CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2016-2038

    Last Modified: 12 Apr 2025

    phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.

    Published: 20 Feb 2016
    5.3
    Medium

    CVE-2016-2039

    Last Modified: 12 Apr 2025

    libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.

    Published: 20 Feb 2016
    5.4
    Medium

    CVE-2016-2040

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.

    Published: 20 Feb 2016
    7.5
    High

    CVE-2016-2041

    Last Modified: 12 Apr 2025

    libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.

    Published: 20 Feb 2016
    5.4
    Medium

    CVE-2016-2045

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.

    Published: 20 Feb 2016
    9.8
    Critical

    CVE-2016-4344

    Last Modified: 12 Apr 2025

    Integer overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long argument to the utf8_encode function, leading to a heap-based buffer overflow.

    Published: 20 Feb 2016
    9.8
    Critical

    CVE-2016-4345

    Last Modified: 12 Apr 2025

    Integer overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.

    Published: 20 Feb 2016
    9.8
    Critical

    CVE-2016-4346

    Last Modified: 12 Apr 2025

    Integer overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a long string, leading to a heap-based buffer overflow.

    Published: 20 Feb 2016
    6.3
    Medium

    CVE-2015-7769

    Last Modified: 12 Apr 2025

    baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Published: 19 Feb 2016
    7.5
    High

    CVE-2016-1335

    Last Modified: 12 Apr 2025

    The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a connection from an endpoint that was previously used for an administrator's connection, aka Bug ID CSCux22492.

    Published: 19 Feb 2016
    5.7
    Medium

    CVE-2016-1156

    Last Modified: 12 Apr 2025

    LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.

    Published: 19 Feb 2016
    9.1
    Critical

    CVE-2016-1154

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 19 Feb 2016
    7.5
    High

    CVE-2016-10743

    Last Modified: 21 Nov 2024

    hostapd before 2.6 does not prevent use of the low-quality PRNG that is reached by an os_random() function call.

    Published: 19 Feb 2016
    Unknown

    CVE-2015-3825

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-3837. Reason: This candidate is a reservation duplicate of CVE-2015-3837. Notes: All CVE users should reference CVE-2015-3837 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Feb 2016
    9.1
    Critical

    CVE-2015-8151

    Last Modified: 12 Apr 2025

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.

    Published: 18 Feb 2016
    8.8
    High

    CVE-2016-0069

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0068.

    Published: 18 Feb 2016
    5.3
    Medium

    CVE-2015-5970

    Last Modified: 12 Apr 2025

    The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.

    Published: 18 Feb 2016
    7.5
    High

    CVE-2015-8148

    Last Modified: 12 Apr 2025

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.

    Published: 18 Feb 2016
    7.5
    High

    CVE-2015-8149

    Last Modified: 12 Apr 2025

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.

    Published: 18 Feb 2016
    7.8
    High

    CVE-2015-8150

    Last Modified: 12 Apr 2025

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

    Published: 18 Feb 2016
    8.8
    High

    CVE-2016-0068

    Last Modified: 12 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.

    Published: 18 Feb 2016
    5.9
    Medium

    CVE-2016-1987

    Last Modified: 12 Apr 2025

    HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.

    Published: 18 Feb 2016
    5.3
    Medium

    CVE-2016-2509

    Last Modified: 12 Apr 2025

    The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 18 Feb 2016
    Unknown

    CVE-2016-0722

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 18 Feb 2016
    Unknown

    CVE-2016-0716

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0729. Reason: This candidate is a reservation duplicate of CVE-2016-0729. Notes: All CVE users should reference CVE-2016-0729 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Feb 2016
    Unknown

    CVE-2016-0717

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0729. Reason: This candidate is a reservation duplicate of CVE-2016-0729. Notes: All CVE users should reference CVE-2016-0729 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 18 Feb 2016
    9.8
    Critical

    CVE-2015-8286

    Last Modified: 12 Apr 2025

    Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.

    Published: 18 Feb 2016
    5.3
    Medium

    CVE-2015-8287

    Last Modified: 12 Apr 2025

    Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL.

    Published: 18 Feb 2016
    9.8
    Critical

    CVE-2016-1629

    Last Modified: 12 Apr 2025

    Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.

    Published: 18 Feb 2016
    9.8
    Critical

    CVE-2016-0705

    Last Modified: 12 Apr 2025

    Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.

    Published: 18 Feb 2016
    6.5
    Medium

    CVE-2016-1333

    Last Modified: 12 Apr 2025

    Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.

    Published: 17 Feb 2016
    5.3
    Medium

    CVE-2016-1334

    Last Modified: 12 Apr 2025

    Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.

    Published: 17 Feb 2016
    6.5
    Medium

    CVE-2016-2398

    Last Modified: 12 Apr 2025

    Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions.

    Published: 17 Feb 2016
    9.8
    Critical

    CVE-2016-2397

    Last Modified: 12 Apr 2025

    The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.

    Published: 17 Feb 2016
    9.9
    Critical

    CVE-2016-2396

    Last Modified: 12 Apr 2025

    The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input.

    Published: 17 Feb 2016
    8.8
    High

    CVE-2016-0766

    Last Modified: 12 Apr 2025

    PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via unspecified vectors.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2016-2046

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 17 Feb 2016
    9.8
    Critical

    CVE-2016-2071

    Last Modified: 12 Apr 2025

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2016-2072

    Last Modified: 12 Apr 2025

    The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 17 Feb 2016
    5.4
    Medium

    CVE-2015-8486

    Last Modified: 12 Apr 2025

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2016-1149

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1150.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2016-1150

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, and CVE-2016-1149.

    Published: 17 Feb 2016
    8.8
    High

    CVE-2016-1151

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.

    Published: 17 Feb 2016
    5.4
    Medium

    CVE-2016-1152

    Last Modified: 12 Apr 2025

    Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2015-8486.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2015-7798

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2016-1149, and CVE-2016-1150.

    Published: 17 Feb 2016
    4.3
    Medium

    CVE-2015-8487

    Last Modified: 12 Apr 2025

    Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2015-7795

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2015-7796

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

    Published: 17 Feb 2016
    6.1
    Medium

    CVE-2015-7797

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-1149, and CVE-2016-1150.

    Published: 17 Feb 2016
    7.4
    High

    CVE-2015-8483

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

    Published: 17 Feb 2016