7.5
    High

    CVE-2016-8858

    Last Modified: 29 May 2026

    The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXINIT requests. NOTE: a third party reports that "OpenSSH upstream does not consider this as a security issue."

    Published:17 Oct 2016
    6.1
    Medium

    CVE-2016-8855

    Last Modified: 15 Mar 2017

    Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev. 160519 (8.1 Update-3) allows remote attacks via the Name or Description parameter. This is fixed in 8.2 Update-2.

    Source:Pralhad Chaskar
    Published:19 Mar 2017
    7.8
    High

    CVE-2016-8823

    Last Modified: 12 Apr 2025

    All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where the size of an input buffer is not validated leading to a denial of service or possible escalation of privileges

    Published:16 Dec 2016
    8.8
    High

    CVE-2016-8812

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52 contains a vulnerability in the kernel mode layer (nvstreamkms.sys) allowing a user to cause a stack buffer overflow with specially crafted executable paths, leading to a denial of service or escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8811

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000170 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8810

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100009a where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8809

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70001b2 where the size of an input buffer is not validated, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8808

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000d5 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8807

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed from an user to the driver is used without validation as the size input to memcpy() causing a stack buffer overflow, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8806

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x5000027 where a pointer passed from an user to the driver is used without validation, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-8805

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000014 where a value passed from an user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    4.6
    Medium

    CVE-2016-8776

    Last Modified: 20 Apr 2025

    Huawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow attackers to bypass the factory reset protection (FRP) to enter some functional modules without authorization and perform operations to update the Google account.

    Published:2 Apr 2017
    6.7
    Medium

    CVE-2016-8769

    Last Modified: 22 Nov 2016

    Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain elevated privileges after the executable file is executed.

    Source:Dhruv Shah
    Published:2 Apr 2017
    8.8
    High

    CVE-2016-8744

    Last Modified: 20 Apr 2025

    Apache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML should unmarshal data to a Java type. In the default configuration in Brooklyn before 0.10.0, SnakeYAML will allow unmarshalling to any Java type available on the classpath. This could provide an authenticated user with a means to cause the JVM running Brooklyn to load and run Java code without detection by Brooklyn. Such code would have the privileges of the Java process running Brooklyn, including the ability to open files and network connections, and execute system commands. There is known to be a proof-of-concept exploit using this vulnerability.

    Published:13 Sept 2017
    7.8
    High

    CVE-2016-8742

    Last Modified: 30 Jan 2017

    The Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service launcher, or CouchDB batch or binary files. A subsequent service or server restart will then run that binary with administrator privilege. This issue affected CouchDB 2.0.0 (Windows platform only) and was addressed in CouchDB 2.0.0.1.

    Source:hyp3rlinx
    Published:12 Feb 2018
    7.5
    High

    CVE-2016-8741

    Last Modified: 20 Apr 2025

    The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.

    Published:28 Dec 2016
    7.5
    High

    CVE-2016-8740

    Last Modified: 14 Dec 2016

    The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.

    Source:Jungun Baek
    Published:4 Dec 2016
    9.8
    Critical

    CVE-2016-8735

    Last Modified: 25 Aug 2026

    Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types.

    Published:22 Nov 2016
    7.8
    High

    CVE-2016-8655

    Last Modified: 15 Nov 2018

    Race condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging the CAP_NET_RAW capability to change a socket version, related to the packet_set_ring and packet_setsockopt functions.

    Source:Metasploit
    Published:6 Dec 2016
    6.7
    Medium

    CVE-2016-8641

    Last Modified: 15 Dec 2016

    A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely changing the ownership afterwards. It's possible for the local attacker to create symbolic links before the files are to be created and possibly escalating the privileges with the ownership change.

    Source:Vincent Malguy
    Published:22 Nov 2016
    7.8
    High

    CVE-2016-8636

    Last Modified: 20 Apr 2025

    Integer overflow in the mem_check_range function in drivers/infiniband/sw/rxe/rxe_mr.c in the Linux kernel before 4.9.10 allows local users to cause a denial of service (memory corruption), obtain sensitive information from kernel memory, or possibly have unspecified other impact via a write or read request involving the "RDMA protocol over infiniband" (aka Soft RoCE) technology.

    Published:7 Feb 2017
    7.5
    High

    CVE-2016-8610

    Last Modified: 20 Apr 2025

    A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections from other clients.

    Published:24 Oct 2016
    9.8
    Critical

    CVE-2016-8582

    Last Modified: 2 Nov 2016

    A vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and retrieve database information or read local system files via MySQL's LOAD_FILE.

    Source:Peter Lapp
    Published:28 Oct 2016
    6.1
    Medium

    CVE-2016-8581

    Last Modified: 2 Nov 2016

    A persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to steal session IDs of logged in users when the current sessions are viewed by an administrator.

    Source:Peter Lapp
    Published:28 Oct 2016
    9.8
    Critical

    CVE-2016-8580

    Last Modified: 2 Nov 2016

    PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary PHP code execution via magic methods in included classes.

    Source:Peter Lapp
    Published:28 Oct 2016
    6.1
    Medium

    CVE-2016-8527

    Last Modified: 1 Mar 2017

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into AirWave in the same browser.

    Source:SEC Consult
    Published:6 Aug 2018
    8.8
    High

    CVE-2016-8526

    Last Modified: 1 Mar 2017

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

    Source:SEC Consult
    Published:6 Aug 2018
    8.8
    High

    CVE-2016-8523

    Last Modified: 10 Feb 2017

    A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.

    Source:MaKyOtOx
    Published:15 Feb 2018
    5.5
    Medium

    CVE-2016-8467

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue is rated as High because it is a local permanent denial of service (device interoperability: completely permanent or requiring re-flashing the entire operating system). Product: Android. Versions: N/A. Android ID: A-30308784.

    Published:13 Jan 2017
    5.5
    Medium

    CVE-2016-8462

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is rated as High because it could be used to access sensitive data. Product: Android. Versions: N/A. Android ID: A-32510383.

    Published:12 Jan 2017
    7.3
    High

    CVE-2016-8380

    Last Modified: 18 Oct 2018

    The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

    Source:Photubias
    Published:5 Apr 2018
    8
    High

    CVE-2016-8377

    Last Modified: 13 Sept 2017

    An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists when the software application connects to a malicious server, resulting in a stack buffer overflow. This causes an exploitable Structured Exception Handler (SEH) overwrite condition that may allow remote code execution.

    Source:James Fitts
    Published:13 Feb 2017
    7.3
    High

    CVE-2016-8371

    Last Modified: 18 Oct 2018

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

    Source:Photubias
    Published:5 Apr 2018
    5.3
    Medium

    CVE-2016-8367

    Last Modified: 20 Apr 2025

    An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard, all versions, Magelis XBT GT Advanced Touchscreen Panels, all versions, and Magelis XBT GTW Advanced Open Touchscreen Panels (Windows XPe). An attacker can open multiple connections to a targeted web server and keep connections open preventing new connections from being made, rendering the web server unavailable during an attack.

    Published:13 Feb 2017
    7.3
    High

    CVE-2016-8366

    Last Modified: 11 Oct 2018

    Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

    Source:Photubias
    Published:5 Apr 2018
    6.2
    Medium

    CVE-2016-8025

    Last Modified: 11 Jan 2017

    SQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to obtain product information via a crafted HTTP request parameter.

    Source:Andrew Fasano
    Published:14 Mar 2017
    8.1
    High

    CVE-2016-8024

    Last Modified: 11 Jan 2017

    Improper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to obtain sensitive information via the server HTTP response spoofing.

    Source:Andrew Fasano
    Published:14 Mar 2017
    8.1
    High

    CVE-2016-8023

    Last Modified: 11 Jan 2017

    Authentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to bypass server authentication via a crafted authentication cookie.

    Source:Andrew Fasano
    Published:14 Mar 2017
    7.5
    High

    CVE-2016-8022

    Last Modified: 11 Jan 2017

    Authentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote unauthenticated attacker to execute arbitrary code or cause a denial of service via a crafted authentication cookie.

    Source:Andrew Fasano
    Published:14 Mar 2017
    5
    Medium

    CVE-2016-8021

    Last Modified: 11 Jan 2017

    Improper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to spoof update server and execute arbitrary code via a crafted input file.

    Source:Andrew Fasano
    Published:14 Mar 2017
    8
    High

    CVE-2016-8020

    Last Modified: 11 Jan 2017

    Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request parameter.

    Source:Andrew Fasano
    Published:14 Mar 2017
    6.1
    Medium

    CVE-2016-8019

    Last Modified: 11 Jan 2017

    Cross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows unauthenticated remote attackers to inject arbitrary web script or HTML via a crafted user input.

    Source:Andrew Fasano
    Published:14 Mar 2017
    4.3
    Medium

    CVE-2016-8018

    Last Modified: 11 Jan 2017

    Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to execute unauthorized commands via a crafted user input.

    Source:Andrew Fasano
    Published:14 Mar 2017
    4.1
    Medium

    CVE-2016-8017

    Last Modified: 11 Jan 2017

    Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.

    Source:Andrew Fasano
    Published:14 Mar 2017
    3.4
    Low

    CVE-2016-8016

    Last Modified: 11 Jan 2017

    Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter.

    Source:Andrew Fasano
    Published:14 Mar 2017
    6.3
    Medium

    CVE-2016-8007

    Last Modified: 20 Apr 2025

    Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific conditions.

    Published:14 Mar 2017
    8.8
    High

    CVE-2016-7998

    Last Modified: 20 Oct 2016

    The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.

    Source:Sysdream
    Published:18 Jan 2017
    7.5
    High

    CVE-2016-7982

    Last Modified: 20 Oct 2016

    Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml action.

    Source:Sysdream
    Published:18 Jan 2017
    8.8
    High

    CVE-2016-7980

    Last Modified: 20 Oct 2016

    Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execute the XML validator on a local file via a crafted valider_xml request. NOTE: this issue can be combined with CVE-2016-7998 to execute arbitrary PHP code.

    Source:Sysdream
    Published:18 Jan 2017
    9.8
    Critical

    CVE-2016-7866

    Last Modified: 14 Dec 2016

    Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.

    Source:hyp3rlinx
    Published:15 Dec 2016