4.3
    Medium

    CVE-2017-0059

    Last Modified: 15 Aug 2017

    Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0008 and CVE-2017-0009.

    Source:Google Security Research
    Published:17 Mar 2017
    4.7
    Medium

    CVE-2017-0058

    Last Modified: 14 Apr 2017

    A Win32k information disclosure vulnerability exists in Microsoft Windows when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user's system, aka "Win32k Information Disclosure Vulnerability."

    Source:Google Security Research
    Published:12 Apr 2017
    6.1
    Medium

    CVE-2017-0055

    Last Modified: 20 Apr 2025

    Microsoft Internet Information Server (IIS) in Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to perform cross-site scripting and run script with local user privileges via a crafted request, aka "Microsoft IIS Server XSS Elevation of Privilege Vulnerability."

    Published:17 Mar 2017
    5.5
    Medium

    CVE-2017-0045

    Last Modified: 16 Mar 2017

    Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse crafted .msdvd files, which allows attackers to obtain information to compromise a target system, aka "Windows DVD Maker Cross-Site Request Forgery Vulnerability."

    Source:hyp3rlinx
    Published:17 Mar 2017
    5.5
    Medium

    CVE-2017-0038

    Last Modified: 6 Mar 2017

    gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220.

    Source:Google Security Research
    Published:20 Feb 2017
    8.1
    High

    CVE-2017-0037

    Last Modified: 15 Aug 2017

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge have a type confusion issue in the Layout::MultiColumnBoxBuilder::HandleColumnBreakOnColumnSpanningElement function in mshtml.dll, which allows remote attackers to execute arbitrary code via vectors involving a crafted Cascading Style Sheets (CSS) token sequence and crafted JavaScript code that operates on a TH element.

    Source:Google Security Research
    Published:26 Feb 2017
    7.8
    High

    CVE-2017-0005

    Last Modified: 22 Apr 2026

    The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application, aka "Windows GDI Elevation of Privilege Vulnerability." This vulnerability is different from those described in CVE-2017-0001, CVE-2017-0025, and CVE-2017-0047.

    Published:17 Mar 2017
    6.1
    Medium

    CVE-2016-1000229

    Last Modified: 21 Nov 2024

    swagger-ui has XSS in key names

    Published:21 Jul 2016
    9.8
    Critical

    CVE-2016-1000125

    Last Modified: 1 Sept 2017

    Unauthenticated SQL Injection in Huge-IT Catalog v1.0.7 for Joomla

    Source:Larry W. Cashdollar
    Published:6 Oct 2016
    9.8
    Critical

    CVE-2016-1000124

    Last Modified: 1 Sept 2017

    Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6

    Source:Larry W. Cashdollar
    Published:6 Oct 2016
    9.8
    Critical

    CVE-2016-1000123

    Last Modified: 1 Sept 2017

    Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla

    Source:Larry W. Cashdollar
    Published:6 Oct 2016
    9.8
    Critical

    CVE-2016-1000031

    Last Modified: 12 Apr 2025

    Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

    Published:20 Apr 2016
    9.8
    Critical

    CVE-2016-1000027

    Last Modified: 21 Nov 2024

    Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

    Published:8 Jul 2016
    5.3
    Medium

    CVE-2016-20012

    Last Modified: 29 May 2026

    OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product

    Published:7 Feb 2016
    Unknown

    CVE-2016-16113

    https://github.com/d3vn0mi/cve-2016-16113

    9.8
    Critical

    CVE-2016-15042

    Last Modified: 8 Apr 2026

    The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

    Published:16 Oct 2024
    7.2
    High

    CVE-2016-15041

    Last Modified: 8 Apr 2026

    The MainWP Dashboard – The Private WordPress Manager for Multiple Website Maintenance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mwp_setup_purchase_username’ parameter in versions up to, and including, 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published:16 Oct 2024
    5.4
    Medium

    CVE-2016-10993

    Last Modified: 21 Nov 2024

    The ScoreMe theme through 2016-04-01 for WordPress has XSS via the s parameter.

    Published:17 Sept 2019
    7.5
    High

    CVE-2016-10956

    Last Modified: 21 Nov 2024

    The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and csvexport.php.

    Published:16 Sept 2019
    7.5
    High

    CVE-2016-10924

    Last Modified: 21 Nov 2024

    The ebook-download plugin before 1.2 for WordPress has directory traversal.

    Published:22 Aug 2019
    6.5
    Medium

    CVE-2016-10761

    Last Modified: 21 Nov 2024

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

    Published:29 Jun 2019
    6.1
    Medium

    CVE-2016-10735

    Last Modified: 21 Nov 2024

    In Bootstrap 3.x before 3.4.0 and 4.x-beta before 4.0.0-beta.2, XSS is possible in the data-target attribute, a different vulnerability than CVE-2018-14041.

    Published:27 Jun 2016
    7.5
    High

    CVE-2016-10726

    Last Modified: 21 Nov 2024

    The XMLUI feature in DSpace before 3.6, 4.x before 4.5, and 5.x before 5.5 allows directory traversal via the themes/ path in an attack with two or more arbitrary characters and a colon before a pathname, as demonstrated by a themes/Reference/aa:etc/passwd URI.

    Published:10 Jul 2018
    7.5
    High

    CVE-2016-10718

    Last Modified: 17 Apr 2018

    Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.

    Source:Sahil Tikoo
    Published:4 Apr 2018
    8.8
    High

    CVE-2016-10709

    Last Modified: 21 Nov 2024

    pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.

    Published:22 Jan 2018
    7.5
    High

    CVE-2016-10708

    Last Modified: 28 Apr 2026

    sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.

    Published:21 Jan 2018
    6.5
    Medium

    CVE-2016-10555

    Last Modified: 21 Nov 2024

    Since "algorithm" isn't enforced in jwt.decode()in jwt-simple 0.3.0 and earlier, a malicious user could choose what algorithm is sent sent to the server. If the server is expecting RSA but is sent HMAC-SHA with RSA's public key, the server will think the public key is actually an HMAC private key. This could be used to forge any data an attacker wants.

    Published:31 May 2018
    6.5
    Medium

    CVE-2016-10504

    Last Modified: 1 Sept 2017

    Heap-based buffer overflow vulnerability in the opj_mqc_byteout function in mqc.c in OpenJPEG before 2.2.0 allows remote attackers to cause a denial of service (application crash) via a crafted bmp file.

    Source:Ke Liu
    Published:30 Aug 2017
    8.8
    High

    CVE-2016-10401

    Last Modified: 1 Nov 2017

    ZyXEL PK5001Z devices have zyad5001 as the su password, which makes it easier for remote attackers to obtain root access if a non-root account password is known (or a non-root default account exists within an ISP's deployment of these devices).

    Source:Matthew Sheimo
    Published:25 Jul 2017
    7.8
    High

    CVE-2016-10277

    Last Modified: 1 Sept 2017

    An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490.

    Source:Roee Hay
    Published:12 May 2017
    6.8
    Medium

    CVE-2016-10258

    Last Modified: 16 Sept 2019

    Unrestricted file upload vulnerability in the Symantec Advanced Secure Gateway (ASG) and ProxySG management consoles. A malicious appliance administrator can upload arbitrary malicious files to the management console and trick another administrator user into downloading and executing malicious code.

    Source:Pankaj Kumar Thakur
    Published:11 Apr 2018
    9.8
    Critical

    CVE-2016-10204

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.

    Published:3 Mar 2017
    9.8
    Critical

    CVE-2016-10191

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in libavformat/rtmppkt.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check for RTMP packet size mismatches.

    Published:9 Feb 2017
    9.8
    Critical

    CVE-2016-10190

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in libavformat/http.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote web servers to execute arbitrary code via a negative chunk size in an HTTP response.

    Published:9 Feb 2017
    9.8
    Critical

    CVE-2016-10176

    Last Modified: 25 Jan 2018

    The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This special URL is handled by the embedded web server (uhttpd) and processed accordingly. The web server also contains another URL, apply_noauth.cgi, that allows an unauthenticated user to perform sensitive actions on the device. This functionality can be exploited to change the router settings (such as the answers to the password-recovery questions) and achieve remote code execution.

    Source:Pedro Ribeiro
    Published:30 Jan 2017
    9.8
    Critical

    CVE-2016-10175

    Last Modified: 25 Jan 2018

    The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions.

    Source:Pedro Ribeiro
    Published:30 Jan 2017
    9.8
    Critical

    CVE-2016-10174

    Last Modified: 25 Jan 2018

    The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.

    Source:Pedro Ribeiro
    Published:30 Jan 2017
    7.8
    High

    CVE-2016-10156

    Last Modified: 7 Mar 2019

    A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local attackers to escalate their privileges to root. This is fixed in v229.

    Source:Sebastian Krahmer
    Published:23 Jan 2017
    7.5
    High

    CVE-2016-10140

    Last Modified: 20 Apr 2025

    Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29, which allows a remote unauthenticated attacker to browse all directories in the web root, e.g., a remote unauthenticated attacker can view all CCTV images on the server via the /events URI.

    Published:13 Jan 2017
    7.8
    High

    CVE-2016-10081

    Last Modified: 22 Feb 2017

    /usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Run a plugin" action.

    Source:Prajith
    Published:29 Dec 2016
    7.5
    High

    CVE-2016-10079

    Last Modified: 12 Jan 2017

    SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.

    Source:Peter Baris
    Published:1 Feb 2017
    9.8
    Critical

    CVE-2016-10074

    Last Modified: 2 Jan 2017

    The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.

    Source:Dawid Golunski
    Published:30 Dec 2016
    7.5
    High

    CVE-2016-10073

    Last Modified: 12 May 2017

    The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and potentially obtain sensitive information via a crafted HTTP Host header, as demonstrated by a password reset request.

    Source:Dawid Golunski
    Published:23 May 2017
    9.8
    Critical

    CVE-2016-10045

    Last Modified: 28 Dec 2016

    The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.

    Source:Dawid Golunski
    Published:30 Dec 2016
    10
    Critical

    CVE-2016-10043

    Last Modified: 31 Jan 2017

    An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was discovered to be vulnerable to OS command injection attacks. It is possible to use the pipe character (|) to inject arbitrary OS commands and retrieve the output in the application's responses. Attackers could execute unauthorized commands, which could then be used to disable the software, or read, write, and modify data for which the attacker does not have permissions to access directly. Since the targeted application is directly executing the commands instead of the attacker, any malicious activities may appear to come from the application or the application's owner (apache user).

    Source:Filippos Mastrogiannis
    Published:31 Jan 2017
    9.8
    Critical

    CVE-2016-10036

    Last Modified: 26 Apr 2018

    Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.

    Source:Alessio Sergi
    Published:1 May 2018
    9.8
    Critical

    CVE-2016-10034

    Last Modified: 2 Jan 2017

    The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted e-mail address.

    Source:Dawid Golunski
    Published:30 Dec 2016
    Unknown

    CVE-2016-010033

    https://github.com/zi0Black/CVE-2016-010033-010045

    9.8
    Critical

    CVE-2016-10033

    Last Modified: 4 May 2017

    The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.

    Source:Dawid Golunski
    Published:30 Dec 2016
    7.5
    High

    CVE-2016-10031

    Last Modified: 26 Dec 2016

    WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly exploit this vulnerability, the local attacker must insert an executable file called mysqld.exe or httpd.exe and replace the original files. The next time the service starts, the malicious file will get executed as SYSTEM. NOTE: the vendor disputes the relevance of this report, taking the position that a configuration in which "'someone' (an attacker) is able to replace files on a PC" is not "the fault of WampServer.

    Source:Heliand Dema
    Published:27 Dec 2016