CVE Feed

    Dashboard / CVE

    9.1
    Critical

    CVE-2016-3065

    Last Modified: 12 Apr 2025

    The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to bypass intended access restrictions and consequently obtain sensitive server memory information or cause a denial of service (server crash) via a crafted bytea value in a BRIN index page.

    Published: 31 Mar 2016
    7.8
    High

    CVE-2016-3096

    Last Modified: 12 Apr 2025

    The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.

    Published: 31 Mar 2016
    5.1
    Medium

    CVE-2015-8839

    Last Modified: 12 Apr 2025

    Multiple race conditions in the ext4 filesystem implementation in the Linux kernel before 4.5 allow local users to cause a denial of service (disk corruption) by writing to a page that is associated with a different user's file after unsynchronized hole punching and page-fault handling.

    Published: 31 Mar 2016
    7.5
    High

    CVE-2016-2193

    Last Modified: 12 Apr 2025

    PostgreSQL before 9.5.x before 9.5.2 does not properly maintain row-security status in cached plans, which might allow attackers to bypass intended access restrictions by leveraging a session that performs queries as more than one role.

    Published: 31 Mar 2016
    5.5
    Medium

    CVE-2016-3095

    Last Modified: 20 Apr 2025

    server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.

    Published: 31 Mar 2016
    6.1
    Medium

    CVE-2016-3097

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via a group name, related to viewing snapshot data.

    Published: 31 Mar 2016
    5.5
    Medium

    CVE-2016-4488

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."

    Published: 31 Mar 2016
    5.5
    Medium

    CVE-2016-4487

    Last Modified: 20 Apr 2025

    Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."

    Published: 31 Mar 2016
    7.5
    High

    CVE-2016-3956

    Last Modified: 12 Apr 2025

    The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers.

    Published: 31 Mar 2016
    7.8
    High

    CVE-2016-2063

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the supply_lm_input_write function in drivers/thermal/supply_lm_core.c in the MSM Thermal driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted application that sends a large amount of data through the debugfs interface.

    Published: 30 Mar 2016
    7.5
    High

    CVE-2015-8851

    Last Modified: 21 Nov 2024

    node-uuid before 1.4.4 uses insufficiently random data to create a GUID, which could make it easier for attackers to have unspecified impact via brute force guessing.

    Published: 30 Mar 2016
    8.8
    High

    CVE-2016-3616

    Last Modified: 20 Apr 2025

    The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

    Published: 30 Mar 2016
    6.2
    Medium

    CVE-2016-3186

    Last Modified: 12 Apr 2025

    Buffer overflow in the readextension function in gif2tiff.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (application crash) via a crafted GIF file.

    Published: 30 Mar 2016
    6.2
    Medium

    CVE-2016-1760

    Last Modified: 12 Apr 2025

    The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app's events via a crafted app.

    Published: 29 Mar 2016
    7.8
    High

    CVE-2016-2288

    Last Modified: 12 Apr 2025

    Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file.

    Published: 29 Mar 2016
    8.2
    High

    CVE-2016-5362

    Last Modified: 12 Apr 2025

    The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP discovery message.

    Published: 29 Mar 2016
    8.2
    High

    CVE-2016-5363

    Last Modified: 12 Apr 2025

    The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP discovery message or (2) crafted non-IP traffic.

    Published: 29 Mar 2016
    8.8
    High

    CVE-2016-3068

    Last Modified: 12 Apr 2025

    Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

    Published: 29 Mar 2016
    8.8
    High

    CVE-2016-3069

    Last Modified: 12 Apr 2025

    Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

    Published: 29 Mar 2016
    6.1
    Medium

    CVE-2016-3079

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Web UI in Spacewalk and Red Hat Satellite 5.7 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to systems/SystemEntitlements.do; (2) the label parameter to admin/multiorg/EntitlementDetails.do; or the name of a (3) snapshot tag or (4) system group in System Set Manager (SSM).

    Published: 29 Mar 2016
    8.8
    High

    CVE-2016-3630

    Last Modified: 12 Apr 2025

    The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.

    Published: 29 Mar 2016
    7.5
    High

    CVE-2016-3075

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.

    Published: 29 Mar 2016
    6.1
    Medium

    CVE-2016-3080

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in spacewalk-java in Red Hat Satellite 5.7 allows remote attackers to inject arbitrary web script or HTML via the (1) RHNMD User or (2) Filesystem parameters, related to display of monitoring probes.

    Published: 29 Mar 2016
    7.8
    High

    CVE-2016-0226

    Last Modified: 12 Apr 2025

    The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.

    Published: 28 Mar 2016
    6.1
    Medium

    CVE-2016-1314

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (CDM) 8.1(1) allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux80760.

    Published: 28 Mar 2016
    7.5
    High

    CVE-2016-2344

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in manager.exe in Backburner Manager in Autodesk Backburner 2016 2016.0.0.2150 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted command. NOTE: this is only a vulnerability in environments in which the administrator has not followed documentation that outlines the security risks of operating Backburner on untrusted networks.

    Published: 28 Mar 2016
    9.8
    Critical

    CVE-2016-2074

    Last Modified: 12 Apr 2025

    Buffer overflow in lib/flow.c in ovs-vswitchd in Open vSwitch 2.2.x and 2.3.x before 2.3.3 and 2.4.x before 2.4.1 allows remote attackers to execute arbitrary code via crafted MPLS packets, as demonstrated by a long string in an ovs-appctl command.

    Published: 28 Mar 2016
    5.5
    Medium

    CVE-2016-4797

    Last Modified: 20 Apr 2025

    Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.

    Published: 28 Mar 2016
    5.9
    Medium

    CVE-2016-1344

    Last Modified: 12 Apr 2025

    The IKEv2 implementation in Cisco IOS 15.0 through 15.6 and IOS XE 3.3 through 3.17 allows remote attackers to cause a denial of service (device reload) via fragmented packets, aka Bug ID CSCux38417.

    Published: 26 Mar 2016
    7.5
    High

    CVE-2016-1349

    Last Modified: 12 Apr 2025

    The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

    Published: 26 Mar 2016
    7.5
    High

    CVE-2016-1350

    Last Modified: 12 Apr 2025

    Cisco IOS 15.3 and 15.4, Cisco IOS XE 3.8 through 3.11, and Cisco Unified Communications Manager allow remote attackers to cause a denial of service (device reload) via malformed SIP messages, aka Bug ID CSCuj23293.

    Published: 26 Mar 2016
    7.5
    High

    CVE-2016-1351

    Last Modified: 12 Apr 2025

    The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a denial of service (device reload) via a crafted header in a packet, aka Bug ID CSCuu64279.

    Published: 26 Mar 2016
    6.1
    Medium

    CVE-2016-1160

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WP Favorite Posts plugin before 1.6.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Mar 2016
    7.5
    High

    CVE-2016-1348

    Last Modified: 12 Apr 2025

    Cisco IOS 15.0 through 15.5 and IOS XE 3.3 through 3.16 allow remote attackers to cause a denial of service (device reload) via a crafted DHCPv6 Relay message, aka Bug ID CSCus55821.

    Published: 26 Mar 2016
    9.8
    Critical

    CVE-2016-4073

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the mbfl_strcut function in ext/mbstring/libmbfl/mbfl/mbfilter.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted mb_strcut call.

    Published: 26 Mar 2016
    5.4
    Medium

    CVE-2016-2340

    Last Modified: 12 Apr 2025

    The AMF framework in Granite Data Services 3.1.1-SNAPSHOT allows remote authenticated users to read arbitrary files, send TCP requests to intranet servers, or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 25 Mar 2016
    7.5
    High

    CVE-2016-1347

    Last Modified: 12 Apr 2025

    The Wide Area Application Services (WAAS) Express implementation in Cisco IOS 15.1 through 15.5 allows remote attackers to cause a denial of service (device reload) via a crafted TCP segment, aka Bug ID CSCuq59708.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1366

    Last Modified: 12 Apr 2025

    The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denial of service (overwrite) via unspecified vectors, aka Bug ID CSCuw75848.

    Published: 24 Mar 2016
    8.1
    High

    CVE-2016-1762

    Last Modified: 17 Dec 2025

    The xmlNextChar function in libxml2 before 2.9.4 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

    Published: 24 Mar 2016
    5.5
    Medium

    CVE-2016-1732

    Last Modified: 12 Apr 2025

    AppleRAID in Apple OS X before 10.11.4 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1735

    Last Modified: 12 Apr 2025

    Bluetooth in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1736.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1744

    Last Modified: 12 Apr 2025

    The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.

    Published: 24 Mar 2016
    5.5
    Medium

    CVE-2016-1752

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to cause a denial of service via a crafted app.

    Published: 24 Mar 2016
    9.8
    Critical

    CVE-2016-1761

    Last Modified: 12 Apr 2025

    libxml2 in Apple iOS before 9.3, OS X before 10.11.4, and watchOS before 2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.

    Published: 24 Mar 2016
    7.8
    High

    CVE-2016-1767

    Last Modified: 12 Apr 2025

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1768.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1771

    Last Modified: 12 Apr 2025

    The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.

    Published: 24 Mar 2016
    6.5
    Medium

    CVE-2016-1779

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request.

    Published: 24 Mar 2016
    8.8
    High

    CVE-2016-1783

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 24 Mar 2016
    5.4
    Medium

    CVE-2016-1786

    Last Modified: 12 Apr 2025

    The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status code, which allows remote attackers to spoof the displayed URL, bypass the Same Origin Policy, and obtain sensitive cached information via a crafted web site.

    Published: 24 Mar 2016
    5.3
    Medium

    CVE-2016-1787

    Last Modified: 12 Apr 2025

    Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.

    Published: 24 Mar 2016