CVE Feed

    Dashboard / CVE

    5.1
    Medium

    CVE-2016-2547

    Last Modified: 12 Apr 2025

    sound/core/timer.c in the Linux kernel before 4.4.1 employs a locking approach that does not consider slave timer instances, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.

    Published: 19 Jan 2016
    6.2
    Medium

    CVE-2016-2548

    Last Modified: 12 Apr 2025

    sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a denial of service (system crash) via a crafted ioctl call, related to the (1) snd_timer_close and (2) _snd_timer_stop functions.

    Published: 19 Jan 2016
    6.2
    Medium

    CVE-2016-2549

    Last Modified: 12 Apr 2025

    sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.

    Published: 19 Jan 2016
    5.5
    Medium

    CVE-2016-7915

    Last Modified: 12 Apr 2025

    The hid_input_field function in drivers/hid/hid-core.c in the Linux kernel before 4.6 allows physically proximate attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) by connecting a device, as demonstrated by a Logitech DJ receiver.

    Published: 19 Jan 2016
    5.5
    Medium

    CVE-2016-7916

    Last Modified: 12 Apr 2025

    Race condition in the environ_read function in fs/proc/base.c in the Linux kernel before 4.5.4 allows local users to obtain sensitive information from kernel memory by reading a /proc/*/environ file during a process-setup time interval in which environment-variable copying is incomplete.

    Published: 19 Jan 2016
    5.1
    Medium

    CVE-2016-2546

    Last Modified: 12 Apr 2025

    sound/core/timer.c in the Linux kernel before 4.4.1 uses an incorrect type of mutex, which allows local users to cause a denial of service (race condition, use-after-free, and system crash) via a crafted ioctl call.

    Published: 19 Jan 2016
    6.1
    Medium

    CVE-2015-5008

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Jan 2016
    5.3
    Medium

    CVE-2015-4942

    Last Modified: 12 Apr 2025

    IBM WebSphere MQ Light 1.x before 1.0.2 allows remote attackers to cause a denial of service (MQXR service crash) via a series of connect and disconnect actions, a different vulnerability than CVE-2015-4943.

    Published: 18 Jan 2016
    6.1
    Medium

    CVE-2015-4959

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP16 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Jan 2016
    8.6
    High

    CVE-2015-4988

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the replay server in IBM Tealeaf Customer Experience before 8.7.1.8818, 8.8 before 8.8.0.9026, 9.0.0, 9.0.0A, 9.0.1 before 9.0.1.1083, 9.0.1A before 9.0.1.5073, 9.0.2 before 9.0.2.1095, and 9.0.2A before 9.0.2.5144 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 18 Jan 2016
    6.1
    Medium

    CVE-2015-5002

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Host On-Demand 11.0 through 11.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Jan 2016
    5.4
    Medium

    CVE-2015-5009

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Commerce 6.0 through FP11, 6.0 Feature Pack 4, 7.0 through FP9, 7.0 Feature Pack 5 through 8, and 8.0 before 8.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 18 Jan 2016
    3.7
    Low

    CVE-2015-7886

    Last Modified: 12 Apr 2025

    NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors.

    Published: 18 Jan 2016
    5.9
    Medium

    CVE-2016-0201

    Last Modified: 12 Apr 2025

    GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collision.

    Published: 18 Jan 2016
    7.5
    High

    CVE-2017-5840

    Last Modified: 17 Mar 2026

    The qtdemux_parse_samples function in gst/isomp4/qtdemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving the current stts index.

    Published: 18 Jan 2016
    6.5
    Medium

    CVE-2016-1924

    Last Modified: 12 Apr 2025

    The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

    Published: 18 Jan 2016
    6.5
    Medium

    CVE-2016-1923

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image.

    Published: 18 Jan 2016
    3.3
    Low

    CVE-2015-4958

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 does not properly restrict browser caching, which allows local users to obtain sensitive information by reading cache files.

    Published: 17 Jan 2016
    4.3
    Medium

    CVE-2015-7468

    Last Modified: 12 Apr 2025

    Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended restrictions on administrator tasks via unspecified vectors.

    Published: 17 Jan 2016
    7.5
    High

    CVE-2015-7470

    Last Modified: 12 Apr 2025

    Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-middle attackers to obtain sensitive information via unspecified vectors, as demonstrated by login information.

    Published: 17 Jan 2016
    4.1
    Medium

    CVE-2015-4960

    Last Modified: 12 Apr 2025

    IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.

    Published: 17 Jan 2016
    5.4
    Medium

    CVE-2015-7414

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 9.1, 10.1, 11.0 before 11.0.0.0 IF11, 11.3 before 11.3.0.0 IF7, and 11.4 before 11.4.0.4 IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 17 Jan 2016
    5.4
    Medium

    CVE-2015-7467

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 17 Jan 2016
    4.3
    Medium

    CVE-2015-7469

    Last Modified: 12 Apr 2025

    Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows remote authenticated users to bypass intended read-only restrictions by leveraging a JazzGuest role.

    Published: 17 Jan 2016
    5.5
    Medium

    CVE-2015-8897

    Last Modified: 20 Apr 2025

    The SpliceImage function in MagickCore/transform.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (application crash) via a crafted png file.

    Published: 17 Jan 2016
    5.5
    Medium

    CVE-2015-8898

    Last Modified: 20 Apr 2025

    The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image file.

    Published: 17 Jan 2016
    9.1
    Critical

    CVE-2016-1142

    Last Modified: 12 Apr 2025

    Seeds acmailer before 3.8.21 and 3.9.x before 3.9.15 Beta allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

    Published: 16 Jan 2016
    7.3
    High

    CVE-2015-6863

    Last Modified: 12 Apr 2025

    HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

    Published: 16 Jan 2016
    6.3
    Medium

    CVE-2015-6864

    Last Modified: 12 Apr 2025

    HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certificate upload component.

    Published: 16 Jan 2016
    3.7
    Low

    CVE-2016-1133

    Last Modified: 12 Apr 2025

    CRLF injection vulnerability in the on_req function in lib/handler/redirect.c in H2O before 1.6.2 and 1.7.x before 1.7.0-beta3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URI.

    Published: 16 Jan 2016
    6.1
    Medium

    CVE-2016-1293

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Management Center in Cisco FireSIGHT System Software 6.0.0 and 6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCux40414.

    Published: 16 Jan 2016
    6.1
    Medium

    CVE-2016-1294

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Management Center in Cisco FireSIGHT System Software 6.0.1 allows remote attackers to inject arbitrary web script or HTML via a crafted cookie, aka Bug ID CSCuw89094.

    Published: 16 Jan 2016
    5.3
    Medium

    CVE-2016-1295

    Last Modified: 12 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt, aka Bug ID CSCuo65775.

    Published: 16 Jan 2016
    9.8
    Critical

    CVE-2016-1909

    Last Modified: 12 Apr 2025

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.

    Published: 15 Jan 2016
    6.1
    Medium

    CVE-2016-1911

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in SAP NetWeaver 7.4 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) Runtime Workbench (RWB) or (2) Pmitest servlet in the Process Monitoring Infrastructure (PMI), aka SAP Security Notes 2206793 and 2234918.

    Published: 15 Jan 2016
    5.3
    Medium

    CVE-2016-1910

    Last Modified: 12 Apr 2025

    The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

    Published: 15 Jan 2016
    5.4
    Medium

    CVE-2016-1912

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

    Published: 15 Jan 2016
    5.4
    Medium

    CVE-2016-1913

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Redhen module 7.x-1.x before 7.x-1.11 for Drupal allow remote authenticated users with certain access to inject arbitrary web script or HTML via unspecified vectors, related to (1) individual contacts, (2) notes, or (3) engagement scores.

    Published: 15 Jan 2016
    6.2
    Medium

    CVE-2015-8675

    Last Modified: 12 Apr 2025

    Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display.

    Published: 15 Jan 2016
    5.3
    Medium

    CVE-2016-1258

    Last Modified: 12 Apr 2025

    Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2X51 before 13.2X51-D20, 13.3 before 13.3R8, 14.1 before 14.1R6, and 14.2 before 14.2R5, allows remote attackers to cause a denial of service (J-Web crash) via unspecified vectors.

    Published: 15 Jan 2016
    5.3
    Medium

    CVE-2016-1260

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 13.2X51-D36, 14.1X53 before 14.1X53-D25, and 15.2 before 15.2R1 on EX4300 series switches allow remote attackers to cause a denial of service (network loop and bandwidth consumption) via unspecified vectors related to Spanning Tree Protocol (STP) traffic.

    Published: 15 Jan 2016
    5.4
    Medium

    CVE-2015-8688

    Last Modified: 12 Apr 2025

    Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.

    Published: 15 Jan 2016
    6.1
    Medium

    CVE-2015-8685

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.

    Published: 15 Jan 2016
    5.3
    Medium

    CVE-2016-1256

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R10, 12.3X48 before 12.3X48-D20, 13.2 before 13.2R8, 13.2X51 before 13.2X51-D40, 13.3 before 13.3R7, 14.1 before 14.1R5, 14.1X53 before 14.1X53-D18 or 14.1X53-D30, 14.1X55 before 14.1X55-D25, 14.2 before 14.2R4, 15.1 before 15.1R2, and 15.1X49 before 15.1X49-D10 allow remote attackers to cause a denial of service via a malformed IGMPv3 packet, aka a "multicast denial of service."

    Published: 15 Jan 2016
    5.9
    Medium

    CVE-2016-1257

    Last Modified: 12 Apr 2025

    The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1R3-S9, 14.1R4 before 14.1R4-S7, 14.1X51 before 14.1X51-D65, 14.1X53 before 14.1X53-D12, 14.1X53 before 14.1X53-D28, 14.1X53 before 4.1X53-D35, 14.2R1 before 14.2R5, 14.2R3 before 14.2R3-S4, 14.2R4 before 14.2R4-S1, 15.1 before 15.1R3, 15.1F2 before 15.1F2-S2, and 15.1X49 before 15.1X49-D40, when LDP is enabled, allows remote attackers to cause a denial of service (RPD routing process crash) via a crafted LDP packet.

    Published: 15 Jan 2016
    5.9
    Medium

    CVE-2016-1262

    Last Modified: 12 Apr 2025

    Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, when the Real Time Streaming Protocol Application Layer Gateway (RTSP ALG) is enabled, allow remote attackers to cause a denial of service (flowd crash) via a crafted RTSP packet.

    Published: 15 Jan 2016
    5.5
    Medium

    CVE-2016-1897

    Last Modified: 12 Apr 2025

    FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a local file.

    Published: 15 Jan 2016
    5.4
    Medium

    CVE-2015-3948

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Advantech WebAccess before 8.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Jan 2016
    9.8
    Critical

    CVE-2016-0859

    Last Modified: 12 Apr 2025

    Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request.

    Published: 15 Jan 2016
    8.8
    High

    CVE-2015-5007

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 8 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 15 Jan 2016