CVE Feed

    Dashboard / CVE

    4.7
    Medium

    CVE-2016-3435

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote attackers to affect availability via vectors related to PIA Core Technology.

    Published: 21 Apr 2016
    8.2
    High

    CVE-2016-3436

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Tasks.

    Published: 21 Apr 2016
    8.2
    High

    CVE-2016-3437

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle CRM Wireless component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Person Address Page.

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-3441

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect confidentiality, integrity, and availability via vectors related to Filesystem.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-3442

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Portal.

    Published: 21 Apr 2016
    6.9
    Medium

    CVE-2016-3447

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to OAF Core.

    Published: 21 Apr 2016
    8.6
    High

    CVE-2016-3455

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Outside In Filters.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-3460

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to ePerformance.

    Published: 21 Apr 2016
    7.2
    High

    CVE-2016-3461

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the MySQL Enterprise Monitor component in Oracle MySQL 3.0.25 and earlier and 3.1.2 and earlier allows remote administrators to affect confidentiality, integrity, and availability via vectors related to Monitoring: Server.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-3462

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Network Configuration Service.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-3465

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows local users to affect availability via vectors related to ZFS.

    Published: 21 Apr 2016
    9.1
    Critical

    CVE-2016-3466

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Field Service component in Oracle E-Business Suite 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Wireless.

    Published: 21 Apr 2016
    Unknown

    CVE-2016-6479

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-6479. Reason: This candidate is a duplicate of CVE-2015-6479. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2015-6479 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Apr 2016
    7.8
    High

    CVE-2016-3418

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the DataStore component in Oracle Berkeley DB 11.2.5.0.32, 11.2.5.1.29, 11.2.5.2.42, 11.2.5.3.28, 12.1.6.0.35, and 12.1.6.1.26 allows local users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2016-0682, CVE-2016-0689, CVE-2016-0692, and CVE-2016-0694.

    Published: 21 Apr 2016
    6.4
    Medium

    CVE-2016-3420

    Last Modified: 8 May 2025

    Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.1, 9.3.1.2, 9.3.2, and 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to Security, a different vulnerability than CVE-2016-3431.

    Published: 21 Apr 2016
    5.4
    Medium

    CVE-2016-3423

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Rich Text Editor, a different vulnerability than CVE-2016-0698.

    Published: 21 Apr 2016
    4.5
    Medium

    CVE-2016-3429

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Retail Xstore Point of Service component in Oracle Retail Applications 5.0, 5.5, 6.0, 6.5, 7.0, and 7.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Xstore Services.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-3434

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Logout.

    Published: 21 Apr 2016
    7.5
    High

    CVE-2015-8867

    Last Modified: 12 Apr 2025

    The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-0639

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Pluggable Authentication.

    Published: 21 Apr 2016
    6.1
    Medium

    CVE-2016-0640

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect integrity and availability via vectors related to DML.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0646

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DML.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0654

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0656.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0658

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Optimizer.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0666

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to Security: Privileges.

    Published: 21 Apr 2016
    5.1
    Medium

    CVE-2016-0641

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect confidentiality and availability via vectors related to MyISAM.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0642

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0647

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to FTS.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0651

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0652

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to DML.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0659

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Optimizer.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0661

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Options.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0665

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier allows local users to affect availability via vectors related to Security: Encryption.

    Published: 21 Apr 2016
    4.4
    Medium

    CVE-2016-0667

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Locking.

    Published: 21 Apr 2016
    4.1
    Medium

    CVE-2016-0668

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB.

    Published: 21 Apr 2016
    9.6
    Critical

    CVE-2015-8866

    Last Modified: 12 Apr 2025

    ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related issue to CVE-2015-5161.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0657

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect confidentiality via vectors related to JSON.

    Published: 21 Apr 2016
    3.3
    Low

    CVE-2016-0643

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect confidentiality via vectors related to DML.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0644

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to DDL.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0648

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to PS.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0649

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to PS.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0650

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.5.47 and earlier, 5.6.28 and earlier, and 5.7.10 and earlier and MariaDB before 5.5.48, 10.0.x before 10.0.24, and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to Replication.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0653

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0655

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier and MariaDB 10.0.x before 10.0.25 and 10.1.x before 10.1.14 allows local users to affect availability via vectors related to InnoDB.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0656

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0654.

    Published: 21 Apr 2016
    5.5
    Medium

    CVE-2016-0662

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Partition.

    Published: 21 Apr 2016
    4.7
    Medium

    CVE-2016-0663

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema.

    Published: 21 Apr 2016
    9.8
    Critical

    CVE-2016-2002

    Last Modified: 19 Nov 2025

    The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPort parameter, aka ZDI-CAN-3417.

    Published: 20 Apr 2016
    9.8
    Critical

    CVE-2016-2003

    Last Modified: 12 Apr 2025

    HPE P9000 Command View Advanced Edition Software (CVAE) 7.x and 8.x before 8.4.0-00 and XP7 CVAE 7.x and 8.x before 8.4.0-00 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 20 Apr 2016
    5.5
    Medium

    CVE-2016-2202

    Last Modified: 12 Apr 2025

    The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restrictions via unspecified vectors.

    Published: 20 Apr 2016