CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-0712

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.

    Published: 11 Apr 2016
    6.1
    Medium

    CVE-2016-2163

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.

    Published: 11 Apr 2016
    7.8
    High

    CVE-2016-2393

    Last Modified: 12 Apr 2025

    Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.

    Published: 11 Apr 2016
    7.8
    High

    CVE-2015-8868

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.

    Published: 11 Apr 2016
    7.8
    High

    CVE-2015-5349

    Last Modified: 12 Apr 2025

    The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that is interpreted as a formula when imported into a spreadsheet.

    Published: 11 Apr 2016
    5.9
    Medium

    CVE-2016-1546

    Last Modified: 12 Apr 2025

    The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modified flow-control windows.

    Published: 11 Apr 2016
    5.4
    Medium

    CVE-2016-3101

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.

    Published: 11 Apr 2016
    7.3
    High

    CVE-2016-3102

    Last Modified: 20 Apr 2025

    The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access or (2) get/set array operations.

    Published: 11 Apr 2016
    7.5
    High

    CVE-2016-3633

    Last Modified: 12 Apr 2025

    The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.

    Published: 11 Apr 2016
    5.9
    Medium

    CVE-2016-4008

    Last Modified: 12 Apr 2025

    The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.

    Published: 11 Apr 2016
    5.3
    Medium

    CVE-2015-8108

    Last Modified: 12 Apr 2025

    The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors.

    Published: 8 Apr 2016
    9.8
    Critical

    CVE-2015-8833

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item.

    Published: 8 Apr 2016
    9.8
    Critical

    CVE-2015-8841

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the Archive support module in ESET NOD32 before update 11861 allows remote attackers to execute arbitrary code via a large number of languages in an EPOC installation file of type SIS_FILE_MULTILANG.

    Published: 8 Apr 2016
    6.2
    Medium

    CVE-2016-1885

    Last Modified: 12 Apr 2025

    Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based buffer overflow.

    Published: 8 Apr 2016
    6.5
    Medium

    CVE-2016-3985

    Last Modified: 12 Apr 2025

    The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.

    Published: 8 Apr 2016
    7.8
    High

    CVE-2016-3986

    Last Modified: 12 Apr 2025

    Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a crafted PE file, related to authenticode parsing.

    Published: 8 Apr 2016
    9.8
    Critical

    CVE-2016-3987

    Last Modified: 12 Apr 2025

    The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

    Published: 8 Apr 2016
    6.1
    Medium

    CVE-2016-1180

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Apr 2016
    6.2
    Medium

    CVE-2015-5969

    Last Modified: 12 Apr 2025

    The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to discover database credentials by listing a process and its arguments.

    Published: 8 Apr 2016
    6.1
    Medium

    CVE-2016-1375

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco IP Interoperability and Collaboration System 4.10(1) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy12339.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3983

    Last Modified: 12 Apr 2025

    McAfee Advanced Threat Defense (ATD) before 3.4.8.178 might allow remote attackers to bypass malware detection by leveraging information about the parent process.

    Published: 8 Apr 2016
    5.3
    Medium

    CVE-2016-3963

    Last Modified: 12 Apr 2025

    Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 443.

    Published: 8 Apr 2016
    5.1
    Medium

    CVE-2016-3984

    Last Modified: 12 Apr 2025

    The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.

    Published: 8 Apr 2016
    9.8
    Critical

    CVE-2016-3154

    Last Modified: 12 Apr 2025

    The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object.

    Published: 8 Apr 2016
    8.8
    High

    CVE-2015-6541

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) before 8.5 allow remote attackers to hijack the authentication of arbitrary users for requests that change account preferences via a SOAP request to service/soap/BatchRequest.

    Published: 8 Apr 2016
    9.8
    Critical

    CVE-2016-3153

    Last Modified: 12 Apr 2025

    SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.

    Published: 8 Apr 2016
    7.3
    High

    CVE-2016-3187

    Last Modified: 12 Apr 2025

    The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspecified impact, via a base64-encoded pp parameter.

    Published: 8 Apr 2016
    7.3
    High

    CVE-2016-3188

    Last Modified: 12 Apr 2025

    The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions, (2) container, (3) token, (4) password, (5) password_confirm, (6) text_format, or (7) markup field type, and consequently have unspecified impact, via unspecified vectors.

    Published: 8 Apr 2016
    6.1
    Medium

    CVE-2016-3978

    Last Modified: 12 Apr 2025

    The Web User Interface (WebUI) in FortiOS 5.0.x before 5.0.13, 5.2.x before 5.2.3, and 5.4.x before 5.4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or cross-site scripting (XSS) attacks via the "redirect" parameter to "login."

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3979

    Last Modified: 12 Apr 2025

    Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory corruption and process crash) via a crafted HTTP request, related to the IctParseCookies function, aka SAP Security Note 2256185.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3980

    Last Modified: 12 Apr 2025

    The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a crafted HTTP request, aka SAP Security Note 2259547.

    Published: 8 Apr 2016
    3.3
    Low

    CVE-2014-9770

    Last Modified: 12 Apr 2025

    tmpfiles.d/systemd.conf in systemd before 214 uses weak permissions for journal files under (1) /run/log/journal/%m and (2) /var/log/journal/%m, which allows local users to obtain sensitive information by reading these files.

    Published: 8 Apr 2016
    7.8
    High

    CVE-2016-3945

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image, which triggers an out-of-bounds write.

    Published: 8 Apr 2016
    8.8
    High

    CVE-2015-8840

    Last Modified: 12 Apr 2025

    The XML Data Archiving Service (XML DAS) in SAP NetWeaver AS Java does not check authorization, which allows remote authenticated users to obtain sensitive information, gain privileges, or possibly have unspecified other impact via requests to (1) webcontent/cas/cas_enter.jsp, (2) webcontent/cas/cas_validate.jsp, or (3) webcontent/aas/aas_store.jsp, aka SAP Security Note 1945215.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3624

    Last Modified: 12 Apr 2025

    The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) by setting the "-v" option to -1.

    Published: 8 Apr 2016
    3.3
    Low

    CVE-2015-8842

    Last Modified: 12 Apr 2025

    tmpfiles.d/systemd.conf in systemd before 229 uses weak permissions for /var/log/journal/%m/system.journal, which allows local users to obtain sensitive information by reading the file.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3623

    Last Modified: 12 Apr 2025

    The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by setting the (1) v or (2) h parameter to 0.

    Published: 8 Apr 2016
    6.5
    Medium

    CVE-2016-3625

    Last Modified: 12 Apr 2025

    tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3634

    Last Modified: 12 Apr 2025

    The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.

    Published: 8 Apr 2016
    7.8
    High

    CVE-2016-3632

    Last Modified: 12 Apr 2025

    The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3658

    Last Modified: 12 Apr 2025

    The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.

    Published: 8 Apr 2016
    7.5
    High

    CVE-2016-3976

    Last Modified: 21 Apr 2026

    Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backslash) in the fileName parameter to CrashFileDownloadServlet, aka SAP Security Note 2234971.

    Published: 7 Apr 2016
    6.1
    Medium

    CVE-2016-2789

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 7 Apr 2016
    9.8
    Critical

    CVE-2016-2851

    Last Modified: 12 Apr 2025

    Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.

    Published: 7 Apr 2016
    9.8
    Critical

    CVE-2016-2563

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.

    Published: 7 Apr 2016
    5.9
    Medium

    CVE-2015-2774

    Last Modified: 12 Apr 2025

    Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).

    Published: 7 Apr 2016
    6.1
    Medium

    CVE-2016-2511

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.

    Published: 7 Apr 2016
    7.8
    High

    CVE-2015-8680

    Last Modified: 12 Apr 2025

    The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8307.

    Published: 7 Apr 2016
    7.8
    High

    CVE-2015-8307

    Last Modified: 12 Apr 2025

    The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the graphics permission, aka an "interface access control vulnerability," a different vulnerability than CVE-2015-8680.

    Published: 7 Apr 2016
    7.8
    High

    CVE-2015-8318

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with software CRR-TL00 before CRR-TL00C01B160SP01, CRR-UL00 before CRR-UL00C00B160, and CRR-CL00 before CRR-CL00C92B161 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2015-8319.

    Published: 7 Apr 2016