7
    High

    CVE-2016-5195

    Last Modified: 24 Jul 2017

    Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW."

    Source:Robin Verton
    Published:19 Oct 2016
    9.8
    Critical

    CVE-2016-5180

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.

    Published:29 Sept 2016
    9.8
    Critical

    CVE-2016-5108

    Last Modified: 11 Jan 2017

    Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted QuickTime IMA file.

    Source:Patrick Coleman
    Published:8 Jun 2016
    5.3
    Medium

    CVE-2016-5063

    Last Modified: 28 Jan 2018

    The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass authorization checks and make an RPC call via unspecified vectors.

    Source:Paul Taylor
    Published:2 May 2017
    9.8
    Critical

    CVE-2016-4999

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the getStringParameterSQL method in main/java/org/dashbuilder/dataprovider/sql/dialect/DefaultDialect.java in Dashbuilder before 0.6.0.Beta1 allows remote attackers to execute arbitrary SQL commands via a data set lookup filter in the (1) Data Set Authoring or (2) Displayer editor UI.

    Published:14 Jul 2016
    7.8
    High

    CVE-2016-4997

    Last Modified: 30 Jan 2017

    The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before 4.6.3 allow local users to gain privileges or cause a denial of service (memory corruption) by leveraging in-container root access to provide a crafted offset value that triggers an unintended decrement.

    Source:Qian Zhang
    Published:24 Jun 2016
    8.8
    High

    CVE-2016-4977

    Last Modified: 20 Apr 2025

    When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via the crafting of the value for response_type.

    Published:25 May 2017
    7.5
    High

    CVE-2016-4974

    Last Modified: 12 Apr 2025

    Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.

    Published:2 Jul 2016
    8.8
    High

    CVE-2016-4971

    Last Modified: 29 Oct 2021

    GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

    Source:liewehacksie
    Published:9 Jun 2016
    9.8
    Critical

    CVE-2016-4861

    Last Modified: 20 Apr 2025

    The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.

    Published:16 Feb 2017
    8.8
    High

    CVE-2016-4845

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.

    Published:24 Sept 2016
    8.8
    High

    CVE-2016-4808

    Last Modified: 16 May 2016

    Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a logged in user to perform some unwanted actions i.e An attacker can trick an victim to disable the installed application just by sending a URL to victim.

    Source:Narendra Bhati
    Published:11 Jan 2017
    4.8
    Medium

    CVE-2016-4807

    Last Modified: 16 May 2016

    Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged in user (admin).

    Source:Narendra Bhati
    Published:11 Jan 2017
    7.5
    High

    CVE-2016-4806

    Last Modified: 16 May 2016

    Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files.

    Source:Narendra Bhati
    Published:11 Jan 2017
    7.5
    High

    CVE-2016-4793

    Last Modified: 16 May 2016

    The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

    Source:Dawid Golunski
    Published:23 Jan 2017
    7.8
    High

    CVE-2016-4669

    Last Modified: 1 Nov 2016

    An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute arbitrary code in a privileged context or cause a denial of service (MIG code mishandling and system crash) via unspecified vectors.

    Source:Google Security Research
    Published:20 Feb 2017
    8.8
    High

    CVE-2016-4657

    Last Modified: 1 Mar 2018

    WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Source:qwertyoruiop
    Published:25 Aug 2016
    7.8
    High

    CVE-2016-4656

    Last Modified: 5 Jun 2018

    The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Metasploit
    Published:25 Aug 2016
    5.5
    Medium

    CVE-2016-4655

    Last Modified: 5 Jun 2018

    The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

    Source:Metasploit
    Published:25 Aug 2016
    8.8
    High

    CVE-2016-4631

    Last Modified: 12 Apr 2025

    ImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TIFF file.

    Published:22 Jul 2016
    7.8
    High

    CVE-2016-4625

    Last Modified: 14 Nov 2016

    Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors.

    Source:Google Security Research
    Published:22 Jul 2016
    8.8
    High

    CVE-2016-4622

    Last Modified: 12 Apr 2025

    WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4589, CVE-2016-4623, and CVE-2016-4624.

    Published:22 Jul 2016
    5.5
    Medium

    CVE-2016-4578

    Last Modified: 11 Mar 2019

    sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface, related to the (1) snd_timer_user_ccallback and (2) snd_timer_user_tinterrupt functions.

    Source:wally0813
    Published:3 May 2016
    7
    High

    CVE-2016-4558

    Last Modified: 4 May 2016

    The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted application on (1) a system with more than 32 Gb of memory, related to the program reference count or (2) a 1 Tb system, related to the map reference count.

    Source:Google Security Research
    Published:28 Apr 2016
    7.8
    High

    CVE-2016-4557

    Last Modified: 30 Jan 2017

    The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.

    Source:Metasploit
    Published:26 Apr 2016
    7.5
    High

    CVE-2016-4535

    Last Modified: 4 May 2016

    Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable.

    Source:Google Security Research
    Published:5 May 2016
    3
    Low

    CVE-2016-4534

    Last Modified: 7 Mar 2016

    The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles.

    Source:Maurizio Agazzini
    Published:5 May 2016
    3.3
    Low

    CVE-2016-4486

    Last Modified: 19 Dec 2018

    The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message.

    Source:Jinbum Park
    Published:4 May 2016
    8.8
    High

    CVE-2016-4469

    Last Modified: 13 Jul 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add new repository proxy connectors via the token parameter to admin/addProxyConnector_commit.action, (2) new repositories via the token parameter to admin/addRepository_commit.action, (3) edit existing repositories via the token parameter to admin/editRepository_commit.action, (4) add legacy artifact paths via the token parameter to admin/addLegacyArtifactPath_commit.action, (5) change the organizational appearance via the token parameter to admin/saveAppearance.action, or (6) upload new artifacts via the token parameter to upload_submit.action.

    Source:Julien Ahrens
    Published:28 Jul 2016
    8.8
    High

    CVE-2016-4468

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH before 11.2 and 12.x before 12.2; Elastic Runtime before 1.6.29 and 1.7.x before 1.7.7; and Ops Manager 1.7.x before 1.7.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published:11 Apr 2017
    9.8
    Critical

    CVE-2016-4464

    Last Modified: 12 Apr 2025

    The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecified other impact via a crafted SAML token with a trusted signature.

    Published:21 Sept 2016
    7.5
    High

    CVE-2016-4463

    Last Modified: 12 Apr 2025

    Stack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply nested DTD.

    Published:29 Jun 2016
    9.8
    Critical

    CVE-2016-4438

    Last Modified: 12 Apr 2025

    The REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.

    Published:17 Jun 2016
    9.8
    Critical

    CVE-2016-4437

    Last Modified: 1 May 2020

    Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.

    Source:Metasploit
    Published:3 Jun 2016
    9.8
    Critical

    CVE-2016-4372

    Last Modified: 19 Sept 2017

    HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02, and iMC UAM_TAM before 7.2 E0405P05 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.

    Source:Raphael Kuhn
    Published:15 Jul 2016
    8.8
    High

    CVE-2016-4340

    Last Modified: 15 Aug 2016

    The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4 allows remote authenticated users to "log in" as any other user via unspecified vectors.

    Source:Kaimi
    Published:23 Jan 2017
    8.1
    High

    CVE-2016-4338

    Last Modified: 21 Dec 2017

    The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.

    Source:Timo Lindfors
    Published:23 Jan 2017
    9.8
    Critical

    CVE-2016-4337

    Last Modified: 30 Jun 2016

    SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.

    Source:Gal Goldshtein & Viktor Minin
    Published:12 Apr 2017
    6.1
    Medium

    CVE-2016-4316

    Last Modified: 16 Aug 2016

    Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description parameter to ndatasource/newdatasource.jsp; the (6) phase parameter to viewflows/handlers.jsp; or the (7) url parameter to ndatasource/validateconnection-ajaxprocessor.jsp.

    Source:hyp3rlinx
    Published:16 Feb 2017
    5.7
    Medium

    CVE-2016-4315

    Last Modified: 16 Aug 2016

    Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.

    Source:hyp3rlinx
    Published:16 Feb 2017
    4.9
    Medium

    CVE-2016-4314

    Last Modified: 16 Aug 2016

    Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp.

    Source:hyp3rlinx
    Published:16 Feb 2017
    7.8
    High

    CVE-2016-4313

    Last Modified: 16 May 2016

    Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.

    Source:hyp3rlinx
    Published:24 Apr 2017
    7.5
    High

    CVE-2016-4312

    Last Modified: 16 Aug 2016

    XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct server-side request forgery (SSRF) attacks, or have unspecified other impact via a crafted XACML request to entitlement/eval-policy-submit.jsp. NOTE: this issue can be combined with CVE-2016-4311 to exploit the vulnerability without credentials.

    Source:hyp3rlinx
    Published:16 Feb 2017
    8.8
    High

    CVE-2016-4311

    Last Modified: 16 Aug 2016

    Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.

    Source:hyp3rlinx
    Published:16 Feb 2017
    7.5
    High

    CVE-2016-4309

    Last Modified: 20 Jun 2016

    Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    Source:hyp3rlinx
    Published:30 Jun 2016
    8.8
    High

    CVE-2016-4275

    Last Modified: 23 Sept 2016

    Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4274, CVE-2016-4276, CVE-2016-4280, CVE-2016-4281, CVE-2016-4282, CVE-2016-4283, CVE-2016-4284, CVE-2016-4285, CVE-2016-6922, and CVE-2016-6924.

    Source:Google Security Research
    Published:13 Sept 2016
    8.8
    High

    CVE-2016-4273

    Last Modified: 12 Oct 2016

    Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-6982, CVE-2016-6983, CVE-2016-6984, CVE-2016-6985, CVE-2016-6986, CVE-2016-6989, and CVE-2016-6990.

    Source:COSIG
    Published:11 Oct 2016
    8.6
    High

    CVE-2016-4264

    Last Modified: 7 Sept 2016

    The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:Dawid Golunski
    Published:1 Sept 2016
    7.5
    High

    CVE-2016-4232

    Last Modified: 21 Oct 2016

    Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to obtain sensitive information from process memory via unspecified vectors.

    Source:Google Security Research
    Published:12 Jul 2016
    8.8
    High

    CVE-2016-4231

    Last Modified: 8 Sept 2016

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4173, CVE-2016-4174, CVE-2016-4222, CVE-2016-4226, CVE-2016-4227, CVE-2016-4228, CVE-2016-4229, CVE-2016-4230, and CVE-2016-4248.

    Source:Google Security Research
    Published:12 Jul 2016