CVE Feed

    Dashboard / CVE

    8.4
    High

    CVE-2016-0805

    Last Modified: 12 Apr 2025

    The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25773204.

    Published: 7 Feb 2016
    8.4
    High

    CVE-2016-0806

    Last Modified: 12 Apr 2025

    The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application, aka internal bug 25344453.

    Published: 7 Feb 2016
    8.4
    High

    CVE-2016-0807

    Last Modified: 12 Apr 2025

    The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted application that mishandles a Desc Size element in an ELF Note, aka internal bug 25187394.

    Published: 7 Feb 2016
    6.2
    Medium

    CVE-2016-0808

    Last Modified: 12 Apr 2025

    Integer overflow in the getCoverageFormat12 function in CmapCoverage.cpp in the Minikin library in Android 5.x before 5.1.1 LMY49G and 6.x before 2016-02-01 allows attackers to cause a denial of service (continuous rebooting) via an application that triggers loading of a crafted TTF font, aka internal bug 25645298.

    Published: 7 Feb 2016
    8.8
    High

    CVE-2016-0809

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers to gain privileges by leveraging access to the local physical environment during execution of a crafted application, aka internal bug 25753768.

    Published: 7 Feb 2016
    6.1
    Medium

    CVE-2016-0812

    Last Modified: 12 Apr 2025

    The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.0 before 2016-02-01 does not properly check for setup completion, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25229538.

    Published: 7 Feb 2016
    6.1
    Medium

    CVE-2016-0813

    Last Modified: 12 Apr 2025

    packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before 2016-02-01 does not properly check for device provisioning, which allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25476219.

    Published: 7 Feb 2016
    5.3
    Medium

    CVE-2016-20012

    Last Modified: 29 May 2026

    OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product

    Published: 7 Feb 2016
    6.5
    Medium

    CVE-2016-7534

    Last Modified: 20 Apr 2025

    The generic decoder in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds access) via a crafted file.

    Published: 7 Feb 2016
    6.1
    Medium

    CVE-2016-1310

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy09033.

    Published: 6 Feb 2016
    6.1
    Medium

    CVE-2016-1311

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface in Cisco Jabber Guest Server 10.6(8) allows remote attackers to inject arbitrary web script or HTML via the host tag parameter, aka Bug ID CSCuy08224.

    Published: 6 Feb 2016
    8.1
    High

    CVE-2015-7914

    Last Modified: 12 Apr 2025

    Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.

    Published: 6 Feb 2016
    9.8
    Critical

    CVE-2015-7915

    Last Modified: 12 Apr 2025

    Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 6 Feb 2016
    6.5
    Medium

    CVE-2015-7916

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted query.

    Published: 6 Feb 2016
    6.1
    Medium

    CVE-2016-1306

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Fog Director 1.0(0) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCux80466.

    Published: 6 Feb 2016
    Unknown

    CVE-2015-6553

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn. Further investigation showed that it was not a security issue in customer-controlled software. Notes: none

    Published: 5 Feb 2016
    6.5
    Medium

    CVE-2016-0862

    Last Modified: 12 Apr 2025

    General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive cleartext account information via unspecified vectors.

    Published: 5 Feb 2016
    8.8
    High

    CVE-2016-0861

    Last Modified: 12 Apr 2025

    General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors.

    Published: 5 Feb 2016
    Unknown

    CVE-2015-2302

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6405. Reason: This candidate is a reservation duplicate of CVE-2014-6405. Notes: All CVE users should reference CVE-2014-6405 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2016
    Unknown

    CVE-2015-2303

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6406. Reason: This candidate is a reservation duplicate of CVE-2014-6406. Notes: All CVE users should reference CVE-2014-6406 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Feb 2016
    8.8
    High

    CVE-2016-1521

    Last Modified: 12 Apr 2025

    The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

    Published: 5 Feb 2016
    8.8
    High

    CVE-2016-1522

    Last Modified: 12 Apr 2025

    Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.

    Published: 5 Feb 2016
    5.5
    Medium

    CVE-2016-10371

    Last Modified: 20 Apr 2025

    The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted TIFF file.

    Published: 5 Feb 2016
    6.5
    Medium

    CVE-2016-1523

    Last Modified: 12 Apr 2025

    The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.

    Published: 5 Feb 2016
    8.1
    High

    CVE-2016-1526

    Last Modified: 12 Apr 2025

    The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, incorrectly validates a size value, which allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.

    Published: 5 Feb 2016
    7.8
    High

    CVE-2016-2226

    Last Modified: 20 Apr 2025

    Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

    Published: 5 Feb 2016
    6.5
    Medium

    CVE-2016-7527

    Last Modified: 20 Apr 2025

    coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 5 Feb 2016
    6.5
    Medium

    CVE-2016-7533

    Last Modified: 20 Apr 2025

    The ReadWPGImage function in coders/wpg.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WPG file.

    Published: 5 Feb 2016
    7.1
    High

    CVE-2016-2538

    Last Modified: 12 Apr 2025

    Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS control message packet that is mishandled in the (1) rndis_query_response, (2) rndis_set_response, or (3) usb_net_handle_dataout function.

    Published: 5 Feb 2016
    7.5
    High

    CVE-2015-8269

    Last Modified: 12 Apr 2025

    The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.

    Published: 4 Feb 2016
    5.9
    Medium

    CVE-2016-1284

    Last Modified: 12 Apr 2025

    rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query.

    Published: 4 Feb 2016
    6.5
    Medium

    CVE-2016-0740

    Last Modified: 12 Apr 2025

    Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.

    Published: 4 Feb 2016
    4.3
    Medium

    CVE-2016-0757

    Last Modified: 12 Apr 2025

    OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload new image data by removing the last location of an image.

    Published: 4 Feb 2016
    6.5
    Medium

    CVE-2016-0775

    Last Modified: 12 Apr 2025

    Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.

    Published: 4 Feb 2016
    5.3
    Medium

    CVE-2015-8748

    Last Modified: 12 Apr 2025

    Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as demonstrated by ".*".

    Published: 3 Feb 2016
    10
    Critical

    CVE-2015-8747

    Last Modified: 12 Apr 2025

    The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.

    Published: 3 Feb 2016
    10
    Critical

    CVE-2016-1505

    Last Modified: 12 Apr 2025

    The filesystem storage backend in Radicale before 1.1 on Windows allows remote attackers to read or write to arbitrary files via a crafted path, as demonstrated by /c:/file/ignore.

    Published: 3 Feb 2016
    6.5
    Medium

    CVE-2016-2213

    Last Modified: 12 Apr 2025

    The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data.

    Published: 3 Feb 2016
    6.8
    Medium

    CVE-2016-0774

    Last Modified: 12 Apr 2025

    The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on Debian wheezy and the kernel package before 3.10.0-229.26.2 on Red Hat Enterprise Linux (RHEL) 7.1 do not properly consider the side effects of failed __copy_to_user_inatomic and __copy_from_user_inatomic calls, which allows local users to cause a denial of service (system crash) or possibly gain privileges via a crafted application, aka an "I/O vector array overrun." NOTE: this vulnerability exists because of an incorrect fix for CVE-2015-1805.

    Published: 2 Feb 2016
    5
    Medium

    CVE-2016-7917

    Last Modified: 12 Apr 2025

    The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability.

    Published: 2 Feb 2016
    9.8
    Critical

    CVE-2015-8803

    Last Modified: 12 Apr 2025

    The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805.

    Published: 2 Feb 2016
    9.8
    Critical

    CVE-2015-8804

    Last Modified: 12 Apr 2025

    x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors.

    Published: 2 Feb 2016
    9.8
    Critical

    CVE-2015-8805

    Last Modified: 12 Apr 2025

    The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803.

    Published: 2 Feb 2016
    6
    Medium

    CVE-2016-2841

    Last Modified: 12 Apr 2025

    The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP registers, involving ring buffer control.

    Published: 2 Feb 2016
    8.2
    High

    CVE-2016-3142

    Last Modified: 12 Apr 2025

    The phar_parse_zipfile function in zip.c in the PHAR extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read and application crash) by placing a PK\x05\x06 signature at an invalid location.

    Published: 2 Feb 2016
    Unknown

    CVE-2016-7028

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0728. Reason: This candidate is a duplicate of CVE-2016-0728. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-0728 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Feb 2016
    7.5
    High

    CVE-2015-8265

    Last Modified: 12 Apr 2025

    Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C00 allow DNS query packets using the static source port, which makes it easier for remote attackers to spoof responses via unspecified vectors.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-2049

    Last Modified: 12 Apr 2025

    examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might allow remote attackers to hijack the authentication of arbitrary users via vectors involving a crafted HTTP Host header.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-2199

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Organizations and Remediation management page in Enterprise Manager in McAfee Vulnerability Manager (MVM) before 7.5.10 allow remote attackers to hijack the authentication of administrators for requests that have unspecified impact via unknown vectors.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1717

    Last Modified: 12 Apr 2025

    The Disk Images component in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016