CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2015-3571

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3571. Reason: This candidate is a duplicate of CVE-2014-3571. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-3571 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Apr 2016
    8.1
    High

    CVE-2016-10750

    Last Modified: 21 Nov 2024

    In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization. If an attacker can reach a listening Hazelcast instance with a crafted JoinRequest, and vulnerable classes exist in the classpath, the attacker can run arbitrary code.

    Published: 26 Apr 2016
    6.5
    Medium

    CVE-2016-1549

    Last Modified: 20 Apr 2025

    A malicious authenticated peer can create arbitrarily-many ephemeral associations in order to win the clock selection algorithm in ntpd in NTP 4.2.8p4 and earlier and NTPsec 3e160db8dc248a0bcb053b56a80167dc742d2b74 and a5fb34b9cc89b92a8fef2f459004865c93bb7f92 and modify a victim's clock.

    Published: 26 Apr 2016
    6.5
    Medium

    CVE-2016-2813

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

    Published: 26 Apr 2016
    9.8
    Critical

    CVE-2016-2785

    Last Modified: 12 Apr 2025

    Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restrictions by leveraging incorrect URL decoding.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2806

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2807

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2814

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.

    Published: 26 Apr 2016
    4.3
    Medium

    CVE-2016-2820

    Last Modified: 12 Apr 2025

    The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

    Published: 26 Apr 2016
    5.3
    Medium

    CVE-2016-1550

    Last Modified: 20 Apr 2025

    An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92. An attacker can send a series of crafted messages to attempt to recover the message digest key.

    Published: 26 Apr 2016
    3.7
    Low

    CVE-2016-1551

    Last Modified: 20 Apr 2025

    ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stored in the same structure, any packet with a source ip address of a reference clock (127.127.1.1 for example) that reaches the receive() function will match that reference clock's peer record and will be treated as a trusted peer. Any system that lacks the typical martian packet filtering which would block these packets is in danger of having its time controlled by an attacker.

    Published: 26 Apr 2016
    5.3
    Medium

    CVE-2016-1547

    Last Modified: 20 Apr 2025

    An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 by sending a crypto NAK packet to a victim client with a spoofed source address of an existing associated peer. This is true even if authentication is enabled.

    Published: 26 Apr 2016
    7.2
    High

    CVE-2016-1548

    Last Modified: 20 Apr 2025

    An attacker can spoof a packet from a legitimate ntpd server with an origin timestamp that matches the peer->dst timestamp recorded for that server. After making this switch, the client in NTP 4.2.8p4 and earlier and NTPSec aa48d001683e5b791a743ec9c575aaf7d867a2b0c will reject all future legitimate server responses. It is possible to force the victim client to move time after the mode has been changed. ntpq gives no indication that the mode has been switched.

    Published: 26 Apr 2016
    5.3
    Medium

    CVE-2016-2516

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the same IP address multiple times in an unconfig directive.

    Published: 26 Apr 2016
    5.3
    Medium

    CVE-2016-2517

    Last Modified: 20 Apr 2025

    NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging knowledge of the controlkey or requestkey and sending a crafted packet to ntpd, which changes the value of trustedkey, controlkey, or requestkey. NOTE: this vulnerability exists because of a CVE-2016-2516 regression.

    Published: 26 Apr 2016
    5.9
    Medium

    CVE-2016-2519

    Last Modified: 20 Apr 2025

    ntpd in NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (ntpd abort) by a large request data value, which triggers the ctl_getitem function to return a NULL value.

    Published: 26 Apr 2016
    7.5
    High

    CVE-2016-2812

    Last Modified: 12 Apr 2025

    Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2804

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2805

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 26 Apr 2016
    7.5
    High

    CVE-2016-2808

    Last Modified: 12 Apr 2025

    The watch implementation in the JavaScript engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code or cause a denial of service (generation-count overflow, out-of-bounds HashMap write access, and application crash) via a crafted web site.

    Published: 26 Apr 2016
    5.5
    Medium

    CVE-2016-2809

    Last Modified: 12 Apr 2025

    The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

    Published: 26 Apr 2016
    5
    Medium

    CVE-2016-2810

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

    Published: 26 Apr 2016
    8.8
    High

    CVE-2016-2811

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

    Published: 26 Apr 2016
    6.5
    Medium

    CVE-2016-2816

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

    Published: 26 Apr 2016
    5.4
    Medium

    CVE-2016-2817

    Last Modified: 12 Apr 2025

    The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

    Published: 26 Apr 2016
    8.1
    High

    CVE-2016-3081

    Last Modified: 12 Apr 2025

    Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions.

    Published: 26 Apr 2016
    9.8
    Critical

    CVE-2016-3082

    Last Modified: 12 Apr 2025

    XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary code via the stylesheet location parameter.

    Published: 26 Apr 2016
    7.8
    High

    CVE-2016-4557

    Last Modified: 12 Apr 2025

    The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.

    Published: 26 Apr 2016
    5.3
    Medium

    CVE-2016-2518

    Last Modified: 20 Apr 2025

    The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.

    Published: 26 Apr 2016
    7.5
    High

    CVE-2016-2333

    Last Modified: 12 Apr 2025

    SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 25 Apr 2016
    2.5
    Low

    CVE-2016-1185

    Last Modified: 12 Apr 2025

    The Cybozu kintone mobile application 1.x before 1.0.6 for Android allows attackers to discover an authentication token via a crafted application.

    Published: 25 Apr 2016
    7.8
    High

    CVE-2016-1202

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.

    Published: 25 Apr 2016
    9.8
    Critical

    CVE-2016-2331

    Last Modified: 12 Apr 2025

    The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Published: 25 Apr 2016
    8.8
    High

    CVE-2016-2332

    Last Modified: 12 Apr 2025

    flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter.

    Published: 25 Apr 2016
    8.1
    High

    CVE-2016-2346

    Last Modified: 12 Apr 2025

    Allround Automations PL/SQL Developer 11 before 11.0.6 relies on unverified HTTP data for updates, which allows man-in-the-middle attackers to execute arbitrary code by modifying fields in the client-server data stream.

    Published: 25 Apr 2016
    4.7
    Medium

    CVE-2019-3901

    Last Modified: 21 Nov 2024

    A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before perf_event_alloc() actually attaches to it, allowing an attacker to bypass the ptrace_may_access() check and the perf_event_exit_task(current) call that is performed in install_exec_creds() during privileged execve() calls. This issue affects kernel versions before 4.8.

    Published: 25 Apr 2016
    7.5
    High

    CVE-2016-3704

    Last Modified: 20 Apr 2025

    Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.

    Published: 25 Apr 2016
    4.7
    Medium

    CVE-2016-6130

    Last Modified: 12 Apr 2025

    Race condition in the sclp_ctl_ioctl_sccb function in drivers/s390/char/sclp_ctl.c in the Linux kernel before 4.6 allows local users to obtain sensitive information from kernel memory by changing a certain length value, aka a "double fetch" vulnerability.

    Published: 25 Apr 2016
    5.3
    Medium

    CVE-2016-3702

    Last Modified: 20 Apr 2025

    Padding oracle flaw in CloudForms Management Engine (aka CFME) 5 allows remote attackers to obtain sensitive cleartext information.

    Published: 25 Apr 2016
    9.8
    Critical

    CVE-2016-4539

    Last Modified: 12 Apr 2025

    The xml_parse_into_struct function in ext/xml/xml.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (buffer under-read and segmentation fault) or possibly have unspecified other impact via crafted XML data in the second argument, leading to a parser level of zero.

    Published: 25 Apr 2016
    9.8
    Critical

    CVE-2016-4537

    Last Modified: 12 Apr 2025

    The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.

    Published: 24 Apr 2016
    9.8
    Critical

    CVE-2016-4543

    Last Modified: 12 Apr 2025

    The exif_process_IFD_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate IFD sizes, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

    Published: 24 Apr 2016
    9.8
    Critical

    CVE-2016-4538

    Last Modified: 12 Apr 2025

    The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 modifies certain data structures without considering whether they are copies of the _zero_, _one_, or _two_ global variable, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.

    Published: 24 Apr 2016
    9.8
    Critical

    CVE-2016-4544

    Last Modified: 12 Apr 2025

    The exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not validate TIFF start data, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

    Published: 24 Apr 2016
    7.5
    High

    CVE-2016-4074

    Last Modified: 12 Apr 2025

    The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted JSON file. This issue has been fixed in jq 1.6_rc1-r0.

    Published: 24 Apr 2016
    9.8
    Critical

    CVE-2016-4542

    Last Modified: 12 Apr 2025

    The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.

    Published: 24 Apr 2016
    7.5
    High

    CVE-2016-2109

    Last Modified: 12 Apr 2025

    The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.

    Published: 23 Apr 2016
    5.4
    Medium

    CVE-2016-1916

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote authenticated users to inject arbitrary web script or HTML by leveraging basic administrative access to create a crafted policy, leading to improper rendering on a certain Export IT screen.

    Published: 22 Apr 2016
    6.1
    Medium

    CVE-2016-1036

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Analytics AppMeasurement for Flash Library before 4.0.1, when debugTracking is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Apr 2016
    6.1
    Medium

    CVE-2016-3126

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 22 Apr 2016