CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2016-2001

    Last Modified: 12 Apr 2025

    HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection attacks via unspecified vectors.

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0153

    Last Modified: 12 Apr 2025

    OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 allows remote attackers to execute arbitrary code via a crafted file, aka "Windows OLE Remote Code Execution Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0159

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0166

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    9.3
    Critical

    CVE-2016-0088

    Last Modified: 12 Apr 2025

    Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via a crafted application, aka "Hyper-V Remote Code Execution Vulnerability."

    Published: 12 Apr 2016
    7.1
    High

    CVE-2016-0090

    Last Modified: 12 Apr 2025

    Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0127

    Last Modified: 12 Apr 2025

    Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010 SP2, and Office Web Apps Server 2013 SP1 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    6.8
    Medium

    CVE-2016-0128

    Last Modified: 12 Apr 2025

    The SAM and LSAD protocol implementations in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 do not properly establish an RPC channel, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "Windows SAM and LSAD Downgrade Vulnerability" or "BADLOCK."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0139

    Last Modified: 12 Apr 2025

    Microsoft Excel 2010 SP2, Word for Mac 2011, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    8.8
    High

    CVE-2016-0145

    Last Modified: 12 Apr 2025

    The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold and 1511; Office 2007 SP3 and 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, and 3.5.1; Skype for Business 2016; Lync 2010; Lync 2010 Attendee; Lync 2013 SP1; and Live Meeting 2007 Console allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0154

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0160

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 11 mishandles DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0164

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-0887

    Last Modified: 12 Apr 2025

    EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote attackers to discover a private-key prime by conducting a Lenstra side-channel attack that leverages an application's failure to detect an RSA signature failure during a TLS session.

    Published: 12 Apr 2016
    9.1
    Critical

    CVE-2016-1034

    Last Modified: 12 Apr 2025

    The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 allows remote attackers to read or write to arbitrary files via unspecified vectors.

    Published: 12 Apr 2016
    7.1
    High

    CVE-2016-0089

    Last Modified: 12 Apr 2025

    Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory via a crafted application, aka "Hyper-V Information Disclosure Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0122

    Last Modified: 12 Apr 2025

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    8.4
    High

    CVE-2016-0135

    Last Modified: 12 Apr 2025

    The Secondary Logon Service in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0136

    Last Modified: 12 Apr 2025

    Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, Excel Services on SharePoint Server 2007 SP3, and Excel Services on SharePoint Server 2010 SP2 allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0143

    Last Modified: 12 Apr 2025

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0165 and CVE-2016-0167.

    Published: 12 Apr 2016
    8.8
    High

    CVE-2016-0147

    Last Modified: 12 Apr 2025

    Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulnerability."

    Published: 12 Apr 2016
    7.8
    High

    CVE-2016-0148

    Last Modified: 12 Apr 2025

    Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET Framework Remote Code Execution Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0150

    Last Modified: 12 Apr 2025

    HTTP.sys in Microsoft Windows 10 Gold and 1511 allows remote attackers to cause a denial of service (system hang) via crafted HTTP 2.0 requests, aka "HTTP.sys Denial of Service Vulnerability."

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0155

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0156 and CVE-2016-0157.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0156

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0155 and CVE-2016-0157.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-0157

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0155 and CVE-2016-0156.

    Published: 12 Apr 2016
    6.5
    Medium

    CVE-2016-0158

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161.

    Published: 12 Apr 2016
    6.5
    Medium

    CVE-2016-0161

    Last Modified: 12 Apr 2025

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.

    Published: 12 Apr 2016
    6.1
    Medium

    CVE-2015-7520

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) RadioGroup and (2) CheckBoxMultipleChoice classes in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 allow remote attackers to inject arbitrary web script or HTML via a crafted "value" attribute in a <input> element.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-3656

    Last Modified: 12 Apr 2025

    The GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote attackers to cause a denial of service (service crash) via a crafted request.

    Published: 12 Apr 2016
    8.8
    High

    CVE-2016-2405

    Last Modified: 12 Apr 2025

    Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cause a denial of service (system crash) via a crafted URL.

    Published: 12 Apr 2016
    6.1
    Medium

    CVE-2015-5347

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the getWindowOpenJavaScript function in org.apache.wicket.extensions.ajax.markup.html.modal.ModalWindow in Apache Wicket 1.5.x before 1.5.15, 6.x before 6.22.0, and 7.x before 7.2.0 might allow remote attackers to inject arbitrary web script or HTML via a ModalWindow title.

    Published: 12 Apr 2016
    7.2
    High

    CVE-2016-3654

    Last Modified: 12 Apr 2025

    The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5H2 allows remote authenticated administrators to execute arbitrary OS commands via an SSH command parameter.

    Published: 12 Apr 2016
    9.8
    Critical

    CVE-2016-3655

    Last Modified: 12 Apr 2025

    The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to execute arbitrary OS commands via an unspecified API call.

    Published: 12 Apr 2016
    4.9
    Medium

    CVE-2016-4004

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read arbitrary files via a ..\ (dot dot backslash) in the file parameter to ViewFile.

    Published: 12 Apr 2016
    9.8
    Critical

    CVE-2016-3657

    Last Modified: 12 Apr 2025

    Buffer overflow in the GlobalProtect Portal in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remote attackers to cause a denial of service (device crash) or possibly execute arbitrary code via an SSL VPN request.

    Published: 12 Apr 2016
    8.8
    High

    CVE-2016-0785

    Last Modified: 12 Apr 2025

    Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL evaluation.

    Published: 12 Apr 2016
    6.1
    Medium

    CVE-2016-2162

    Last Modified: 12 Apr 2025

    Apache Struts 2.x before 2.3.25 does not sanitize text in the Locale object constructed by I18NInterceptor, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors involving language display.

    Published: 12 Apr 2016
    8.8
    High

    CVE-2016-3172

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the parent_id parameter in an item_edit action.

    Published: 12 Apr 2016
    6.1
    Medium

    CVE-2016-4003

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the URLDecoder function in JRE before 1.8, as used in Apache Struts 2.x before 2.3.28, when using a single byte page encoding, allows remote attackers to inject arbitrary web script or HTML via multi-byte characters in a url-encoded parameter.

    Published: 12 Apr 2016
    7.4
    High

    CVE-2016-3164

    Last Modified: 12 Apr 2025

    Drupal 6.x before 6.38, 7.x before 7.43, and 8.x before 8.0.4 might allow remote attackers to conduct open redirect attacks by leveraging (1) custom code or (2) a form shown on a 404 error page, related to path manipulation.

    Published: 12 Apr 2016
    6.4
    Medium

    CVE-2016-3168

    Last Modified: 12 Apr 2025

    The System module in Drupal 6.x before 6.38 and 7.x before 7.43 might allow remote attackers to hijack the authentication of site administrators for requests that download and run files with arbitrary JSON-encoded content, aka a "reflected file download vulnerability."

    Published: 12 Apr 2016
    8.1
    High

    CVE-2016-3169

    Last Modified: 12 Apr 2025

    The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code that calls the user_save function with an explicit category and loads all roles into the array.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-3163

    Last Modified: 12 Apr 2025

    The XML-RPC system in Drupal 6.x before 6.38 and 7.x before 7.43 might make it easier for remote attackers to conduct brute-force attacks via a large number of calls made at once to the same method.

    Published: 12 Apr 2016
    7.5
    High

    CVE-2016-3165

    Last Modified: 12 Apr 2025

    The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access restrictions by leveraging permission to submit a form with a button that has "#access" set to FALSE in the server-side form definition.

    Published: 12 Apr 2016
    5.9
    Medium

    CVE-2016-3166

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the drupal_set_header function in Drupal 6.x before 6.38, when used with PHP before 5.1.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks by leveraging a module that allows user-submitted data to appear in HTTP headers.

    Published: 12 Apr 2016
    7.4
    High

    CVE-2016-3167

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the drupal_goto function in Drupal 6.x before 6.38, when used with PHP before 5.4.7, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a double-encoded URL in the "destination" parameter.

    Published: 12 Apr 2016
    5.3
    Medium

    CVE-2016-3170

    Last Modified: 12 Apr 2025

    The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensitive username information by leveraging a configuration that permits using an email address to login and a module that permits logging in.

    Published: 12 Apr 2016
    8.1
    High

    CVE-2016-3171

    Last Modified: 12 Apr 2025

    Drupal 6.x before 6.38, when used with PHP before 5.4.45, 5.5.x before 5.5.29, or 5.6.x before 5.6.13, might allow remote attackers to execute arbitrary code via vectors related to session data truncation.

    Published: 12 Apr 2016
    8.1
    High

    CVE-2016-3162

    Last Modified: 12 Apr 2025

    The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or substitute a link to a file uploaded to an unprocessed form by leveraging permission to create content or comment and upload files.

    Published: 12 Apr 2016