7
    High

    CVE-2016-10010

    Last Modified: 23 Dec 2016

    sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to gain privileges via unspecified vectors, related to serverloop.c.

    Source:Google Security Research
    Published:19 Dec 2016
    7.3
    High

    CVE-2016-10009

    Last Modified: 23 Dec 2016

    Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute arbitrary local PKCS#11 modules by leveraging control over a forwarded agent-socket.

    Source:Google Security Research
    Published:19 Dec 2016
    6.1
    Medium

    CVE-2016-10006

    Last Modified: 12 Apr 2025

    In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.

    Published:24 Dec 2016
    6.5
    Medium

    CVE-2016-9951

    Last Modified: 19 Dec 2016

    An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on Apport crash files generated by local systems. The Relaunch button will be hidden when crash files are opened directly in Apport-GTK.

    Source:Donncha OCearbhaill
    Published:17 Dec 2016
    7.8
    High

    CVE-2016-9950

    Last Modified: 19 Dec 2016

    An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage" fields. These fields are used to build a path to the package specific hook files in the /usr/share/apport/package-hooks/ directory. An attacker can exploit this path traversal to execute arbitrary Python files from the local system.

    Source:Donncha OCearbhaill
    Published:17 Dec 2016
    7.8
    High

    CVE-2016-9949

    Last Modified: 19 Dec 2016

    An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.

    Source:Donncha OCearbhaill
    Published:17 Dec 2016
    7.5
    High

    CVE-2016-9920

    Last Modified: 12 Apr 2025

    steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does not properly restrict the use of custom envelope-from addresses on the sendmail command line, which allows remote authenticated users to execute arbitrary code via a modified HTTP request that sends a crafted e-mail message.

    Published:8 Dec 2016
    9.8
    Critical

    CVE-2016-9899

    Last Modified: 16 Jan 2017

    Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

    Source:Marcin Ressel
    Published:14 Dec 2016
    7.5
    High

    CVE-2016-9838

    Last Modified: 18 Jul 2018

    An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user's account and reset the user's group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task.

    Source:Charles Fol
    Published:16 Dec 2016
    6.1
    Medium

    CVE-2016-9834

    Last Modified: 3 Jul 2017

    An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.

    Source:Bhadresh Patel
    Published:7 Jun 2017
    5.5
    Medium

    CVE-2016-9813

    Last Modified: 13 Jun 2017

    The _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.

    Source:Hanno Boeck
    Published:25 Nov 2016
    9.8
    Critical

    CVE-2016-9796

    Last Modified: 4 Dec 2016

    Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port 30024. An attacker can bypass authentication, and OmniVista invokes methods (AddJobSet, AddJob, and ExecuteNow) that can be used to run arbitrary commands on the server, with the privilege of NT AUTHORITY\SYSTEM on the server. NOTE: The discoverer states "The vendor position is to refer to the technical guidelines of the product security deployment to mitigate this issue, which means applying proper firewall rules to prevent unauthorised clients to connect to the OmniVista server."

    Source:malerisch
    Published:3 Dec 2016
    7.8
    High

    CVE-2016-9795

    Last Modified: 20 Apr 2025

    The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infrastructure Managers 12.8 and 12.9; CA Workload Automation AE 11, 11.3, 11.3.5, and 11.3.6 on AIX, HP-UX, Linux, and Solaris allows local users to modify arbitrary files and consequently gain root privileges via vectors related to insufficient validation.

    Published:27 Jan 2017
    7.8
    High

    CVE-2016-9793

    Last Modified: 18 Sept 2017

    The sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability for a crafted setsockopt system call with the (1) SO_SNDBUFFORCE or (2) SO_RCVBUFFORCE option.

    Source:Andrey Konovalov
    Published:2 Dec 2016
    4.2
    Medium

    CVE-2016-9722

    Last Modified: 13 Jul 2018

    IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 119737.

    Source:Metasploit
    Published:10 Jan 2018
    9.8
    Critical

    CVE-2016-9684

    Last Modified: 21 Feb 2017

    The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn't properly escape the information it's passed in the 'CERT' variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.

    Source:xort
    Published:22 Feb 2017
    9.8
    Critical

    CVE-2016-9683

    Last Modified: 21 Feb 2017

    The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component responsible for handling some of the server's internal configurations. The CGI application doesn't properly escape the information it's passed when processing a particular multi-part form request involving scripts. The filename of the 'scriptname' variable is read in unsanitized before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account. This is SonicWall Issue ID 181195.

    Source:xort
    Published:22 Feb 2017
    9.8
    Critical

    CVE-2016-9682

    Last Modified: 19 Jul 2017

    The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.

    Source:xort
    Published:22 Feb 2017
    8.8
    High

    CVE-2016-9651

    Last Modified: 14 Jun 2017

    A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Source:Qihoo360
    Published:1 Dec 2016
    8.1
    High

    CVE-2016-9606

    Last Modified: 21 Nov 2024

    JBoss RESTEasy before version 3.1.2 could be forced into parsing a request with YamlProvider, resulting in unmarshalling of potentially untrusted data which could allow an attacker to execute arbitrary code with RESTEasy application permissions.

    Published:15 Dec 2016
    7.5
    High

    CVE-2016-9589

    Last Modified: 21 Nov 2024

    Undertow in Red Hat wildfly before version 11.0.0.Beta1 is vulnerable to a resource exhaustion resulting in a denial of service. Undertow keeps a cache of seen HTTP headers in persistent connections. It was found that this cache can easily exploited to fill memory with garbage, up to "max-headers" (default 200) * "max-header-size" (default 1MB) per active TCP connection.

    Published:22 Mar 2017
    8.1
    High

    CVE-2016-9587

    Last Modified: 11 Jan 2017

    Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems. An attacker with control over a client system being managed by Ansible and the ability to send facts back to the Ansible server could use this flaw to execute arbitrary code on the Ansible server using the Ansible server privileges.

    Source:Computest
    Published:9 Jan 2017
    7.8
    High

    CVE-2016-9566

    Last Modified: 16 Dec 2016

    base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink attack on the log file. NOTE: this can be leveraged by remote attackers using CVE-2016-9565.

    Source:Dawid Golunski
    Published:7 Dec 2016
    9.8
    Critical

    CVE-2016-9565

    Last Modified: 16 Dec 2016

    MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofing a crafted response from the Nagios RSS feed server. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4796.

    Source:Dawid Golunski
    Published:13 Dec 2016
    7.2
    High

    CVE-2016-9554

    Last Modified: 18 Jul 2017

    The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the component responsible for performing diagnostic tests with the UNIX wget utility. The application doesn't properly escape the information passed in the 'url' variable before calling the executeCommand class function ($this->dtObj->executeCommand). This function calls exec() with unsanitized user input allowing for remote command injection. The page that contains the vulnerabilities, /controllers/MgrDiagnosticTools.php, is accessed by a built-in command answered by the administrative interface. The command that calls to that vulnerable page (passed in the 'section' parameter) is: 'configuration'. Exploitation of this vulnerability yields shell access to the remote machine under the 'spiderman' user account.

    Source:xort
    Published:28 Jan 2017
    7.2
    High

    CVE-2016-9553

    Last Modified: 18 Jul 2017

    The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device. The device doesn't properly escape the information passed in the variables 'unblockip' and 'blockip' before calling the shell_exec() function which allows for system commands to be injected into the device. The code erroneously suggests that the information handled is protected by utilizing the variable name 'escapedips' - however this was not the case. The Sophos ID is NSWA-1258.

    Source:xort
    Published:28 Jan 2017
    9.8
    Critical

    CVE-2016-9488

    Last Modified: 26 Jul 2020

    ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

    Source:aldorm
    Published:5 Jun 2018
    5.3
    Medium

    CVE-2016-9355

    Last Modified: 20 Apr 2025

    An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physical access to an Alaris 8015 PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling an Alaris 8015 PC unit and accessing the device's flash memory. Older software versions of the Alaris 8015 PC unit, Version 9.5 and prior versions, store wireless network authentication credentials and other sensitive technical data on the affected device's removable flash memory. Being able to remove the flash memory from the affected device reduces the risk of detection, allowing an attacker to extract stored data at the attacker's convenience.

    Published:13 Feb 2017
    7
    High

    CVE-2016-9351

    Last Modified: 8 Aug 2017

    An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker to upload and unpack a zip file.

    Source:James Fitts
    Published:13 Feb 2017
    7.5
    High

    CVE-2016-9349

    Last Modified: 8 Aug 2017

    An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.

    Source:James Fitts
    Published:13 Feb 2017
    7.5
    High

    CVE-2016-9332

    Last Modified: 18 Nov 2016

    An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could provide unexpected values and cause the program to crash or excessive consumption of resources could result in a denial-of-service condition.

    Source:Zhou Yu
    Published:13 Feb 2017
    5.4
    Medium

    CVE-2016-9316

    Last Modified: 15 Feb 2017

    Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allow authenticated, remote users with least privileges to inject arbitrary HTML/JavaScript code into web pages. This was resolved in Version 6.5 CP 1737.

    Source:SlidingWindow
    Published:21 Feb 2017
    8.8
    High

    CVE-2016-9315

    Last Modified: 15 Feb 2017

    Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to change Master Admin's password and/or add new admin accounts. This was resolved in Version 6.5 CP 1737.

    Source:SlidingWindow
    Published:21 Feb 2017
    7.8
    High

    CVE-2016-9314

    Last Modified: 15 Feb 2017

    Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to backup the system configuration and download it onto their local machine. This backup file contains sensitive information like passwd/shadow files, RSA certificates, Private Keys and Default Passphrase, etc. This was resolved in Version 6.5 CP 1737.

    Source:SlidingWindow
    Published:21 Feb 2017
    9.8
    Critical

    CVE-2016-9299

    Last Modified: 17 May 2018

    The remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted serialized Java object, which triggers an LDAP query to a third-party server.

    Source:Metasploit
    Published:11 Nov 2016
    9.9
    Critical

    CVE-2016-9269

    Last Modified: 15 Feb 2017

    Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA) version 6.5-SP2_Build_Linux_1707 and earlier allows authenticated, remote users with least privileges to run arbitrary commands on the system as root via Patch Update functionality. This was resolved in Version 6.5 CP 1737.

    Source:SlidingWindow
    Published:21 Feb 2017
    7.5
    High

    CVE-2016-9244

    Last Modified: 12 Apr 2018

    A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31 bytes of uninitialized memory. A remote attacker may exploit this vulnerability to obtain Secure Sockets Layer (SSL) session IDs from other sessions. It is possible that other data from uninitialized memory may be returned as well.

    Source:@0x00string
    Published:9 Feb 2017
    7.8
    High

    CVE-2016-9192

    Last Modified: 12 Apr 2025

    A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitrary executable file with privileges equivalent to the Microsoft Windows operating system SYSTEM account. More Information: CSCvb68043. Known Affected Releases: 4.3(2039) 4.3(748). Known Fixed Releases: 4.3(4019) 4.4(225).

    Published:14 Dec 2016
    7.5
    High

    CVE-2016-9177

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Published:4 Nov 2016
    7.8
    High

    CVE-2016-9151

    Last Modified: 12 May 2017

    Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows local users to gain privileges via crafted values of unspecified environment variables.

    Source:Google Security Research
    Published:19 Nov 2016
    9.8
    Critical

    CVE-2016-9150

    Last Modified: 18 Nov 2016

    Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x before 7.1.6 allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:Google Security Research
    Published:19 Nov 2016
    6.8
    Medium

    CVE-2016-9111

    Last Modified: 2 Nov 2016

    Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging physical access to a VDI for temporary disconnection of a LAN cable. NOTE: as of 20161208, the vendor could not reproduce the issue, stating "the researcher was unable to provide us with information that would allow us to confirm the behaviour and, despite extensive investigation on test deployments of supported products, we were unable to reproduce the behaviour as he described. The researcher has also, despite additional requests for information, ceased to respond to us."

    Source:Rithwik Jayasimha
    Published:7 Nov 2016
    7.2
    High

    CVE-2016-9091

    Last Modified: 4 Apr 2017

    Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges.

    Source:Chris Hebert
    Published:5 Apr 2017
    7.5
    High

    CVE-2016-9079

    Last Modified: 14 Jul 2017

    A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.

    Source:Rh0
    Published:1 Dec 2016
    7.5
    High

    CVE-2016-9066

    Last Modified: 25 Nov 2025

    A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

    Published:16 Nov 2016
    5.5
    Medium

    CVE-2016-9018

    Last Modified: 26 Oct 2016

    Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in RealNetworks RealPlayer 18.1.5.705 through a crafted .QCP media file.

    Source:Alwin Peppels
    Published:28 Oct 2016
    7.8
    High

    CVE-2016-8972

    Last Modified: 22 Dec 2016

    IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

    Source:Hector X. Monsegur
    Published:15 Feb 2017
    8.1
    High

    CVE-2016-8870

    Last Modified: 16 Nov 2016

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

    Source:Xiphos Research Ltd
    Published:4 Nov 2016
    9.8
    Critical

    CVE-2016-8869

    Last Modified: 16 Nov 2016

    The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows remote attackers to gain privileges by leveraging incorrect use of unfiltered data when registering on a site.

    Source:Xiphos Research Ltd
    Published:4 Nov 2016
    9.8
    Critical

    CVE-2016-8863

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

    Published:7 Mar 2017