CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-1917

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1918.

    Published: 22 Apr 2016
    6.1
    Medium

    CVE-2016-1918

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-1917.

    Published: 22 Apr 2016
    8.2
    High

    CVE-2016-2204

    Last Modified: 12 Apr 2025

    The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to obtain root-shell access via crafted terminal-window input.

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-2203

    Last Modified: 12 Apr 2025

    The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.

    Published: 22 Apr 2016
    Unknown

    CVE-2015-4829

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0638. Reason: This candidate is a reservation duplicate of CVE-2016-0638. Notes: All CVE users should reference CVE-2016-0638 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-4064

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted remerge call.

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-4063

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.

    Published: 22 Apr 2016
    5.5
    Medium

    CVE-2016-4062

    Last Modified: 12 Apr 2025

    Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-4059

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via a crafted FlateDecode stream in a PDF document.

    Published: 22 Apr 2016
    7.5
    High

    CVE-2016-4060

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to cause a denial of service (application crash) via unspecified vectors.

    Published: 22 Apr 2016
    7.5
    High

    CVE-2016-4061

    Last Modified: 12 Apr 2025

    Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content stream.

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-4065

    Last Modified: 12 Apr 2025

    The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 7.3.4 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted (1) JPEG, (2) GIF, or (3) BMP image.

    Published: 22 Apr 2016
    7.2
    High

    CVE-2016-1593

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

    Published: 22 Apr 2016
    5.4
    Medium

    CVE-2016-1596

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6) tf_aManufacturerFullName, (7) tf_aManufacturerName, (8) tf_aManufacturerAddress, or (9) tf_aManufacturerCity parameter.

    Published: 22 Apr 2016
    6.5
    Medium

    CVE-2016-1594

    Last Modified: 12 Apr 2025

    Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.

    Published: 22 Apr 2016
    6.5
    Medium

    CVE-2016-1595

    Last Modified: 12 Apr 2025

    LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4079

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not verify BER identifiers, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4085

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a packet.

    Published: 22 Apr 2016
    6.1
    Medium

    CVE-2016-2305

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 22 Apr 2016
    7.8
    High

    CVE-2016-3697

    Last Modified: 12 Apr 2025

    libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4078

    Last Modified: 12 Apr 2025

    The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote attackers to cause a denial of service (deep recursion and application crash) via a crafted packet, related to epan/dissectors/packet-capwap.c and epan/dissectors/packet-ieee80211.c.

    Published: 22 Apr 2016
    9.8
    Critical

    CVE-2016-3074

    Last Modified: 12 Apr 2025

    Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.

    Published: 22 Apr 2016
    7.5
    High

    CVE-2016-2306

    Last Modified: 12 Apr 2025

    The HMI web server in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

    Published: 22 Apr 2016
    4.3
    Medium

    CVE-2016-2304

    Last Modified: 12 Apr 2025

    Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 22 Apr 2016
    7.3
    High

    CVE-2016-2299

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 22 Apr 2016
    6.5
    Medium

    CVE-2016-2300

    Last Modified: 12 Apr 2025

    Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.

    Published: 22 Apr 2016
    6.3
    Medium

    CVE-2016-2301

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 22 Apr 2016
    5.3
    Medium

    CVE-2016-2302

    Last Modified: 12 Apr 2025

    Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.

    Published: 22 Apr 2016
    5.3
    Medium

    CVE-2016-2303

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

    Published: 22 Apr 2016
    8.8
    High

    CVE-2016-2354

    Last Modified: 12 Apr 2025

    The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote attackers to send arbitrary CAN commands by leveraging access to a device inside or adjacent to the vehicle, as demonstrated by a CAN command to disrupt braking or steering.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4006

    Last Modified: 12 Apr 2025

    epan/proto.c in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not limit the protocol-tree depth, which allows remote attackers to cause a denial of service (stack memory consumption and application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4076

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4077

    Last Modified: 12 Apr 2025

    epan/reassemble.c in TShark in Wireshark 2.0.x before 2.0.3 relies on incorrect special-case handling of truncated Tvb data structures, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4080

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-pktc.c in the PKTC dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 misparses timestamp fields, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4081

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4082

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses the wrong variable to index an array, which allows remote attackers to cause a denial of service (out-of-bounds access and application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4083

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 22 Apr 2016
    5.9
    Medium

    CVE-2016-4084

    Last Modified: 12 Apr 2025

    Integer signedness error in epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 allows remote attackers to cause a denial of service (integer overflow and application crash) via a crafted packet that triggers an unexpected array size.

    Published: 22 Apr 2016
    4.6
    Medium

    CVE-2016-3145

    Last Modified: 12 Apr 2025

    Lexmark printers with firmware ATL before ATL.021.063, CB before CB.021.063, PP before PP.021.063, and YK before YK.021.063 mishandle Erase Printer Memory and Erase Hard Disk actions, which allows physically proximate attackers to obtain sensitive information via direct read operations on non-volatile memory.

    Published: 22 Apr 2016
    9.8
    Critical

    CVE-2016-2004

    Last Modified: 12 Apr 2025

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.

    Published: 21 Apr 2016
    4.3
    Medium

    CVE-2015-6479

    Last Modified: 12 Apr 2025

    ACEmanager in Sierra Wireless ALEOS 4.4.2 and earlier on ES440, ES450, GX400, GX440, GX450, and LS300 devices allows remote attackers to read the filteredlogs.txt file, and consequently discover potentially sensitive boot-sequence information, via unspecified vectors.

    Published: 21 Apr 2016
    3.7
    Low

    CVE-2016-0671

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-0682

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0689, CVE-2016-0692, CVE-2016-0694, and CVE-2016-3418.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-0685

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Processing.

    Published: 21 Apr 2016
    3.3
    Low

    CVE-2016-0691

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-0692

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0689, CVE-2016-0694, and CVE-2016-3418.

    Published: 21 Apr 2016
    6
    Medium

    CVE-2016-0697

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users to affect confidentiality and integrity via unknown vectors.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2016-1364

    Last Modified: 12 Apr 2025

    Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a denial of service (device reload) via crafted Bonjour traffic, aka Bug ID CSCur66908.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-3416

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality and integrity via vectors related to Console.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-3417

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to PIA Search Functionality.

    Published: 21 Apr 2016