CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2016-2383

    Last Modified: 12 Apr 2025

    The adjust_branches function in kernel/bpf/verifier.c in the Linux kernel before 4.5 does not consider the delta in the backward-jump case, which allows local users to obtain sensitive information from kernel memory by creating a packet filter and then loading crafted BPF instructions.

    Published: 14 Feb 2016
    5.5
    Medium

    CVE-2016-10070

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.

    Published: 14 Feb 2016
    7.8
    High

    CVE-2016-10065

    Last Modified: 20 Apr 2025

    The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file.

    Published: 14 Feb 2016
    5.5
    Medium

    CVE-2016-10071

    Last Modified: 20 Apr 2025

    coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.

    Published: 14 Feb 2016
    4.6
    Medium

    CVE-2016-2384

    Last Modified: 12 Apr 2025

    Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.

    Published: 14 Feb 2016
    9.8
    Critical

    CVE-2016-3141

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

    Published: 14 Feb 2016
    6.5
    Medium

    CVE-2016-7536

    Last Modified: 20 Apr 2025

    magick/profile.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted profile.

    Published: 14 Feb 2016
    8.8
    High

    CVE-2016-0863

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.

    Published: 13 Feb 2016
    5.3
    Medium

    CVE-2016-0864

    Last Modified: 12 Apr 2025

    Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.

    Published: 13 Feb 2016
    8.8
    High

    CVE-2016-0865

    Last Modified: 12 Apr 2025

    Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.

    Published: 13 Feb 2016
    6.1
    Medium

    CVE-2016-0866

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Feb 2016
    9.6
    Critical

    CVE-2016-1524

    Last Modified: 12 Apr 2025

    Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote attackers to execute arbitrary Java code by using (1) fileUpload.do or (2) lib-1.0/external/flash/fileUpload.do to upload a JSP file, and then accessing it via a direct request for a /null URI.

    Published: 13 Feb 2016
    8.6
    High

    CVE-2016-1525

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allows remote authenticated users to read arbitrary files via a .. (dot dot) in the realName parameter.

    Published: 13 Feb 2016
    8.8
    High

    CVE-2016-2327

    Last Modified: 12 Apr 2025

    libavcodec/pngenc.c in FFmpeg before 2.8.5 uses incorrect line sizes in certain row calculations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .avi file, related to the apng_encode_frame and encode_apng functions.

    Published: 12 Feb 2016
    8.8
    High

    CVE-2016-2326

    Last Modified: 12 Apr 2025

    Integer overflow in the asf_write_packet function in libavformat/asfenc.c in FFmpeg before 2.8.5 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PTS (aka presentation timestamp) value in a .mov file.

    Published: 12 Feb 2016
    8.8
    High

    CVE-2016-2328

    Last Modified: 12 Apr 2025

    libswscale/swscale_unscaled.c in FFmpeg before 2.8.6 does not validate certain height values, which allows remote attackers to cause a denial of service (out-of-bounds array read access) or possibly have unspecified other impact via a crafted .cine file, related to the bayer_to_rgb24_wrapper and bayer_to_yv12_wrapper functions.

    Published: 12 Feb 2016
    8.8
    High

    CVE-2016-2329

    Last Modified: 12 Apr 2025

    libavcodec/tiff.c in FFmpeg before 2.8.6 does not properly validate RowsPerStrip values and YCbCr chrominance subsampling factors, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted TIFF file, related to the tiff_decode_tag and decode_frame functions.

    Published: 12 Feb 2016
    8.8
    High

    CVE-2016-2330

    Last Modified: 12 Apr 2025

    libavcodec/gif.c in FFmpeg before 2.8.6 does not properly calculate a buffer size, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via a crafted .tga file, related to the gif_image_write_image, gif_encode_init, and gif_encode_close functions.

    Published: 12 Feb 2016
    6.5
    Medium

    CVE-2016-0881

    Last Modified: 12 Apr 2025

    EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.

    Published: 12 Feb 2016
    5.4
    Medium

    CVE-2016-0882

    Last Modified: 12 Apr 2025

    EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 12 Feb 2016
    7.5
    High

    CVE-2016-1315

    Last Modified: 12 Apr 2025

    The proxy engine in Cisco Advanced Malware Protection (AMP), when used with Email Security Appliance (ESA) 9.5.0-201, 9.6.0-051, and 9.7.0-125, allows remote attackers to bypass intended content restrictions via a malformed e-mail message containing an encoded file, aka Bug ID CSCux45338.

    Published: 12 Feb 2016
    5.3
    Medium

    CVE-2016-1324

    Last Modified: 12 Apr 2025

    The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125.

    Published: 12 Feb 2016
    6.7
    Medium

    CVE-2016-1320

    Last Modified: 12 Apr 2025

    The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.

    Published: 12 Feb 2016
    7.5
    High

    CVE-2016-1322

    Last Modified: 12 Apr 2025

    The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584.

    Published: 12 Feb 2016
    4.3
    Medium

    CVE-2016-1323

    Last Modified: 12 Apr 2025

    The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048.

    Published: 12 Feb 2016
    9.8
    Critical

    CVE-2016-1986

    Last Modified: 12 Apr 2025

    HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 12 Feb 2016
    6.5
    Medium

    CVE-2016-7535

    Last Modified: 20 Apr 2025

    coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted PSD file.

    Published: 12 Feb 2016
    9.8
    Critical

    CVE-2016-1287

    Last Modified: 12 Apr 2025

    Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0 before 9.0(4.38), 9.1 before 9.1(7), 9.2 before 9.2(4.5), 9.3 before 9.3(3.7), 9.4 before 9.4(2.4), and 9.5 before 9.5(2.2) on ASA 5500 devices, ASA 5500-X devices, ASA Services Module for Cisco Catalyst 6500 and Cisco 7600 devices, ASA 1000V devices, Adaptive Security Virtual Appliance (aka ASAv), Firepower 9300 ASA Security Module, and ISA 3000 devices allows remote attackers to execute arbitrary code or cause a denial of service (device reload) via crafted UDP packets, aka Bug IDs CSCux29978 and CSCux42019.

    Published: 11 Feb 2016
    5.5
    Medium

    CVE-2016-2085

    Last Modified: 12 Apr 2025

    The evm_verify_hmac function in security/integrity/evm/evm_main.c in the Linux kernel before 4.5 does not properly copy data, which makes it easier for local users to forge MAC values via a timing side-channel attack.

    Published: 11 Feb 2016
    8.8
    High

    CVE-2016-1949

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.

    Published: 11 Feb 2016
    9.8
    Critical

    CVE-2015-8812

    Last Modified: 12 Apr 2025

    drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.

    Published: 11 Feb 2016
    7.5
    High

    CVE-2016-0793

    Last Modified: 12 Apr 2025

    Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on Windows allows remote attackers to read the sensitive files in the (1) WEB-INF or (2) META-INF directory via a request that contains (a) lowercase or (b) "meaningless" characters.

    Published: 11 Feb 2016
    7.5
    High

    CVE-2016-0773

    Last Modified: 12 Apr 2025

    PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regular expression.

    Published: 11 Feb 2016
    3.3
    Low

    CVE-2016-1544

    Last Modified: 21 Nov 2024

    nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).

    Published: 11 Feb 2016
    6.5
    Medium

    CVE-2016-2392

    Last Modified: 12 Apr 2025

    The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors involving a remote NDIS control message packet.

    Published: 11 Feb 2016
    9.8
    Critical

    CVE-2016-0953

    Last Modified: 12 Apr 2025

    Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

    Published: 10 Feb 2016
    6.1
    Medium

    CVE-2016-0955

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.

    Published: 10 Feb 2016
    7.5
    High

    CVE-2016-0957

    Last Modified: 12 Apr 2025

    Dispatcher before 4.1.5 in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 does not properly implement a URL filter, which allows remote attackers to bypass dispatcher rules via unspecified vectors.

    Published: 10 Feb 2016
    9.8
    Critical

    CVE-2016-0952

    Last Modified: 12 Apr 2025

    Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.

    Published: 10 Feb 2016
    8.8
    High

    CVE-2016-0948

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Adobe Connect before 9.5.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 10 Feb 2016
    9.8
    Critical

    CVE-2016-0949

    Last Modified: 12 Apr 2025

    Adobe Connect before 9.5.2 allows remote attackers to have an unspecified impact via a crafted parameter in a URL.

    Published: 10 Feb 2016
    5.3
    Medium

    CVE-2016-0950

    Last Modified: 12 Apr 2025

    Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.

    Published: 10 Feb 2016
    9.8
    Critical

    CVE-2016-0951

    Last Modified: 12 Apr 2025

    Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.

    Published: 10 Feb 2016
    7.5
    High

    CVE-2016-0956

    Last Modified: 12 Apr 2025

    The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 10 Feb 2016
    7.5
    High

    CVE-2016-0958

    Last Modified: 12 Apr 2025

    Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.

    Published: 10 Feb 2016
    4.3
    Medium

    CVE-2015-7677

    Last Modified: 12 Apr 2025

    The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.

    Published: 10 Feb 2016
    8.8
    High

    CVE-2015-7678

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Ipswitch MOVEit Mobile 1.2.0.962 and earlier allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 10 Feb 2016
    6.5
    Medium

    CVE-2015-7675

    Last Modified: 12 Apr 2025

    The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.

    Published: 10 Feb 2016
    6.1
    Medium

    CVE-2015-7679

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.

    Published: 10 Feb 2016
    5.3
    Medium

    CVE-2015-7680

    Last Modified: 12 Apr 2025

    Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.

    Published: 10 Feb 2016