CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2016-2781

    Last Modified: 9 Jun 2025

    chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

    Published: 28 Feb 2016
    Unknown

    CVE-2016-2777

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-1868. Reason: This candidate is a reservation duplicate of CVE-2016-1868. Notes: All CVE users should reference CVE-2016-1868 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Feb 2016
    8.8
    High

    CVE-2015-6022

    Last Modified: 12 Apr 2025

    Unrestricted file upload vulnerability in QNAP Signage Station before 2.0.1 allows remote authenticated users to execute arbitrary code by uploading an executable file, and then accessing this file via an unspecified URL.

    Published: 27 Feb 2016
    7.5
    High

    CVE-2015-6036

    Last Modified: 12 Apr 2025

    QNAP Signage Station before 2.0.1 allows remote attackers to bypass authentication, and consequently upload files, via a spoofed HTTP request.

    Published: 27 Feb 2016
    7.5
    High

    CVE-2015-7262

    Last Modified: 12 Apr 2025

    QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, allows remote authenticated users to gain privileges by registering an executable file, and then waiting for this file to be run in a privileged context after a reboot.

    Published: 27 Feb 2016
    9.8
    Critical

    CVE-2015-7261

    Last Modified: 12 Apr 2025

    The FTP service in QNAP iArtist Lite before 1.4.54, as distributed with QNAP Signage Station before 2.0.1, has hardcoded credentials, which makes it easier for remote attackers to obtain access via a session on TCP port 21.

    Published: 27 Feb 2016
    8.8
    High

    CVE-2016-1297

    Last Modified: 12 Apr 2025

    The Device Manager GUI in Cisco Application Control Engine (ACE) 4710 A5 before A5(3.1) allows remote authenticated users to bypass intended RBAC restrictions and execute arbitrary CLI commands with admin privileges via an unspecified parameter in a POST request, aka Bug ID CSCul84801.

    Published: 26 Feb 2016
    5.3
    Medium

    CVE-2016-1342

    Last Modified: 12 Apr 2025

    The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654.

    Published: 26 Feb 2016
    Unknown

    CVE-2016-7575

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-7575. Reason: This candidate is a duplicate of CVE-2015-7575. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2015-7575 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Feb 2016
    7.8
    High

    CVE-2016-2521

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 on Windows allows local users to gain privileges via a Trojan horse riched20.dll.dll file in the current working directory, related to use of QLibrary.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2528

    Last Modified: 12 Apr 2025

    The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length values, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4417

    Last Modified: 12 Apr 2025

    Off-by-one error in epan/dissectors/packet-gsm_abis_oml.c in the GSM A-bis OML dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers a 0xff tag value.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4418

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet that triggers an empty set.

    Published: 26 Feb 2016
    9.8
    Critical

    CVE-2016-0799

    Last Modified: 12 Apr 2025

    The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2524

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2525

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2526

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.5
    Medium

    CVE-2016-2527

    Last Modified: 12 Apr 2025

    wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is present at the end of certain strings, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2523

    Last Modified: 12 Apr 2025

    The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2530

    Last Modified: 12 Apr 2025

    The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 mishandles the case of an unrecognized TLV type, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet, a different vulnerability than CVE-2016-2531.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2531

    Last Modified: 12 Apr 2025

    Off-by-one error in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that triggers a 0xff tag value, a different vulnerability than CVE-2016-2530.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2532

    Last Modified: 12 Apr 2025

    The dissect_llrp_parameters function in epan/dissectors/packet-llrp.c in the LLRP dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 does not limit the recursion depth, which allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted packet.

    Published: 26 Feb 2016
    7.8
    High

    CVE-2016-2779

    Last Modified: 20 Apr 2025

    runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4415

    Last Modified: 12 Apr 2025

    wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 2.x before 2.0.2 incorrectly increases a certain octet count, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted file.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4416

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 2.x before 2.0.2 mishandles the Grouping subfield, which allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4420

    Last Modified: 12 Apr 2025

    The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4421

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a denial of service (deep recursion, stack consumption, and application crash) via a packet that specifies deeply nested data.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-2522

    Last Modified: 12 Apr 2025

    The dissect_ber_constrained_bitstring function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 2.0.x before 2.0.2 does not verify that a certain length is nonzero, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Published: 26 Feb 2016
    5.5
    Medium

    CVE-2016-2529

    Last Modified: 12 Apr 2025

    The iseries_check_file_type function in wiretap/iseries.c in the iSeries file parser in Wireshark 2.0.x before 2.0.2 does not consider that a line may lack the "OBJECT PROTOCOL" substring, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

    Published: 26 Feb 2016
    5.9
    Medium

    CVE-2016-4419

    Last Modified: 12 Apr 2025

    epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to cause a denial of service (large loop) via a crafted packet.

    Published: 26 Feb 2016
    Unknown

    CVE-2015-3591

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-3591. Reason: This candidate is a duplicate of CVE-2014-3591. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-3591 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Feb 2016
    9.8
    Critical

    CVE-2016-0729

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.

    Published: 25 Feb 2016
    7.5
    High

    CVE-2016-0798

    Last Modified: 12 Apr 2025

    Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing an invalid username in a connection attempt, related to apps/s_server.c and crypto/srp/srp_vfy.c.

    Published: 25 Feb 2016
    9.8
    Critical

    CVE-2015-8277

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a.

    Published: 24 Feb 2016
    9.8
    Critical

    CVE-2016-1341

    Last Modified: 12 Apr 2025

    Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079.

    Published: 24 Feb 2016
    7.8
    High

    CVE-2016-2542

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file.

    Published: 24 Feb 2016
    6.1
    Medium

    CVE-2016-2104

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Red Hat Satellite 5 allow remote attackers to inject arbitrary web script or HTML via (1) the label parameter to admin/BunchDetail.do; (2) the package_name, (3) search_subscribed_channels, or (4) channel_filter parameter to software/packages/NameOverview.do; or unspecified vectors related to (5) <input:hidden> or (6) <bean:message> tags.

    Published: 24 Feb 2016
    9.8
    Critical

    CVE-2016-0791

    Last Modified: 12 Apr 2025

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.

    Published: 24 Feb 2016
    7.5
    High

    CVE-2016-2571

    Last Modified: 12 Apr 2025

    http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

    Published: 24 Feb 2016
    6.5
    Medium

    CVE-2016-3077

    Last Modified: 20 Apr 2025

    The VersionMapper.fromKernelVersionString method in oVirt Engine allows remote authenticated users to cause a denial of service (process crash) for all VMs.

    Published: 24 Feb 2016
    7.5
    High

    CVE-2016-2572

    Last Modified: 12 Apr 2025

    http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

    Published: 24 Feb 2016
    8.8
    High

    CVE-2016-0792

    Last Modified: 12 Apr 2025

    Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.

    Published: 24 Feb 2016
    7.5
    High

    CVE-2016-2569

    Last Modified: 12 Apr 2025

    Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.

    Published: 24 Feb 2016
    9.8
    Critical

    CVE-2016-0788

    Last Modified: 12 Apr 2025

    The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

    Published: 24 Feb 2016
    6.1
    Medium

    CVE-2016-0789

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 24 Feb 2016
    5.3
    Medium

    CVE-2016-0790

    Last Modified: 12 Apr 2025

    Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.

    Published: 24 Feb 2016
    7.5
    High

    CVE-2016-2570

    Last Modified: 12 Apr 2025

    The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.

    Published: 24 Feb 2016
    7.8
    High

    CVE-2016-2853

    Last Modified: 12 Apr 2025

    The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

    Published: 24 Feb 2016
    7.8
    High

    CVE-2016-2854

    Last Modified: 12 Apr 2025

    The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

    Published: 24 Feb 2016
    7.5
    High

    CVE-2013-7448

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in wiki.c in didiwiki allows remote attackers to read arbitrary files via the page parameter to api/page/get.

    Published: 23 Feb 2016