CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2016-1575

    Last Modified: 12 Apr 2025

    The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

    Published: 2 May 2016
    7.8
    High

    CVE-2016-1576

    Last Modified: 12 Apr 2025

    The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an overlayfs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

    Published: 2 May 2016
    8.8
    High

    CVE-2016-1541

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive.

    Published: 2 May 2016
    5.5
    Medium

    CVE-2016-4491

    Last Modified: 20 Apr 2025

    The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once."

    Published: 2 May 2016
    7.5
    High

    CVE-2016-4476

    Last Modified: 12 Apr 2025

    hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attackers to cause a denial of service (daemon outage) via a crafted WPS operation.

    Published: 2 May 2016
    7.8
    High

    CVE-2016-4477

    Last Modified: 12 Apr 2025

    wpa_supplicant 0.4.0 through 2.5 does not reject \n and \r characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.

    Published: 2 May 2016
    6.5
    Medium

    CVE-2016-4425

    Last Modified: 4 Dec 2025

    Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data.

    Published: 1 May 2016
    8.6
    High

    CVE-2016-5094

    Last Modified: 12 Apr 2025

    Integer overflow in the php_html_entities function in ext/standard/html.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a large output string from the htmlspecialchars function.

    Published: 1 May 2016
    5.5
    Medium

    CVE-2016-5240

    Last Modified: 20 Apr 2025

    The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.

    Published: 1 May 2016
    5.3
    Medium

    CVE-2016-1199

    Last Modified: 12 Apr 2025

    The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via unspecified vectors, a different vulnerability than CVE-2016-1200.

    Published: 30 Apr 2016
    10
    Critical

    CVE-2016-1343

    Last Modified: 12 Apr 2025

    The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuy39059.

    Published: 30 Apr 2016
    8.8
    High

    CVE-2016-1111

    Last Modified: 12 Apr 2025

    Double free vulnerability in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code via a crafted Graphics State dictionary.

    Published: 30 Apr 2016
    6.3
    Medium

    CVE-2016-1200

    Last Modified: 12 Apr 2025

    The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2016-1199.

    Published: 30 Apr 2016
    8.8
    High

    CVE-2016-1201

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.

    Published: 30 Apr 2016
    Unknown

    CVE-2014-8486

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-8496. Reason: This candidate is a duplicate of CVE-2014-8496. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-8496 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 29 Apr 2016
    7.5
    High

    CVE-2016-1386

    Last Modified: 12 Apr 2025

    The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative notifications via crafted attribute-value pairs, aka Bug ID CSCux15521.

    Published: 28 Apr 2016
    7.4
    High

    CVE-2016-1389

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Cisco WebEx Meetings Server (CWMS) 2.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCuy44695.

    Published: 28 Apr 2016
    7.8
    High

    CVE-2016-4349

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Cisco WebEx Productivity Tools 2.40.5001.10012 allows local users to gain privileges via a Trojan horse cryptsp.dll, dwmapi.dll, msimg32.dll, ntmarta.dll, propsys.dll, riched20.dll, rpcrtremote.dll, secur32.dll, sxs.dll, or uxtheme.dll file in the current working directory, aka Bug ID CSCuy56140.

    Published: 28 Apr 2016
    4.3
    Medium

    CVE-2016-0211

    Last Modified: 12 Apr 2025

    IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.

    Published: 28 Apr 2016
    6.1
    Medium

    CVE-2016-1205

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the shiro8 (1) category_freearea_ addition_plugin plugin 1.0 and (2) itemdetail_freearea_ addition_plugin plugin 1.0 for EC-CUBE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Apr 2016
    4.3
    Medium

    CVE-2016-4347

    Last Modified: 24 Jun 2025

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7558. Reason: This candidate is a reservation duplicate of CVE-2015-7558. Notes: All CVE users should reference CVE-2015-7558 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Apr 2016
    8.8
    High

    CVE-2016-1663

    Last Modified: 12 Apr 2025

    The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted web site.

    Published: 28 Apr 2016
    6.8
    Medium

    CVE-2016-2167

    Last Modified: 12 Apr 2025

    The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.

    Published: 28 Apr 2016
    9.8
    Critical

    CVE-2016-3078

    Last Modified: 12 Apr 2025

    Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.

    Published: 28 Apr 2016
    9.1
    Critical

    CVE-2015-8869

    Last Modified: 12 Apr 2025

    OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.

    Published: 28 Apr 2016
    5.3
    Medium

    CVE-2016-10739

    Last Modified: 21 Nov 2024

    In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially dangerous substrings.

    Published: 28 Apr 2016
    8.8
    High

    CVE-2016-1660

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted web site.

    Published: 28 Apr 2016
    8
    High

    CVE-2016-1661

    Last Modified: 12 Apr 2025

    Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted web site, related to BindingSecurity.cpp and DOMWindow.cpp.

    Published: 28 Apr 2016
    4.3
    Medium

    CVE-2016-1664

    Last Modified: 12 Apr 2025

    The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to spoof the address bar via a crafted web site.

    Published: 28 Apr 2016
    9.8
    Critical

    CVE-2016-1662

    Last Modified: 12 Apr 2025

    extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

    Published: 28 Apr 2016
    6.5
    Medium

    CVE-2016-1665

    Last Modified: 12 Apr 2025

    The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.

    Published: 28 Apr 2016
    9.8
    Critical

    CVE-2016-1666

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 28 Apr 2016
    6.5
    Medium

    CVE-2016-2168

    Last Modified: 12 Apr 2025

    The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.

    Published: 28 Apr 2016
    7.5
    High

    CVE-2016-4348

    Last Modified: 12 Apr 2025

    The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.

    Published: 28 Apr 2016
    7
    High

    CVE-2016-4558

    Last Modified: 12 Apr 2025

    The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.

    Published: 28 Apr 2016
    7.8
    High

    CVE-2016-2143

    Last Modified: 12 Apr 2025

    The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted application, related to arch/s390/include/asm/mmu_context.h and arch/s390/include/asm/pgalloc.h.

    Published: 27 Apr 2016
    7.4
    High

    CVE-2016-1000352

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the ECIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

    Published: 27 Apr 2016
    6.3
    Medium

    CVE-2016-5728

    Last Modified: 12 Apr 2025

    Race condition in the vop_ioctl function in drivers/misc/mic/vop/vop_vringh.c in the MIC VOP driver in the Linux kernel before 4.6.1 allows local users to obtain sensitive information from kernel memory or cause a denial of service (memory corruption and system crash) by changing a certain header, aka a "double fetch" vulnerability.

    Published: 27 Apr 2016
    5.6
    Medium

    CVE-2016-0264

    Last Modified: 12 Apr 2025

    Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 27 Apr 2016
    7.4
    High

    CVE-2016-1000344

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES implementation allowed the use of ECB mode. This mode is regarded as unsafe and support for it has been removed from the provider.

    Published: 27 Apr 2016
    5.9
    Medium

    CVE-2016-1000345

    Last Modified: 12 May 2025

    In the Bouncy Castle JCE Provider version 1.55 and earlier the DHIES/ECIES CBC mode vulnerable to padding oracle attack. For BC 1.55 and older, in an environment where timings can be easily observed, it is possible with enough observations to identify when the decryption is failing due to padding.

    Published: 27 Apr 2016
    7.1
    High

    CVE-2016-3708

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in other namespaces, allows remote authenticated users to access network resources on restricted pods via an s2i build with a builder image that (1) contains ONBUILD commands or (2) does not contain a tar binary.

    Published: 27 Apr 2016
    7.5
    High

    CVE-2016-4049

    Last Modified: 12 Apr 2025

    The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to cause a denial of service (assertion failure and daemon crash) via a large BGP packet.

    Published: 27 Apr 2016
    6.5
    Medium

    CVE-2016-5318

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in the _TIFFVGetField function in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted tiff.

    Published: 27 Apr 2016
    6.5
    Medium

    CVE-2016-5319

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in tif_packbits.c in libtiff 4.0.6 and earlier allows remote attackers to crash the application via a crafted bmp file.

    Published: 27 Apr 2016
    7.5
    High

    CVE-2016-3706

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.

    Published: 27 Apr 2016
    8.6
    High

    CVE-2016-5096

    Last Modified: 12 Apr 2025

    Integer overflow in the fread function in ext/standard/file.c in PHP before 5.5.36 and 5.6.x before 5.6.22 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large integer in the second argument.

    Published: 27 Apr 2016
    9.8
    Critical

    CVE-2016-1601

    Last Modified: 12 Apr 2025

    yast2-users before 3.1.47, as used in SUSE Linux Enterprise 12 SP1, does not properly set empty password fields in /etc/shadow during an AutoYaST installation when the profile does not contain inst-sys users, which might allow attackers to have unspecified impact via unknown vectors.

    Published: 26 Apr 2016
    Unknown

    CVE-2015-3572

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3572. Reason: This candidate is a duplicate of CVE-2014-3572. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-3572 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Apr 2016
    Unknown

    CVE-2015-3569

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3569. Reason: This candidate is a duplicate of CVE-2014-3569. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-3569 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Apr 2016