 2025

    Integer overflow in the PointGFp constructor in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to overwrite memory and possibly execute arbitrary code via a crafted ECC point, which triggers a heap-based buffer overflow.

    Published: 13 May 2016
    7.5
    High

    CVE-2016-2194

    Last Modified: 12 Apr 2025

    The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspecified input to the OS2ECP function, related to a composite modulus.

    Published: 13 May 2016
    7.5
    High

    CVE-2016-2849

    Last Modified: 12 Apr 2025

    Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.

    Published: 13 May 2016
    9.8
    Critical

    CVE-2016-2196

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.

    Published: 13 May 2016
    10
    Critical

    CVE-2010-5326

    Last Modified: 22 Apr 2026

    The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

    Published: 13 May 2016
    7.8
    High

    CVE-2016-9754

    Last Modified: 12 Apr 2025

    The ring_buffer_resize function in kernel/trace/ring_buffer.c in the profiling subsystem in the Linux kernel before 4.6.1 mishandles certain integer calculations, which allows local users to gain privileges by writing to the /sys/kernel/debug/tracing/buffer_size_kb file.

    Published: 13 May 2016
    5.5
    Medium

    CVE-2014-8181

    Last Modified: 21 Nov 2024

    The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.

    Published: 13 May 2016
    7.1
    High

    CVE-2016-1393

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Cisco Cloud Network Automation Provisioner (CNAP) 1.0 and 1.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy72175.

    Published: 12 May 2016
    4.2
    Medium

    CVE-2016-4499

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (application crash) via unspecified vectors.

    Published: 12 May 2016
    4.2
    Medium

    CVE-2016-4496

    Last Modified: 12 Apr 2025

    Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by triggering a crafted index value, as demonstrated by an integer overflow.

    Published: 12 May 2016
    4.2
    Medium

    CVE-2016-4497

    Last Modified: 12 Apr 2025

    Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

    Published: 12 May 2016
    5.5
    Medium

    CVE-2016-4498

    Last Modified: 12 Apr 2025

    Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 12 May 2016
    6.1
    Medium

    CVE-2016-8639

    Last Modified: 21 Nov 2024

    It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface.

    Published: 12 May 2016
    7.8
    High

    CVE-2016-0758

    Last Modified: 12 Apr 2025

    Integer overflow in lib/asn1_decoder.c in the Linux kernel before 4.6 allows local users to gain privileges via crafted ASN.1 data.

    Published: 12 May 2016
    7.5
    High

    CVE-2016-4809

    Last Modified: 12 Apr 2025

    The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.

    Published: 12 May 2016
    6.5
    Medium

    CVE-2016-5035

    Last Modified: 20 Apr 2025

    The _dwarf_read_line_table_header function in dwarf_line_table_reader.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 12 May 2016
    7.5
    High

    CVE-2016-5036

    Last Modified: 20 Apr 2025

    The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.

    Published: 12 May 2016
    7.5
    High

    CVE-2016-5038

    Last Modified: 20 Apr 2025

    The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.

    Published: 12 May 2016
    6.1
    Medium

    CVE-2016-1236

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) revision.php, (2) log.php, (3) listing.php, and (4) comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a (a) file or (b) directory in a repository.

    Published: 11 May 2016
    9.8
    Critical

    CVE-2016-1054

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1069, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

    Published: 11 May 2016
    9.8
    Critical

    CVE-2016-1069

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1045, CVE-2016-1046, CVE-2016-1047, CVE-2016-1048, CVE-2016-1049, CVE-2016-1050, CVE-2016-1051, CVE-2016-1052, CVE-2016-1053, CVE-2016-1054, CVE-2016-1055, CVE-2016-1056, CVE-2016-1057, CVE-2016-1058, CVE-2016-1059, CVE-2016-1060, CVE-2016-1061, CVE-2016-1065, CVE-2016-1066, CVE-2016-1067, CVE-2016-1068, CVE-2016-1070, CVE-2016-1075, CVE-2016-1094, CVE-2016-1121, CVE-2016-1122, CVE-2016-4102, and CVE-2016-4107.

    Published: 11 May 2016