CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-1723

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1725 and CVE-2016-1726.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-1726

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1725.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-1724

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1727.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-1725

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.2.1 and Safari before 9.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1723 and CVE-2016-1726.

    Published: 1 Feb 2016
    8.8
    High

    CVE-2016-1727

    Last Modified: 12 Apr 2025

    WebKit, as used in Apple iOS before 9.2.1, Safari before 9.0.3, and tvOS before 9.1.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-1724.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1721

    Last Modified: 12 Apr 2025

    The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1722

    Last Modified: 12 Apr 2025

    syslog in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1716

    Last Modified: 12 Apr 2025

    AppleGraphicsPowerManagement in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    7.3
    High

    CVE-2016-1718

    Last Modified: 12 Apr 2025

    The IOAcceleratorFamily2 interface in IOAcceleratorFamily in Apple OS X before 10.11.3 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1719

    Last Modified: 12 Apr 2025

    The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    7.8
    High

    CVE-2016-1720

    Last Modified: 12 Apr 2025

    IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 1 Feb 2016
    4.3
    Medium

    CVE-2016-1728

    Last Modified: 12 Apr 2025

    The Cascading Style Sheets (CSS) implementation in Apple iOS before 9.2.1 and Safari before 9.0.3 mishandles the "a:visited button" selector during height processing, which makes it easier for remote attackers to obtain sensitive browser-history information via a crafted web site.

    Published: 1 Feb 2016
    7.3
    High

    CVE-2016-1729

    Last Modified: 12 Apr 2025

    Untrusted search path vulnerability in OSA Scripts in Apple OS X before 10.11.3 allows attackers to load arbitrary script libraries via a quarantined application.

    Published: 1 Feb 2016
    5.4
    Medium

    CVE-2016-1730

    Last Modified: 12 Apr 2025

    WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.

    Published: 1 Feb 2016
    5.5
    Medium

    CVE-2016-2048

    Last Modified: 12 Apr 2025

    Django 1.9.x before 1.9.2, when ModelAdmin.save_as is set to True, allows remote authenticated users to bypass intended access restrictions and create ModelAdmin objects via the "Save as New" option when editing objects and leveraging the "change" permission.

    Published: 1 Feb 2016
    5.3
    Medium

    CVE-2016-2217

    Last Modified: 20 Apr 2025

    The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret.

    Published: 1 Feb 2016
    9.8
    Critical

    CVE-2016-4000

    Last Modified: 20 Apr 2025

    Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

    Published: 1 Feb 2016
    5.3
    Medium

    CVE-2016-1940

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.

    Published: 31 Jan 2016
    7.4
    High

    CVE-2016-1942

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.

    Published: 31 Jan 2016
    5.3
    Medium

    CVE-2016-1948

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.

    Published: 31 Jan 2016
    6.1
    Medium

    CVE-2016-1941

    Last Modified: 12 Apr 2025

    The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.

    Published: 31 Jan 2016
    9.8
    Critical

    CVE-2016-2554

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive.

    Published: 31 Jan 2016
    10
    Critical

    CVE-2016-1985

    Last Modified: 12 Apr 2025

    HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.

    Published: 30 Jan 2016
    7.5
    High

    CVE-2016-0867

    Last Modified: 12 Apr 2025

    CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.

    Published: 30 Jan 2016
    7.5
    High

    CVE-2016-1145

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 30 Jan 2016
    6.1
    Medium

    CVE-2016-1143

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in main.rb in Vine MV before 2015-11-08 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jan 2016
    5.4
    Medium

    CVE-2016-1144

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in JOB-CUBE -JOB WEB SYSTEM before 1.2.2 and -JOB WEB SYSTEM High Income 1.0.6 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jan 2016
    6.1
    Medium

    CVE-2016-1140

    Last Modified: 12 Apr 2025

    KDDI HOME SPOT CUBE devices before 2 allow remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 30 Jan 2016
    4.7
    Medium

    CVE-2016-1141

    Last Modified: 12 Apr 2025

    KDDI HOME SPOT CUBE devices before 2 allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Published: 30 Jan 2016
    5.4
    Medium

    CVE-2016-1136

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Jan 2016
    7.4
    High

    CVE-2016-1137

    Last Modified: 12 Apr 2025

    Open redirect vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 30 Jan 2016
    4.7
    Medium

    CVE-2016-1138

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to inject arbitrary HTTP headers via unspecified vectors.

    Published: 30 Jan 2016
    7.5
    High

    CVE-2016-1139

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on KDDI HOME SPOT CUBE devices before 2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 30 Jan 2016
    7.5
    High

    CVE-2016-1303

    Last Modified: 12 Apr 2025

    The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID CSCul65330.

    Published: 30 Jan 2016
    6.1
    Medium

    CVE-2016-1304

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux82596.

    Published: 30 Jan 2016
    6.1
    Medium

    CVE-2016-1488

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 30 Jan 2016
    9
    Critical

    CVE-2015-7923

    Last Modified: 12 Apr 2025

    Westermo WeOS before 4.19.0 uses the same SSL private key across different customers' installations, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection mechanisms by leveraging knowledge of a key.

    Published: 30 Jan 2016
    7.5
    High

    CVE-2017-5848

    Last Modified: 17 Mar 2026

    The gst_ps_demux_parse_psm function in gst/mpegdemux/gstmpegdemux.c in gst-plugins-bad in GStreamer allows remote attackers to cause a denial of service (invalid memory read and crash) via vectors involving PSM parsing.

    Published: 30 Jan 2016
    5.3
    Medium

    CVE-2016-0756

    Last Modified: 12 Apr 2025

    The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, which allows remote attackers to spoof XMPP network domains via a crafted stream id and domain name that is included in the target domain as a suffix.

    Published: 29 Jan 2016
    7.5
    High

    CVE-2016-1493

    Last Modified: 12 Apr 2025

    Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.

    Published: 29 Jan 2016
    8.3
    High

    CVE-2015-7521

    Last Modified: 12 Apr 2025

    The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations.

    Published: 29 Jan 2016
    7.5
    High

    CVE-2015-8773

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows attackers to cause a denial of service (system crash) via a long vault GUID in an ioctl call.

    Published: 29 Jan 2016
    9.1
    Critical

    CVE-2015-8772

    Last Modified: 12 Apr 2025

    McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large VERIFY_INFORMATION.Length value in an IOCTL_DISK_VERIFY ioctl call.

    Published: 29 Jan 2016
    5.3
    Medium

    CVE-2016-0754

    Last Modified: 12 Apr 2025

    cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a remote file name.

    Published: 29 Jan 2016
    7.5
    High

    CVE-2015-8770

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

    Published: 29 Jan 2016
    5.3
    Medium

    CVE-2015-8792

    Last Modified: 12 Apr 2025

    The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process heap memory via crafted EBML lacing, which triggers an invalid memory access.

    Published: 29 Jan 2016
    7.5
    High

    CVE-2016-1879

    Last Modified: 12 Apr 2025

    The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet.

    Published: 29 Jan 2016
    7.5
    High

    CVE-2016-1882

    Last Modified: 12 Apr 2025

    FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options.

    Published: 29 Jan 2016
    4.3
    Medium

    CVE-2015-8790

    Last Modified: 12 Apr 2025

    The EbmlUnicodeString::UpdateFromUTF8 function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted UTF-8 string, which triggers an invalid memory access.

    Published: 29 Jan 2016
    4.3
    Medium

    CVE-2015-8791

    Last Modified: 12 Apr 2025

    The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.

    Published: 29 Jan 2016