CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2016-10197

    Last Modified: 20 Apr 2025

    The search_make_new function in evdns.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (out-of-bounds read) via an empty hostname.

    Published: 3 Mar 2016
    7.6
    High

    CVE-2016-1577

    Last Modified: 12 Apr 2025

    Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.

    Published: 3 Mar 2016
    5.7
    Medium

    CVE-2016-2116

    Last Modified: 12 Apr 2025

    Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.

    Published: 3 Mar 2016
    6.1
    Medium

    CVE-2016-2279

    Last Modified: 3 Jun 2026

    Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Mar 2016
    7.2
    High

    CVE-2016-2278

    Last Modified: 12 Apr 2025

    Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

    Published: 2 Mar 2016
    8.8
    High

    CVE-2016-1632

    Last Modified: 12 Apr 2025

    The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass intended access restrictions via crafted JavaScript code that triggers an incorrect cast, related to extensions/renderer/v8_helpers.h and gin/converter.h.

    Published: 2 Mar 2016
    8.8
    High

    CVE-2016-1634

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the StyleResolver::appendCSSStyleSheet function in WebKit/Source/core/css/resolver/StyleResolver.cpp in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted web site that triggers Cascading Style Sheets (CSS) style invalidation during a certain subtree-removal action.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-4071

    Last Modified: 12 Apr 2025

    Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-1633

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in Blink, as used in Google Chrome before 49.0.2623.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-1639

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in browser/extensions/api/webrtc_audio_private/webrtc_audio_private_api.cc in the WebRTC Audio Private API implementation in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect reliance on the resource context pointer.

    Published: 2 Mar 2016
    4.3
    Medium

    CVE-2016-1640

    Last Modified: 12 Apr 2025

    The Web Store inline-installer implementation in the Extensions UI in Google Chrome before 49.0.2623.75 does not block installations upon deletion of an installation frame, which makes it easier for remote attackers to trick a user into believing that an installation request originated from the user's next navigation target via a crafted web site.

    Published: 2 Mar 2016
    8.8
    High

    CVE-2016-1630

    Last Modified: 12 Apr 2025

    The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 49.0.2623.75, mishandles widget updates, which makes it easier for remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 2 Mar 2016
    8.8
    High

    CVE-2016-1631

    Last Modified: 12 Apr 2025

    The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome before 49.0.2623.75 mishandles nested message loops, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

    Published: 2 Mar 2016
    6.2
    Medium

    CVE-2015-1339

    Last Modified: 12 Apr 2025

    Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.

    Published: 2 Mar 2016
    7
    High

    CVE-2016-1531

    Last Modified: 12 Apr 2025

    Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-1635

    Last Modified: 12 Apr 2025

    extensions/renderer/render_frame_observer_natives.cc in Google Chrome before 49.0.2623.75 does not properly consider object lifetimes and re-entrancy issues during OnDocumentElementCreated handling, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-1636

    Last Modified: 12 Apr 2025

    The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache information about integrity-check occurrences instead of integrity-check successes, which allows remote attackers to bypass the Subresource Integrity (aka SRI) protection mechanism by triggering two loads of the same resource.

    Published: 2 Mar 2016
    6.5
    Medium

    CVE-2016-1637

    Last Modified: 12 Apr 2025

    The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site.

    Published: 2 Mar 2016
    6.3
    Medium

    CVE-2016-1638

    Last Modified: 12 Apr 2025

    extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web APIs, which allows remote attackers to bypass intended access restrictions via a crafted platform app.

    Published: 2 Mar 2016
    8.8
    High

    CVE-2016-1641

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 49.0.2623.75 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering an image download after a certain data structure is deleted, as demonstrated by a favicon.ico download.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-1642

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 2 Mar 2016
    9.8
    Critical

    CVE-2016-2843

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.9.385.26, as used in Google Chrome before 49.0.2623.75, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 2 Mar 2016
    5.4
    Medium

    CVE-2016-2561

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.4.x before 4.4.15.5 and 4.5.x before 4.5.5.1 allow remote authenticated users to inject arbitrary web script or HTML via (1) normalization.php or (2) js/normalization.js in the database normalization page, (3) templates/database/structure/sortable_header.phtml in the database structure page, or (4) the pos parameter to db_central_columns.php in the central columns page.

    Published: 1 Mar 2016
    6.1
    Medium

    CVE-2016-2560

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.15, 4.4.x before 4.4.15.5, and 4.5.x before 4.5.5.1 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted Host HTTP header, related to libraries/Config.class.php; (2) crafted JSON data, related to file_echo.php; (3) a crafted SQL query, related to js/functions.js; (4) the initial parameter to libraries/server_privileges.lib.php in the user accounts page; or (5) the it parameter to libraries/controllers/TableSearchController.class.php in the zoom search page.

    Published: 1 Mar 2016
    6.8
    Medium

    CVE-2016-2562

    Last Modified: 12 Apr 2025

    The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL servers, which allows man-in-the-middle attackers to spoof these servers and obtain sensitive information via a crafted certificate.

    Published: 1 Mar 2016
    5.4
    Medium

    CVE-2016-2559

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the format function in libraries/sql-parser/src/Utils/Error.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.

    Published: 1 Mar 2016
    5.3
    Medium

    CVE-2016-1353

    Last Modified: 12 Apr 2025

    The TCP implementation in Cisco Videoscape Distribution Suite for Internet Streaming (VDS-IS) 3.3(0), 3.3(1), 4.0(0), and 4.1(0) does not properly initiate new TCP sessions when a previous session is in a FIN wait state, which allows remote attackers to cause a denial of service (TCP outage) via vectors involving FIN packets, aka Bug ID CSCuy45136.

    Published: 1 Mar 2016
    7.5
    High

    CVE-2016-2381

    Last Modified: 12 Apr 2025

    Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

    Published: 1 Mar 2016
    3.1
    Low

    CVE-2016-2513

    Last Modified: 12 Apr 2025

    The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests.

    Published: 1 Mar 2016
    5.9
    Medium

    CVE-2016-0703

    Last Modified: 12 Apr 2025

    The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.

    Published: 1 Mar 2016
    5.9
    Medium

    CVE-2016-0704

    Last Modified: 12 Apr 2025

    An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, a related issue to CVE-2016-0800.

    Published: 1 Mar 2016
    7.5
    High

    CVE-2016-0797

    Last Modified: 12 Apr 2025

    Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function, related to crypto/bn/bn.h and crypto/bn/bn_print.c.

    Published: 1 Mar 2016
    5.1
    Medium

    CVE-2016-0702

    Last Modified: 12 Apr 2025

    The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy Bridge CPU core as a victim and leveraging cache-bank conflicts, aka a "CacheBleed" attack.

    Published: 1 Mar 2016
    5.9
    Medium

    CVE-2016-0800

    Last Modified: 12 Apr 2025

    The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack.

    Published: 1 Mar 2016
    7.4
    High

    CVE-2016-2512

    Last Modified: 12 Apr 2025

    The utils.http.is_safe_url function in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks or possibly conduct cross-site scripting (XSS) attacks via a URL containing basic authentication, as demonstrated by http://mysite.example.com\@attacker.com.

    Published: 1 Mar 2016
    4.9
    Medium

    CVE-2016-0225

    Last Modified: 12 Apr 2025

    IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.

    Published: 29 Feb 2016
    5.4
    Medium

    CVE-2016-0245

    Last Modified: 12 Apr 2025

    The XML parser in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF10 allows remote authenticated users to read arbitrary files or cause a denial of service via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 29 Feb 2016
    7.4
    High

    CVE-2015-7428

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

    Published: 29 Feb 2016
    6.1
    Medium

    CVE-2016-0243

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0244.

    Published: 29 Feb 2016
    3.1
    Low

    CVE-2015-7455

    Last Modified: 12 Apr 2025

    IBM WebSphere Portal 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 uses weak permissions for content items, which allows remote authenticated users to make modifications via the authoring UI.

    Published: 29 Feb 2016
    6.1
    Medium

    CVE-2015-7457

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 29 Feb 2016
    5.4
    Medium

    CVE-2015-7491

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 8.0.x before 8.0.0.1 CF20 and 8.5.x before 8.5.0.0 CF09 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 29 Feb 2016
    6.1
    Medium

    CVE-2015-8524

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Process Portal in IBM Business Process Manager 8.5.0.x through 8.5.0.2, 8.5.5.x through 8.5.5.0, and 8.5.6.x through 8.5.6.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 29 Feb 2016
    9.8
    Critical

    CVE-2016-0212

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0213 and CVE-2016-0216.

    Published: 29 Feb 2016
    9.8
    Critical

    CVE-2016-0213

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0216.

    Published: 29 Feb 2016
    9.8
    Critical

    CVE-2016-0216

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in IBM Tivoli Storage Manager FastBack 5.5 and 6.1.x through 6.1.11.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, a different vulnerability than CVE-2016-0212 and CVE-2016-0213.

    Published: 29 Feb 2016
    6.1
    Medium

    CVE-2016-0244

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF29, 8.0.x before 8.0.0.1 CF20, and 8.5.x before 8.5.0.0 CF09 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2016-0243.

    Published: 29 Feb 2016
    5.3
    Medium

    CVE-2016-2097

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.2 and 4.x before 4.1.14.2 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-0752.

    Published: 29 Feb 2016
    7.3
    High

    CVE-2016-2098

    Last Modified: 12 Apr 2025

    Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

    Published: 29 Feb 2016
    6.1
    Medium

    CVE-2016-2103

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the list_1680466951_oldfilterval parameter to systems/PhysicalList.do or (2) unspecified vectors involving systems/VirtualSystemsList.do.

    Published: 29 Feb 2016