7.8
    High

    CVE-2016-7084

    Last Modified: 19 Sept 2016

    tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allows guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via a JPEG 2000 image.

    Source:Google Security Research
    Published:29 Dec 2016
    7.8
    High

    CVE-2016-7083

    Last Modified: 19 Sept 2016

    VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual printing is enabled, allow guest OS users to execute arbitrary code on the host OS or cause a denial of service (host OS memory corruption) via TrueType fonts embedded in EMFSPOOL.

    Source:Google Security Research
    Published:29 Dec 2016
    8.8
    High

    CVE-2016-7065

    Last Modified: 28 Nov 2016

    The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via a crafted serialized Java object.

    Source:Mediaservice.net Srl.
    Published:7 Oct 2016
    7.5
    High

    CVE-2016-7054

    Last Modified: 12 Dec 2016

    In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS.

    Source:Silverfox
    Published:10 Nov 2016
    8.6
    High

    CVE-2016-7051

    Last Modified: 20 Apr 2025

    XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors related to a DTD.

    Published:14 Apr 2017
    7.8
    High

    CVE-2016-6914

    Last Modified: 26 Dec 2017

    Ubiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain SYSTEM privileges via a Trojan horse taskkill.exe file.

    Source:Julien Ahrens
    Published:27 Dec 2017
    9.8
    Critical

    CVE-2016-6909

    Last Modified: 15 Sept 2016

    Buffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch before 3.4.3 allows remote attackers to execute arbitrary code via a crafted HTTP request, aka EGREGIOUSBLUNDER.

    Source:Shadow Brokers
    Published:24 Aug 2016
    6.5
    Medium

    CVE-2016-6897

    Last Modified: 22 Aug 2016

    Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

    Source:Yorick Koster
    Published:18 Jan 2017
    7.1
    High

    CVE-2016-6896

    Last Modified: 22 Aug 2016

    Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.

    Source:Yorick Koster
    Published:18 Jan 2017
    7.5
    High

    CVE-2016-6855

    Last Modified: 23 Aug 2016

    Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF-8 to GMarkup.

    Source:Kaslov Dmitri
    Published:19 Aug 2016
    6.1
    Medium

    CVE-2016-6854

    Last Modified: 14 Oct 2016

    An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature gets executed when verifying the signature. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).

    Source:Benjamin Daniel Mussler
    Published:15 Dec 2016
    6.1
    Medium

    CVE-2016-6853

    Last Modified: 14 Oct 2016

    An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the names of PGP public keys. When requesting that key later on using a specific URL, such script code might get executed. In case of injecting external websites, users might get lured into a phishing scheme. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.).

    Source:Benjamin Daniel Mussler
    Published:15 Dec 2016
    6.1
    Medium

    CVE-2016-6851

    Last Modified: 14 Oct 2016

    An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader web application. This allows cross-site scripting attacks against arbitrary users since no prior authentication is needed. Malicious script code can be executed within a user's context. This can lead to session hijacking or triggering unwanted actions via the web interface (sending mail, deleting data etc.) in case the user has an active session on the same domain already.

    Source:Benjamin Daniel Mussler
    Published:15 Dec 2016
    5.5
    Medium

    CVE-2016-6828

    Last Modified: 8 Nov 2016

    The tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after a failed data copy, which allows local users to cause a denial of service (tcp_xmit_retransmit_queue use-after-free and system crash) via a crafted SACK option.

    Source:Marco Grassi
    Published:15 Aug 2016
    7.1
    High

    CVE-2016-6816

    Last Modified: 3 Apr 2017

    The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.

    Source:justpentest
    Published:22 Nov 2016
    6.1
    Medium

    CVE-2016-6812

    Last Modified: 20 Apr 2025

    The HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page which lists the names and absolute URL addresses of the available service endpoints. The module calculates the base URL using the current HttpServletRequest. The calculated base URL is used by FormattedServiceListWriter to build the service endpoint absolute URLs. If the unexpected matrix parameters have been injected into the request URL then these matrix parameters will find their way back to the client in the services list page which represents an XSS risk to the client.

    Published:19 Dec 2016
    9.8
    Critical

    CVE-2016-6809

    Last Modified: 20 Apr 2025

    Apache Tika before 1.14 allows Java code execution for serialized objects embedded in MATLAB files. The issue exists because Tika invokes JMatIO to do native deserialization.

    Published:10 Nov 2016
    7.5
    High

    CVE-2016-6802

    Last Modified: 12 Apr 2025

    Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

    Published:13 Sept 2016
    8.8
    High

    CVE-2016-6801

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before 2.4.6, 2.6.x before 2.6.6, 2.8.x before 2.8.3, 2.10.x before 2.10.4, 2.12.x before 2.12.4, and 2.13.x before 2.13.3 allows remote attackers to hijack the authentication of unspecified victims for requests that create a resource via an HTTP POST request with a (1) missing or (2) crafted Content-Type header.

    Published:21 Sept 2016
    9.8
    Critical

    CVE-2016-6798

    Last Modified: 20 Apr 2025

    In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially allowing an attacker to read sensitive data on the filesystem, perform same-site-request-forgery (SSRF), port-scanning behind the firewall or DoS the application.

    Published:19 Jul 2017
    7.8
    High

    CVE-2016-6772

    Last Modified: 20 Dec 2016

    An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31856351.

    Source:Google Security Research
    Published:12 Jan 2017
    8.8
    High

    CVE-2016-6754

    Last Modified: 21 Dec 2016

    A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.

    Source:Guang Gong
    Published:25 Nov 2016
    7.8
    High

    CVE-2016-6707

    Last Modified: 21 Dec 2016

    An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Android ID: A-31350622.

    Source:Google Security Research
    Published:25 Nov 2016
    5.5
    Medium

    CVE-2016-6689

    Last Modified: 21 Dec 2016

    Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347.

    Source:Google Security Research
    Published:10 Oct 2016
    7
    High

    CVE-2016-6664

    Last Modified: 30 Jan 2017

    mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17, when using file-based logging, allows local users with access to the mysql account to gain root privileges via a symlink attack on error logs and possibly other files.

    Source:Dawid Golunski
    Published:19 Oct 2016
    7
    High

    CVE-2016-6663

    Last Modified: 30 Jan 2017

    Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32-25.17, and 5.7.x before 5.7.14-26.17 allows local users with certain permissions to gain privileges by leveraging use of my_copystat by REPAIR TABLE to repair a MyISAM table.

    Source:Dawid Golunski
    Published:12 Sept 2016
    9.8
    Critical

    CVE-2016-6662

    Last Modified: 17 Nov 2016

    Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain protection mechanisms by setting general_log_file to a my.cnf configuration. NOTE: this can be leveraged to execute arbitrary code with root privileges by setting malloc_lib. NOTE: the affected MySQL version information is from Oracle's October 2016 CPU. Oracle has not commented on third-party claims that the issue was silently patched in MySQL 5.5.52, 5.6.33, and 5.7.15.

    Source:Dawid Golunski
    Published:12 Sept 2016
    9.8
    Critical

    CVE-2016-6603

    Last Modified: 25 Jan 2018

    ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

    Source:Pedro Ribeiro
    Published:23 Jan 2017
    9.8
    Critical

    CVE-2016-6602

    Last Modified: 25 Jan 2018

    ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.

    Source:Pedro Ribeiro
    Published:23 Jan 2017
    7.5
    High

    CVE-2016-6601

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.

    Source:Pedro Ribeiro
    Published:23 Jan 2017
    9.8
    Critical

    CVE-2016-6600

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to upload and execute arbitrary JSP files via a .. (dot dot) in the fileName parameter to servlets/FileUploadServlet.

    Source:Pedro Ribeiro
    Published:23 Jan 2017
    9.8
    Critical

    CVE-2016-6599

    Last Modified: 2 Feb 2018

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database name, username and password as well as the domain administrator username and password. These are encrypted with a fixed key and IV ("NumaraIT") using the DES algorithm. The domain administrator username and password can only be obtained if the Self-Service component is enabled, which is the most common scenario in enterprise deployments.

    Source:Pedro Ribeiro
    Published:30 Jan 2018
    9.8
    Critical

    CVE-2016-6598

    Last Modified: 2 Feb 2018

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. This can be used to upload a file to the web root and achieve code execution as NETWORK SERVICE or SYSTEM.

    Source:Pedro Ribeiro
    Published:30 Jan 2018
    Unknown

    CVE-2016-6584

    https://github.com/ViralSecurityGroup/KNOXout

    9.8
    Critical

    CVE-2016-6566

    Last Modified: 18 Aug 2017

    The valueAsString parameter inside the JSON payload contained by the ucLogin_txtLoginId_ClientStat POST parameter of the Sungard eTRAKiT3 software version 3.2.1.17 is not properly validated. An unauthenticated remote attacker may be able to modify the POST request and insert a SQL query which may then be executed by the backend server. eTRAKiT 3.2.1.17 was tested, but other versions may also be vulnerable.

    Source:Goran Tuzovic
    Published:13 Jul 2018
    9.8
    Critical

    CVE-2016-6563

    Last Modified: 16 Nov 2017

    Processing malformed SOAP messages when performing the HNAP Login action causes a buffer overflow in the stack in some D-Link DIR routers. The vulnerable XML fields within the SOAP body are: Action, Username, LoginPassword, and Captcha. The following products are affected: DIR-823, DIR-822, DIR-818L(W), DIR-895L, DIR-890L, DIR-885L, DIR-880L, DIR-868L, and DIR-850L.

    Source:Metasploit
    Published:13 Jul 2018
    7.4
    High

    CVE-2016-6516

    Last Modified: 12 Apr 2025

    Race condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial of service (heap-based buffer overflow) or possibly gain privileges by changing a certain count value, aka a "double fetch" vulnerability.

    Published:31 Jul 2016
    7.5
    High

    CVE-2016-6515

    Last Modified: 7 Dec 2016

    The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) via a long string.

    Source:SecPod Research
    Published:21 Jul 2016
    5.9
    Medium

    CVE-2016-6512

    Last Modified: 3 Aug 2016

    epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet, related to the MMSE, WAP, WBXML, and WSP dissectors.

    Source:Antti Levomäki
    Published:27 Jul 2016
    5.9
    Medium

    CVE-2016-6505

    Last Modified: 3 Aug 2016

    epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted packet.

    Source:Chris Benedict
    Published:27 Jul 2016
    5.9
    Medium

    CVE-2016-6504

    Last Modified: 3 Aug 2016

    epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet.

    Source:Chris Benedict
    Published:6 Aug 2016
    5.9
    Medium

    CVE-2016-6503

    Last Modified: 3 Aug 2016

    The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Source:Igor
    Published:6 Aug 2016
    8.6
    High

    CVE-2016-6483

    Last Modified: 24 Oct 2016

    The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before 4.2.2 Patch Level 6, 4.2.3 before Patch Level 2, 5.x before 5.2.0 Patch Level 3, 5.2.1 before Patch Level 1, and 5.2.2 before Patch Level 1 allows remote attackers to conduct SSRF attacks via a crafted URL that results in a Redirection HTTP status code.

    Source:Dawid Golunski
    Published:2 Sept 2016
    6.5
    Medium

    CVE-2016-6435

    Last Modified: 5 Oct 2016

    The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376.

    Source:KoreLogic
    Published:6 Oct 2016
    7.8
    High

    CVE-2016-6434

    Last Modified: 5 Oct 2016

    Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by leveraging CLI access, aka Bug ID CSCva30370.

    Source:KoreLogic
    Published:6 Oct 2016
    8.8
    High

    CVE-2016-6433

    Last Modified: 13 Jan 2017

    The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute arbitrary commands via crafted web-application parameters, aka Bug ID CSCva30872.

    Source:KoreLogic
    Published:6 Oct 2016
    7.5
    High

    CVE-2016-6415

    Last Modified: 21 Dec 2017

    The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and PIX before 7.0 allows remote attackers to obtain sensitive information from device memory via a Security Association (SA) negotiation request, aka Bug IDs CSCvb29204 and CSCvb36055 or BENIGNCERTAIN.

    Source:nixawk
    Published:19 Sept 2016
    7.8
    High

    CVE-2016-6367

    Last Modified: 15 Sept 2016

    Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA.

    Source:Shadow Brokers
    Published:18 Aug 2016
    8.8
    High

    CVE-2016-6366

    Last Modified: 15 Sept 2016

    Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices allows remote authenticated users to execute arbitrary code via crafted IPv4 SNMP packets, aka Bug ID CSCva92151 or EXTRABACON.

    Source:Shadow Brokers
    Published:18 Aug 2016
    8.1
    High

    CVE-2016-6328

    Last Modified: 21 Nov 2024

    A vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause Denial-of-Service (DoS) and Information Disclosure (disclosing some critical heap chunk metadata, even other applications' private data).

    Published:25 Jul 2017