CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2016-1946

    Last Modified: 12 Apr 2025

    The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.

    Published: 26 Jan 2016
    7.5
    High

    CVE-2016-0742

    Last Modified: 12 Apr 2025

    The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

    Published: 26 Jan 2016
    5.3
    Medium

    CVE-2016-0747

    Last Modified: 12 Apr 2025

    The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

    Published: 26 Jan 2016
    7.5
    High

    CVE-2015-8806

    Last Modified: 12 Apr 2025

    dict.c in libxml2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via an unexpected character immediately after the "<!DOCTYPE html" substring in a crafted HTML document.

    Published: 26 Jan 2016
    6.5
    Medium

    CVE-2016-1933

    Last Modified: 12 Apr 2025

    Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.

    Published: 26 Jan 2016
    8.8
    High

    CVE-2016-1935

    Last Modified: 12 Apr 2025

    Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.

    Published: 26 Jan 2016
    6.1
    Medium

    CVE-2016-1937

    Last Modified: 12 Apr 2025

    The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.

    Published: 26 Jan 2016
    6.5
    Medium

    CVE-2016-1938

    Last Modified: 12 Apr 2025

    The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.

    Published: 26 Jan 2016
    4.7
    Medium

    CVE-2016-1943

    Last Modified: 12 Apr 2025

    Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.

    Published: 26 Jan 2016
    9.8
    Critical

    CVE-2016-1944

    Last Modified: 12 Apr 2025

    The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 26 Jan 2016
    8.8
    High

    CVE-2016-1945

    Last Modified: 12 Apr 2025

    The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.

    Published: 26 Jan 2016
    6.5
    Medium

    CVE-2016-4055

    Last Modified: 20 Apr 2025

    The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."

    Published: 26 Jan 2016
    7.5
    High

    CVE-2016-0752

    Last Modified: 22 Apr 2026

    Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a pathname.

    Published: 25 Jan 2016
    6.5
    Medium

    CVE-2016-2073

    Last Modified: 12 Apr 2025

    The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document.

    Published: 25 Jan 2016
    7.5
    High

    CVE-2015-7581

    Last Modified: 12 Apr 2025

    actionpack/lib/action_dispatch/routing/route_set.rb in Action Pack in Ruby on Rails 4.x before 4.2.5.1 and 5.x before 5.0.0.beta1.1 allows remote attackers to cause a denial of service (superfluous caching and memory consumption) by leveraging an application's use of a wildcard controller route.

    Published: 25 Jan 2016
    7.4
    High

    CVE-2016-2069

    Last Modified: 12 Apr 2025

    Race condition in arch/x86/mm/tlb.c in the Linux kernel before 4.4.1 allows local users to gain privileges by triggering access to a paging structure by a different CPU.

    Published: 25 Jan 2016
    3.7
    Low

    CVE-2015-7576

    Last Modified: 12 Apr 2025

    The http_basic_authenticate_with method in actionpack/lib/action_controller/metal/http_authentication.rb in the Basic Authentication implementation in Action Controller in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not use a constant-time algorithm for verifying credentials, which makes it easier for remote attackers to bypass authentication by measuring timing differences.

    Published: 25 Jan 2016
    7.5
    High

    CVE-2016-0751

    Last Modified: 12 Apr 2025

    actionpack/lib/action_dispatch/http/mime_type.rb in Action Pack in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly restrict use of the MIME type cache, which allows remote attackers to cause a denial of service (memory consumption) via a crafted HTTP Accept header.

    Published: 25 Jan 2016
    5.5
    Medium

    CVE-2014-8180

    Last Modified: 20 Apr 2025

    MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.

    Published: 25 Jan 2016
    7.8
    High

    CVE-2015-7552

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the gdk_pixbuf_flip function in gdk-pixbuf-scale.c in gdk-pixbuf 2.30.x allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted BMP file.

    Published: 25 Jan 2016
    5.3
    Medium

    CVE-2015-7577

    Last Modified: 12 Apr 2025

    activerecord/lib/active_record/nested_attributes.rb in Active Record in Ruby on Rails 3.1.x and 3.2.x before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 does not properly implement a certain destroy option, which allows remote attackers to bypass intended change restrictions by leveraging use of the nested attributes feature.

    Published: 25 Jan 2016
    5.3
    Medium

    CVE-2016-0753

    Last Modified: 12 Apr 2025

    Active Model in Ruby on Rails 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 supports the use of instance-level writers for class accessors, which allows remote attackers to bypass intended validation steps via crafted parameters.

    Published: 25 Jan 2016
    8.1
    High

    CVE-2016-1866

    Last Modified: 12 Apr 2025

    Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary code by inserting packets into the minion-master data stream.

    Published: 25 Jan 2016
    4.7
    Medium

    CVE-2016-2053

    Last Modified: 12 Apr 2025

    The asn1_ber_decoder function in lib/asn1_decoder.c in the Linux kernel before 4.3 allows attackers to cause a denial of service (panic) via an ASN.1 BER file that lacks a public key, leading to mishandling by the public_key_verify_signature function in crypto/asymmetric_keys/public_key.c.

    Published: 25 Jan 2016
    7.6
    High

    CVE-2016-2052

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue than CVE-2015-8947.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2015-8781

    Last Modified: 12 Apr 2025

    tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds write) via an invalid number of samples per pixel in a LogL compressed TIFF image, a different vulnerability than CVE-2015-8782.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2015-8782

    Last Modified: 12 Apr 2025

    tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds writes) via a crafted TIFF image, a different vulnerability than CVE-2015-8781.

    Published: 24 Jan 2016
    7.6
    High

    CVE-2015-8947

    Last Modified: 12 Apr 2025

    hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7524

    Last Modified: 21 Nov 2024

    coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 24 Jan 2016
    9.8
    Critical

    CVE-2016-2051

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2015-8783

    Last Modified: 12 Apr 2025

    tif_luv.c in libtiff allows attackers to cause a denial of service (out-of-bounds reads) via a crafted TIFF image.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7525

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2015-8784

    Last Modified: 12 Apr 2025

    The NeXTDecode function in tif_next.c in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted TIFF image, as demonstrated by libtiff5.tif.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7521

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in coders/psd.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7522

    Last Modified: 20 Apr 2025

    The ReadPSDImage function in MagickCore/locale.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted PSD file.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7523

    Last Modified: 21 Nov 2024

    coders/meta.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2016-7528

    Last Modified: 20 Apr 2025

    The ReadVIFFImage function in coders/viff.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via a crafted VIFF file.

    Published: 24 Jan 2016
    5.5
    Medium

    CVE-2021-20265

    Last Modified: 21 Nov 2024

    A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.

    Published: 24 Jan 2016
    6.5
    Medium

    CVE-2015-6317

    Last Modified: 12 Apr 2025

    Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.

    Published: 23 Jan 2016
    5.4
    Medium

    CVE-2015-7417

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.

    Published: 23 Jan 2016
    10
    Critical

    CVE-2015-6013

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6014, CVE-2015-6015, and CVE-2016-0432. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is a stack-based buffer overflow in Oracle Outside In 8.5.2 and earlier, which allows remote attackers to execute arbitrary code via a crafted WK4 file.

    Published: 22 Jan 2016
    10
    Critical

    CVE-2015-6015

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6013, CVE-2015-6014, and CVE-2016-0432. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is a stack-based buffer overflow in Oracle Outside In 8.5.2 and earlier, which allows remote attackers to execute arbitrary code via a crafted Paradox DB file.

    Published: 22 Jan 2016
    10
    Critical

    CVE-2015-6014

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2015-4808, CVE-2015-6013, CVE-2015-6015, and CVE-2016-0432. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this issue is a stack-based buffer overflow in Oracle Outside In 8.5.2 and earlier, which allows remote attackers to execute arbitrary code via a crafted DOC file.

    Published: 22 Jan 2016
    7.5
    High

    CVE-2015-6925

    Last Modified: 12 Apr 2025

    wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.

    Published: 22 Jan 2016
    9.8
    Critical

    CVE-2016-1984

    Last Modified: 12 Apr 2025

    The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.

    Published: 22 Jan 2016
    8.8
    High

    CVE-2016-1134

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.

    Published: 22 Jan 2016
    6.1
    Medium

    CVE-2016-1135

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jan 2016
    9.8
    Critical

    CVE-2015-6412

    Last Modified: 12 Apr 2025

    Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.

    Published: 22 Jan 2016
    9.8
    Critical

    CVE-2015-6435

    Last Modified: 12 Apr 2025

    An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.

    Published: 22 Jan 2016
    7.3
    High

    CVE-2015-7909

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via traffic on TCP port 5000.

    Published: 22 Jan 2016