CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2016-1169

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Apr 2016
    8.8
    High

    CVE-2016-1170

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators.

    Published: 6 Apr 2016
    6.1
    Medium

    CVE-2016-1171

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Apr 2016
    8.8
    High

    CVE-2016-1172

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.

    Published: 6 Apr 2016
    6.1
    Medium

    CVE-2016-1173

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Apr 2016
    8.8
    High

    CVE-2016-1174

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.

    Published: 6 Apr 2016
    9.8
    Critical

    CVE-2016-1291

    Last Modified: 12 Apr 2025

    Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary code via crafted deserialized data in an HTTP POST request, aka Bug ID CSCuw03192.

    Published: 6 Apr 2016
    9.8
    Critical

    CVE-2016-1313

    Last Modified: 12 Apr 2025

    Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default SSH private key, which allows remote attackers to obtain root access via unspecified vectors, aka Bug ID CSCun71294.

    Published: 6 Apr 2016
    7.5
    High

    CVE-2016-2272

    Last Modified: 12 Apr 2025

    Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.

    Published: 6 Apr 2016
    6.5
    Medium

    CVE-2016-2292

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 6 Apr 2016
    6.3
    Medium

    CVE-2016-2277

    Last Modified: 12 Apr 2025

    IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file.

    Published: 6 Apr 2016
    6.1
    Medium

    CVE-2016-3968

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Sophos Cyberoam CR100iNG UTM appliance with firmware 10.6.3 MR-1 build 503, CR35iNG UTM appliance with firmware 10.6.2 MR-1 build 383, and CR35iNG UTM appliance with firmware 10.6.2 Build 378 allow remote attackers to inject arbitrary web script or HTML via the (1) ipFamily parameter to corporate/webpages/trafficdiscovery/LiveConnections.jsp; the (2) ipFamily, (3) applicationname, or (4) username parameter to corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp; or the (5) X-Forwarded-For HTTP header.

    Published: 6 Apr 2016
    6.1
    Medium

    CVE-2016-3969

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in McAfee Email Gateway (MEG) 7.6.x before 7.6.404, when File Filtering is enabled with the action set to ESERVICES:REPLACE, allows remote attackers to inject arbitrary web script or HTML via an attachment in a blocked email.

    Published: 6 Apr 2016
    6.5
    Medium

    CVE-2016-3118

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 allows remote attackers to have an unspecified impact via unknown vectors.

    Published: 6 Apr 2016
    5.5
    Medium

    CVE-2016-7914

    Last Modified: 12 Apr 2025

    The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.5.3 does not check whether a slot is a leaf, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (invalid pointer dereference and out-of-bounds read) via an application that uses associative-array data structures, as demonstrated by the keyutils test suite.

    Published: 6 Apr 2016
    7.8
    High

    CVE-2016-3672

    Last Modified: 12 Apr 2025

    The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid program, by disabling stack-consumption resource limits.

    Published: 6 Apr 2016
    8.8
    High

    CVE-2016-3105

    Last Modified: 12 Apr 2025

    The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

    Published: 6 Apr 2016
    7.5
    High

    CVE-2016-3125

    Last Modified: 12 Apr 2025

    The mod_tls module in ProFTPD before 1.3.5b and 1.3.6 before 1.3.6rc2 does not properly handle the TLSDHParamFile directive, which might cause a weaker than intended Diffie-Hellman (DH) key to be used and consequently allow attackers to have unspecified impact via unknown vectors.

    Published: 5 Apr 2016
    4.3
    Medium

    CVE-2016-1175

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 5 Apr 2016
    6.3
    Medium

    CVE-2016-1176

    Last Modified: 12 Apr 2025

    Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.

    Published: 5 Apr 2016
    5.5
    Medium

    CVE-2016-1789

    Last Modified: 12 Apr 2025

    Apple iBooks Author before 2.4.1 allows remote attackers to read arbitrary files via an iBooks Author file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 5 Apr 2016
    9.8
    Critical

    CVE-2016-2000

    Last Modified: 12 Apr 2025

    HPE Asset Manager 9.40, 9.41, and 9.50 and Asset Manager CloudSystem Chargeback 9.40 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Published: 5 Apr 2016
    6.1
    Medium

    CVE-2016-1177

    Last Modified: 12 Apr 2025

    The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 5 Apr 2016
    7.8
    High

    CVE-2016-3981

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.

    Published: 5 Apr 2016
    7.5
    High

    CVE-2016-3099

    Last Modified: 20 Apr 2025

    mod_ns in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows remote attackers to force the use of ciphers that were not intended to be enabled.

    Published: 5 Apr 2016
    7.5
    High

    CVE-2016-3959

    Last Modified: 12 Apr 2025

    The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.

    Published: 5 Apr 2016
    8.8
    High

    CVE-2016-3982

    Last Modified: 12 Apr 2025

    Off-by-one error in the bmp_rle4_fread function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file, which triggers a heap-based buffer overflow.

    Published: 5 Apr 2016
    9.8
    Critical

    CVE-2015-8519

    Last Modified: 12 Apr 2025

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CVE-2015-8521, and CVE-2015-8522.

    Published: 4 Apr 2016
    9.8
    Critical

    CVE-2015-8520

    Last Modified: 12 Apr 2025

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8521, and CVE-2015-8522.

    Published: 4 Apr 2016
    9.8
    Critical

    CVE-2015-8521

    Last Modified: 12 Apr 2025

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8522.

    Published: 4 Apr 2016
    9.8
    Critical

    CVE-2015-8522

    Last Modified: 12 Apr 2025

    Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8521.

    Published: 4 Apr 2016
    7.5
    High

    CVE-2015-8523

    Last Modified: 12 Apr 2025

    The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) via crafted packets to a TCP port.

    Published: 4 Apr 2016
    4.3
    Medium

    CVE-2016-0289

    Last Modified: 12 Apr 2025

    shiprec.xml in the SHIPREC application in IBM Maximo Asset Management 7.1 and 7.5 before 7.5.0.10 and 7.6 before 7.6.0.4 allows remote authenticated users to bypass intended item-selection restrictions via unspecified vectors.

    Published: 4 Apr 2016
    6.5
    Medium

    CVE-2016-2191

    Last Modified: 12 Apr 2025

    The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.

    Published: 4 Apr 2016
    7.5
    High

    CVE-2016-3071

    Last Modified: 12 Apr 2025

    Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

    Published: 4 Apr 2016
    8.1
    High

    CVE-2016-0363

    Last Modified: 12 Apr 2025

    The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController doPrivileged block, which allows remote attackers to call setSecurityManager and bypass a sandbox protection mechanism via vectors related to a Proxy object instance implementing the java.lang.reflect.InvocationHandler interface. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3009.

    Published: 4 Apr 2016
    5.5
    Medium

    CVE-2016-3076

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.

    Published: 4 Apr 2016
    5.5
    Medium

    CVE-2016-3977

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in util/gif2rgb.c in gif2rgb in giflib 5.1.2 allows remote attackers to cause a denial of service (application crash) via the background color index in a GIF file.

    Published: 4 Apr 2016
    7.5
    High

    CVE-2015-6360

    Last Modified: 12 Apr 2025

    The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted fields in SRTP packets, aka Bug ID CSCux00686.

    Published: 2 Apr 2016
    6.2
    Medium

    CVE-2016-0764

    Last Modified: 20 Apr 2025

    Race condition in Network Manager before 1.0.12 as packaged in Red Hat Enterprise Linux Desktop 7, Red Hat Enterprise Linux HPC Node 7, Red Hat Enterprise Linux Server 7, and Red Hat Enterprise Linux Workstation 7 allows local users to obtain sensitive connection information by reading temporary files during ifcfg and keyfile changes.

    Published: 2 Apr 2016
    7.5
    High

    CVE-2016-2289

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified vectors.

    Published: 1 Apr 2016
    9.8
    Critical

    CVE-2016-2343

    Last Modified: 12 Apr 2025

    Patterson Dental Eaglesoft 17 has a hardcoded password of sql for the dba account, which allows remote attackers to obtain sensitive Dental.DB patient information via SQL statements.

    Published: 1 Apr 2016
    Unknown

    CVE-2015-6264

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1349. Reason: This candidate is a reservation duplicate of CVE-2016-1349. Notes: All CVE users should reference CVE-2016-1349 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Apr 2016
    8.8
    High

    CVE-2016-1167

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users.

    Published: 1 Apr 2016
    8.8
    High

    CVE-2016-1168

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary users.

    Published: 1 Apr 2016
    8.2
    High

    CVE-2016-3947

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.

    Published: 1 Apr 2016
    5.5
    Medium

    CVE-2016-4489

    Last Modified: 20 Apr 2025

    Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtual tables."

    Published: 1 Apr 2016
    7.5
    High

    CVE-2016-3948

    Last Modified: 12 Apr 2025

    Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.

    Published: 1 Apr 2016
    7.5
    High

    CVE-2016-1345

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware protection via crafted fields in HTTP headers, aka Bug ID CSCux22726.

    Published: 1 Apr 2016
    5.5
    Medium

    CVE-2016-4490

    Last Modified: 20 Apr 2025

    Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths.

    Published: 1 Apr 2016