8.8
    High

    CVE-2016-7855

    Last Modified: 21 Apr 2026

    Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.

    Published:26 Oct 2016
    6.1
    Medium

    CVE-2016-7851

    Last Modified: 9 Nov 2016

    Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be exploited in cross-site scripting attacks.

    Source:Vulnerability-Lab
    Published:8 Nov 2016
    8.8
    High

    CVE-2016-7786

    Last Modified: 16 Apr 2018

    Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.

    Source:Frogy
    Published:7 Apr 2017
    7.8
    High

    CVE-2016-7661

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "Power Management" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7660

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "syslog" component. It allows local users to gain privileges via unspecified vectors related to Mach port name references.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7644

    Last Modified: 16 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7637

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7633

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory Services" component. It allows local users to gain privileges or cause a denial of service (use-after-free) via unspecified vectors.

    Source:Google Security Research
    Published:20 Feb 2017
    8.8
    High

    CVE-2016-7626

    Last Modified: 12 Dec 2016

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is affected. The issue involves the "Profiles" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted certificate profile.

    Source:Maksymilian Arciemowicz
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7621

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via unspecified vectors.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7617

    Last Modified: 5 Apr 2017

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (type confusion) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    7.8
    High

    CVE-2016-7612

    Last Modified: 8 Dec 2017

    An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Kernel" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:20 Feb 2017
    5.5
    Medium

    CVE-2016-7608

    Last Modified: 3 Mar 2018

    An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component, which allows local users to obtain sensitive information from kernel memory via unspecified vectors.

    Source:Brandon Azad
    Published:20 Feb 2017
    9.8
    Critical

    CVE-2016-7567

    Last Modified: 9 Nov 2018

    Buffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified impact via a crafted string.

    Source:Magnus Klaaborg Stubman
    Published:27 Sept 2016
    7.5
    High

    CVE-2016-7508

    Last Modified: 27 Jun 2017

    Multiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a certain character when the database is configured to use Big5 Asian encoding.

    Source:Eric CARTER
    Published:21 Jun 2017
    8
    High

    CVE-2016-7454

    Last Modified: 1 Jan 2017

    CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.

    Source:Ayushman Dutta
    Published:17 Dec 2016
    7.5
    High

    CVE-2016-7434

    Last Modified: 21 Nov 2016

    The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

    Source:Magnus Klaaborg Stubman
    Published:21 Nov 2016
    9.8
    Critical

    CVE-2016-7400

    Last Modified: 22 Sept 2016

    Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.

    Source:Manuel García Cárdenas
    Published:7 Feb 2017
    7.8
    High

    CVE-2016-7391

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds check can allow a user to write to kernel memory, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-7390

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x7000194 where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-7387

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x600000D where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    5.5
    Medium

    CVE-2016-7386

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x70000D4 which may lead to leaking of kernel memory contents to user space through an uninitialized buffer.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-7385

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x700010d where a value passed from a user to the driver is used without validation as the index to an internal array, leading to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.8
    High

    CVE-2016-7384

    Last Modified: 31 Oct 2016

    For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) where unchecked input/output lengths in UVMLiteController Device IO Control handling may lead to denial of service or potential escalation of privileges.

    Source:Google Security Research
    Published:8 Nov 2016
    7.5
    High

    CVE-2016-7288

    Last Modified: 14 Feb 2017

    The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7286, CVE-2016-7296, and CVE-2016-7297.

    Source:Google Security Research
    Published:20 Dec 2016
    7.5
    High

    CVE-2016-7287

    Last Modified: 21 Dec 2016

    The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:20 Dec 2016
    7.5
    High

    CVE-2016-7286

    Last Modified: 21 Dec 2016

    The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7288, CVE-2016-7296, and CVE-2016-7297.

    Source:Google Security Research
    Published:20 Dec 2016
    8.8
    High

    CVE-2016-7274

    Last Modified: 15 Mar 2017

    Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Uniscribe Remote Code Execution Vulnerability."

    Source:Hossein Lotfi
    Published:20 Dec 2016
    7.8
    High

    CVE-2016-7255

    Last Modified: 9 Nov 2016

    The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Source:TinySec
    Published:10 Nov 2016
    7.5
    High

    CVE-2016-7241

    Last Modified: 6 Dec 2016

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."

    Source:Google Security Research
    Published:10 Nov 2016
    7.5
    High

    CVE-2016-7240

    Last Modified: 17 Nov 2016

    The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7242, and CVE-2016-7243.

    Source:Google Security Research
    Published:10 Nov 2016
    6.5
    Medium

    CVE-2016-7237

    Last Modified: 9 Nov 2016

    Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."

    Source:laurent gaffie
    Published:10 Nov 2016
    6.1
    Medium

    CVE-2016-7226

    Last Modified: 15 Nov 2016

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:10 Nov 2016
    6.1
    Medium

    CVE-2016-7225

    Last Modified: 15 Nov 2016

    Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:10 Nov 2016
    6.1
    Medium

    CVE-2016-7224

    Last Modified: 15 Nov 2016

    Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:10 Nov 2016
    5.5
    Medium

    CVE-2016-7216

    Last Modified: 15 Nov 2016

    The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:10 Nov 2016
    7.5
    High

    CVE-2016-7203

    Last Modified: 18 Nov 2016

    The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

    Source:Google Security Research
    Published:10 Nov 2016
    7.5
    High

    CVE-2016-7202

    Last Modified: 18 Nov 2016

    The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," as demonstrated by the Chakra JavaScript engine, a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

    Source:Google Security Research
    Published:10 Nov 2016
    8.8
    High

    CVE-2016-7201

    Last Modified: 18 Nov 2016

    The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

    Source:Google Security Research
    Published:10 Nov 2016
    8.8
    High

    CVE-2016-7200

    Last Modified: 18 May 2018

    The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

    Source:Google Security Research
    Published:10 Nov 2016
    7.5
    High

    CVE-2016-7194

    Last Modified: 23 Oct 2016

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3386, CVE-2016-3389, and CVE-2016-7190.

    Source:Google Security Research
    Published:14 Oct 2016
    7.5
    High

    CVE-2016-7190

    Last Modified: 21 Oct 2016

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3386, CVE-2016-3389, and CVE-2016-7194.

    Source:Google Security Research
    Published:14 Oct 2016
    7.5
    High

    CVE-2016-7189

    Last Modified: 21 Oct 2016

    The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2016
    7.8
    High

    CVE-2016-7188

    Last Modified: 17 Oct 2016

    The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2016
    7.8
    High

    CVE-2016-7185

    Last Modified: 21 Oct 2016

    The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." a different vulnerability than CVE-2016-3266, CVE-2016-3376, and CVE-2016-7211.

    Source:Google Security Research
    Published:14 Oct 2016
    9.8
    Critical

    CVE-2016-7182

    Last Modified: 21 Oct 2016

    The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype for Business 2016; Lync 2013 SP1; Lync 2010; Lync 2010 Attendee; and Live Meeting 2007 Console allows attackers to execute arbitrary code via a crafted True Type font, aka "True Type Font Parsing Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2016
    8.1
    High

    CVE-2016-7144

    Last Modified: 20 Apr 2025

    The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.

    Published:18 Jan 2017
    9.8
    Critical

    CVE-2016-7117

    Last Modified: 12 Apr 2025

    Use-after-free vulnerability in the __sys_recvmmsg function in net/socket.c in the Linux kernel before 4.5.2 allows remote attackers to execute arbitrary code via vectors involving a recvmmsg system call that is mishandled during error processing.

    Published:14 Mar 2016
    8.1
    High

    CVE-2016-7098

    Last Modified: 24 Nov 2016

    Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.

    Source:Dawid Golunski
    Published:11 Aug 2016
    7.8
    High

    CVE-2016-7089

    Last Modified: 15 Sept 2016

    WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.

    Source:Shadow Brokers
    Published:24 Aug 2016