9.8
    Critical

    CVE-2016-3078

    Last Modified: 28 Apr 2016

    Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted call to (1) getFromIndex or (2) getFromName in the ZipArchive class.

    Source:Hans Jerry Illikainen
    Published:28 Apr 2016
    9.8
    Critical

    CVE-2016-3074

    Last Modified: 26 Apr 2016

    Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.

    Source:Hans Jerry Illikainen
    Published:22 Apr 2016
    7.8
    High

    CVE-2016-3053

    Last Modified: 4 Nov 2016

    IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

    Source:Hector X. Monsegur
    Published:1 Feb 2017
    8.4
    High

    CVE-2016-2856

    Last Modified: 30 Mar 2017

    pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubuntu4.2 on Ubuntu 15.10 and before 2.23-0ubuntu1 on Ubuntu 16.04 LTS and 16.10 lacks a namespace check associated with file-descriptor passing, which allows local users to capture keystrokes and spoof data, and possibly gain privileges, via pts read and write operations, related to debian/sysdeps/linux.mk. NOTE: this is not considered a vulnerability in the upstream GNU C Library because the upstream documentation has a clear security recommendation against the --enable-pt_chown option.

    Source:halfdog
    Published:14 Mar 2016
    7.8
    High

    CVE-2016-2854

    Last Modified: 30 Mar 2017

    The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory.

    Source:halfdog
    Published:24 Feb 2016
    7.8
    High

    CVE-2016-2853

    Last Modified: 30 Mar 2017

    The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program.

    Source:halfdog
    Published:24 Feb 2016
    9.8
    Critical

    CVE-2016-2851

    Last Modified: 10 Mar 2016

    Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.

    Source:X41 D-Sec GmbH
    Published:7 Apr 2016
    8.8
    High

    CVE-2016-2819

    Last Modified: 20 Mar 2018

    Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

    Source:Rh0
    Published:8 Jun 2016
    4.7
    Medium

    CVE-2016-2784

    Last Modified: 4 May 2016

    CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.

    Source:Mickaël Walter
    Published:26 May 2016
    9.8
    Critical

    CVE-2016-2783

    Last Modified: 20 Apr 2025

    Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.

    Published:23 Jan 2017
    4.6
    Medium

    CVE-2016-2782

    Last Modified: 9 Mar 2016

    The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint.

    Source:OpenSource Security
    Published:12 Jan 2016
    7.5
    High

    CVE-2016-2776

    Last Modified: 5 Oct 2016

    buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.

    Source:Infobyte
    Published:27 Sept 2016
    7.5
    High

    CVE-2016-2569

    Last Modified: 12 Apr 2025

    Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.

    Published:24 Feb 2016
    9.8
    Critical

    CVE-2016-2563

    Last Modified: 11 Jan 2018

    Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to cause a denial of service (stack memory corruption) or execute arbitrary code via a crafted SCP-SINK file-size response to an SCP download request.

    Source:tintinweb
    Published:7 Apr 2016
    9.8
    Critical

    CVE-2016-2555

    Last Modified: 1 Mar 2016

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

    Source:Metasploit
    Published:13 Apr 2017
    8.8
    High

    CVE-2016-2539

    Last Modified: 7 Mar 2016

    Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the authentication of users for requests that upload arbitrary files and execute arbitrary PHP code via vectors involving a crafted zip file.

    Source:mr_me
    Published:7 Feb 2017
    Unknown

    CVE-2016-2534

    https://www.exploit-db.com/exploits/39405

    7.8
    High

    CVE-2016-2494

    Last Modified: 21 Dec 2016

    Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 28085658.

    Source:Google Security Research
    Published:13 Jun 2016
    7.8
    High

    CVE-2016-2468

    Last Modified: 12 Apr 2025

    The Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a crafted application, aka internal bug 27475454.

    Published:13 Jun 2016
    7.8
    High

    CVE-2016-2434

    Last Modified: 12 Apr 2025

    The NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 27251090.

    Published:9 May 2016
    7.8
    High

    CVE-2016-2431

    Last Modified: 12 Apr 2025

    The Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows attackers to gain privileges via a crafted application, aka internal bug 24968809.

    Published:9 May 2016
    9.8
    Critical

    CVE-2016-2417

    Last Modified: 21 Dec 2016

    media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a parameter data structure, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mechanism, via unspecified vectors, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 26914474.

    Source:Google Security Research
    Published:18 Apr 2016
    5.9
    Medium

    CVE-2016-2402

    Last Modified: 20 Apr 2025

    OkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain with a certificate from a non-pinned trusted CA and the pinned certificate.

    Published:30 Jan 2017
    7.8
    High

    CVE-2016-2399

    Last Modified: 23 Feb 2016

    Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom.

    Source:Marco Romano
    Published:30 Jan 2017
    7.5
    High

    CVE-2016-2389

    Last Modified: 17 May 2016

    Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Catalog, aka SAP Security Note 2230978.

    Source:ERPScan
    Published:16 Feb 2016
    5.3
    Medium

    CVE-2016-2388

    Last Modified: 11 Jan 2018

    The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.

    Source:Vahagn Vardanyan
    Published:16 Feb 2016
    9.8
    Critical

    CVE-2016-2386

    Last Modified: 11 Jan 2018

    SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

    Source:Vahagn Vardanyan
    Published:16 Feb 2016
    9.8
    Critical

    CVE-2016-2385

    Last Modified: 30 Mar 2016

    Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arbitrary code via a large SIP packet.

    Source:Stelios Tsampas
    Published:11 Apr 2016
    4.6
    Medium

    CVE-2016-2384

    Last Modified: 13 May 2017

    Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.

    Source:Andrey Konovalov
    Published:14 Feb 2016
    9.8
    Critical

    CVE-2016-2345

    Last Modified: 28 Oct 2017

    Stack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to execute arbitrary code via a crafted string.

    Source:Securifera
    Published:17 Mar 2016
    9.8
    Critical

    CVE-2016-2338

    Last Modified: 21 Nov 2024

    An exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document function heap buffer "head" allocation is made based on tags array length. Specially constructed object passed as element of tags array can increase this array size after mentioned allocation and cause heap overflow.

    Published:14 Feb 2020
    7.8
    High

    CVE-2016-2334

    Last Modified: 12 Apr 2025

    Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.

    Published:13 Dec 2016
    9.4
    Critical

    CVE-2016-2296

    Last Modified: 17 May 2016

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Source:Karn Ganeshen
    Published:14 May 2016
    7.8
    High

    CVE-2016-2288

    Last Modified: 28 Mar 2016

    Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file.

    Source:mr_me
    Published:29 Mar 2016
    6.1
    Medium

    CVE-2016-2279

    Last Modified: 16 May 2018

    Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:t4rkd3vilz
    Published:2 Mar 2016
    7.2
    High

    CVE-2016-2278

    Last Modified: 3 Mar 2016

    Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote authenticated administrators to execute arbitrary OS commands by defeating an msh (aka Minimal Shell) protection mechanism.

    Source:Karn Ganeshen
    Published:2 Mar 2016
    7.5
    High

    CVE-2016-2233

    Last Modified: 4 Apr 2016

    Stack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a denial of service (crash) via a large number of options in a CAP LS message.

    Source:PizzaHatHacker
    Published:18 Jan 2017
    7.8
    High

    CVE-2016-2226

    Last Modified: 28 Jul 2017

    Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.

    Source:Marcel Böhme
    Published:5 Feb 2016
    7.3
    High

    CVE-2016-2210

    Last Modified: 29 Jun 2016

    Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.

    Source:Google Security Research
    Published:30 Jun 2016
    7.3
    High

    CVE-2016-2209

    Last Modified: 29 Jun 2016

    Buffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code via a crafted file.

    Source:Google Security Research
    Published:30 Jun 2016
    9.1
    Critical

    CVE-2016-2208

    Last Modified: 17 May 2016

    The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation and system crash) via a malformed PE header file.

    Source:Google Security Research
    Published:19 May 2016
    8.4
    High

    CVE-2016-2207

    Last Modified: 29 Jun 2016

    The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before 12.1 RU6 MP5; Symantec Protection Engine (SPE) before 7.0.5 HF01, 7.5.x before 7.5.3 HF03, 7.5.4 before HF01, and 7.8.0 before HF01; Symantec Protection for SharePoint Servers (SPSS) 6.0.3 through 6.0.5 before 6.0.5 HF 1.5 and 6.0.6 before HF 1.6; Symantec Mail Security for Microsoft Exchange (SMSMSE) before 7.0_3966002 HF1.1 and 7.5.x before 7.5_3966008 VHF1.2; Symantec Mail Security for Domino (SMSDOM) before 8.0.9 HF1.1 and 8.1.x before 8.1.3 HF1.2; CSAPI before 10.0.4 HF01; Symantec Message Gateway (SMG) before 10.6.1-4; Symantec Message Gateway for Service Providers (SMG-SP) 10.5 before patch 254 and 10.6 before patch 253; Norton AntiVirus, Norton Security, Norton Internet Security, and Norton 360 before NGC 22.7; Norton Security for Mac before 13.0.2; Norton Power Eraser (NPE) before 5.1; and Norton Bootable Removal Tool (NBRT) before 2016.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory access violation) via a crafted RAR file that is mishandled during decompression.

    Source:Google Security Research
    Published:30 Jun 2016
    7.8
    High

    CVE-2016-2203

    Last Modified: 21 Apr 2016

    The management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD password by leveraging certain read privileges.

    Source:Fakhir Karim Reda
    Published:22 Apr 2016
    4.6
    Medium

    CVE-2016-2188

    Last Modified: 4 Oct 2016

    The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.

    Source:OpenSource Security
    Published:14 Mar 2016
    4.6
    Medium

    CVE-2016-2184

    Last Modified: 4 Oct 2016

    The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.

    Source:OpenSource Security
    Published:14 Mar 2016
    7.5
    High

    CVE-2016-2183

    Last Modified: 29 May 2026

    The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DES in CBC mode, aka a "Sweet32" attack.

    Published:24 Aug 2016
    9.8
    Critical

    CVE-2016-2173

    Last Modified: 20 Apr 2025

    org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.

    Published:21 Apr 2017
    7.5
    High

    CVE-2016-2118

    Last Modified: 12 Apr 2025

    The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate users by modifying the client-server data stream, aka "BADLOCK."

    Published:12 Apr 2016
    5.9
    Medium

    CVE-2016-2107

    Last Modified: 4 May 2016

    The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.

    Source:Juraj Somorovsky
    Published:3 May 2016
    7.3
    High

    CVE-2016-2098

    Last Modified: 11 Jul 2016

    Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method.

    Source:Metasploit
    Published:29 Feb 2016