CVE Feed

    Dashboard / CVE

    5.9
    Medium

    CVE-2016-0771

    Last Modified: 12 Apr 2025

    The internal DNS server in Samba 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4, when an AD DC is configured, allows remote authenticated users to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory by uploading a crafted DNS TXT record.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1643

    Last Modified: 12 Apr 2025

    The ImageInputType::ensurePrimaryContent function in WebKit/Source/core/html/forms/ImageInputType.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly maintain the user agent shadow DOM, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1644

    Last Modified: 12 Apr 2025

    WebKit/Source/core/layout/LayoutObject.cpp in Blink, as used in Google Chrome before 49.0.2623.87, does not properly restrict relayout scheduling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted HTML document.

    Published: 8 Mar 2016
    4.3
    Medium

    CVE-2016-1955

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.

    Published: 8 Mar 2016
    6.5
    Medium

    CVE-2016-1956

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.

    Published: 8 Mar 2016
    4.3
    Medium

    CVE-2016-1957

    Last Modified: 12 Apr 2025

    Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.

    Published: 8 Mar 2016
    4.3
    Medium

    CVE-2016-1958

    Last Modified: 12 Apr 2025

    browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.

    Published: 8 Mar 2016
    7.4
    High

    CVE-2016-1963

    Last Modified: 12 Apr 2025

    The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1968

    Last Modified: 12 Apr 2025

    Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1969

    Last Modified: 12 Apr 2025

    The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1970

    Last Modified: 12 Apr 2025

    Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1973

    Last Modified: 12 Apr 2025

    Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.

    Published: 8 Mar 2016
    6.3
    Medium

    CVE-2016-1975

    Last Modified: 12 Apr 2025

    Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 8 Mar 2016
    5.5
    Medium

    CVE-2016-1976

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-1979

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted key data with DER encoding.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2793

    Last Modified: 12 Apr 2025

    CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2794

    Last Modified: 12 Apr 2025

    The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2797

    Last Modified: 12 Apr 2025

    The graphite2::TtfUtil::CmapSubtable12Lookup function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2801.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2798

    Last Modified: 12 Apr 2025

    The graphite2::GlyphCache::Loader::Loader function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2799

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    8.8
    High

    CVE-2016-2802

    Last Modified: 12 Apr 2025

    The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.

    Published: 8 Mar 2016
    5.9
    Medium

    CVE-2016-2774

    Last Modified: 12 Apr 2025

    ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing many sessions.

    Published: 7 Mar 2016
    7.5
    High

    CVE-2016-1234

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.

    Published: 7 Mar 2016
    9.8
    Critical

    CVE-2016-3132

    Last Modified: 12 Apr 2025

    Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.

    Published: 7 Mar 2016
    9.8
    Critical

    CVE-2016-2315

    Last Modified: 12 Apr 2025

    revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.

    Published: 6 Mar 2016
    9.8
    Critical

    CVE-2016-2324

    Last Modified: 12 Apr 2025

    Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.

    Published: 6 Mar 2016
    7.4
    High

    CVE-2016-3699

    Last Modified: 12 Apr 2025

    The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the initrd.

    Published: 5 Mar 2016
    5.3
    Medium

    CVE-2016-2283

    Last Modified: 12 Apr 2025

    Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt data, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

    Published: 4 Mar 2016
    5.9
    Medium

    CVE-2016-2244

    Last Modified: 12 Apr 2025

    HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 4 Mar 2016
    7.9
    High

    CVE-2016-2243

    Last Modified: 12 Apr 2025

    Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.

    Published: 4 Mar 2016
    5.3
    Medium

    CVE-2016-2282

    Last Modified: 12 Apr 2025

    Moxa ioLogik E2200 devices before 3.12 and ioAdmin Configuration Utility before 3.18 do not properly encrypt credentials, which makes it easier for remote attackers to obtain the associated cleartext via unspecified vectors.

    Published: 4 Mar 2016
    6.5
    Medium

    CVE-2016-7537

    Last Modified: 20 Apr 2025

    MagickCore/memory.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted PDB file.

    Published: 4 Mar 2016
    4.6
    Medium

    CVE-2016-3951

    Last Modified: 12 Apr 2025

    Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor.

    Published: 4 Mar 2016
    7.5
    High

    CVE-2015-0718

    Last Modified: 12 Apr 2025

    Cisco NX-OS 4.0 through 6.1 on Nexus 1000V 3000, 4000, 5000, 6000, and 7000 devices and Unified Computing System (UCS) platforms allows remote attackers to cause a denial of service (TCP stack reload) by sending crafted TCP packets to a device that has a TIME_WAIT TCP session, aka Bug ID CSCub70579.

    Published: 3 Mar 2016
    8.8
    High

    CVE-2016-1158

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on Corega CG-WLBARGMH and CG-WLBARGNL devices allows remote attackers to hijack the authentication of administrators for requests that perform administrative functions.

    Published: 3 Mar 2016
    5.3
    Medium

    CVE-2016-1357

    Last Modified: 12 Apr 2025

    The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut85211.

    Published: 3 Mar 2016
    6.4
    Medium

    CVE-2016-1358

    Last Modified: 12 Apr 2025

    Cisco Prime Infrastructure 2.2, 3.0, and 3.1(0.0) allows remote authenticated users to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuw81497.

    Published: 3 Mar 2016
    8.8
    High

    CVE-2016-1359

    Last Modified: 12 Apr 2025

    Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewing of a log file, aka Bug ID CSCuw81494.

    Published: 3 Mar 2016
    7.5
    High

    CVE-2015-6260

    Last Modified: 12 Apr 2025

    Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause a denial of service (SNMP application restart) via a crafted packet, aka Bug ID CSCut84645.

    Published: 3 Mar 2016
    5.4
    Medium

    CVE-2016-0227

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Mar 2016
    3.1
    Low

    CVE-2015-7490

    Last Modified: 12 Apr 2025

    IBM InfoSphere Information Server 8.5 through FP3, 8.7 through FP2, 9.1 through 9.1.2.0, 11.3 through 11.3.1.2, and 11.5 allows remote authenticated users to bypass intended access restrictions via a modified cookie.

    Published: 3 Mar 2016
    5.3
    Medium

    CVE-2016-1288

    Last Modified: 12 Apr 2025

    The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (service outage) by leveraging certain intranet connectivity and sending a malformed HTTPS request, aka Bug ID CSCuu24840.

    Published: 3 Mar 2016
    3.7
    Low

    CVE-2016-1356

    Last Modified: 12 Apr 2025

    Cisco FireSIGHT System Software 6.1.0 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to enumerate valid usernames by measuring timing differences, aka Bug ID CSCuy41615.

    Published: 3 Mar 2016
    6.1
    Medium

    CVE-2016-1354

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID CSCud41176.

    Published: 3 Mar 2016
    6.1
    Medium

    CVE-2016-1355

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Device Management UI in the management interface in Cisco FireSIGHT System Software 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy41687.

    Published: 3 Mar 2016
    9.8
    Critical

    CVE-2016-1329

    Last Modified: 12 Apr 2025

    Cisco NX-OS 6.0(2)U6(1) through 6.0(2)U6(5) on Nexus 3000 devices and 6.0(2)A6(1) through 6.0(2)A6(5) and 6.0(2)A7(1) on Nexus 3500 devices has hardcoded credentials, which allows remote attackers to obtain root privileges via a (1) TELNET or (2) SSH session, aka Bug ID CSCuy25800.

    Published: 3 Mar 2016
    5.3
    Medium

    CVE-2018-14621

    Last Modified: 21 Nov 2024

    An infinite loop vulnerability was found in libtirpc before version 1.0.2-rc2. With the port to using poll rather than select, exhaustion of file descriptors would cause the server to enter an infinite loop, consuming a large amount of CPU time and denying service to other clients until restarted.

    Published: 3 Mar 2016
    Unknown

    CVE-2016-8000

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0800. Reason: This candidate is a duplicate of CVE-2016-0800. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-0800 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 3 Mar 2016
    9.8
    Critical

    CVE-2016-2842

    Last Modified: 12 Apr 2025

    The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.

    Published: 3 Mar 2016
    7.5
    High

    CVE-2018-14622

    Last Modified: 21 Nov 2024

    A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to crash by flooding it with new connections.

    Published: 3 Mar 2016