7.4
    High

    CVE-2016-2087

    Last Modified: 4 Apr 2016

    Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a .. (dot dot) in the server name.

    Source:PizzaHatHacker
    Published:18 Jan 2017
    7.8
    High

    CVE-2016-2067

    Last Modified: 12 Apr 2025

    drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bug CR988993.

    Published:11 Jul 2016
    8.8
    High

    CVE-2016-2056

    Last Modified: 12 Jul 2019

    xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.

    Source:Metasploit
    Published:13 Apr 2016
    9.8
    Critical

    CVE-2016-2004

    Last Modified: 10 Oct 2016

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.

    Source:Ian Lovering
    Published:21 Apr 2016
    8.8
    High

    CVE-2016-1960

    Last Modified: 20 Mar 2018

    Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

    Source:Rh0
    Published:8 Mar 2016
    6.1
    Medium

    CVE-2016-1915

    Last Modified: 22 Feb 2016

    Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to inject arbitrary web script or HTML via the locale parameter to (1) mydevice/index.jsp or (2) mydevice/loggedOut.jsp.

    Source:Security-Assessment.com
    Published:13 Apr 2017
    8.8
    High

    CVE-2016-1914

    Last Modified: 22 Feb 2016

    Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

    Source:Security-Assessment.com
    Published:13 Apr 2017
    5.3
    Medium

    CVE-2016-1910

    Last Modified: 11 Jan 2018

    The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

    Source:Vahagn Vardanyan
    Published:15 Jan 2016
    9.8
    Critical

    CVE-2016-1909

    Last Modified: 8 Jan 2018

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for the Fortimanager_Access account, which allows remote attackers to obtain administrative access via an SSH session.

    Source:operator8203
    Published:15 Jan 2016
    7.8
    High

    CVE-2016-1887

    Last Modified: 28 Feb 2018

    Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer overflow.

    Source:CTurt
    Published:25 May 2016
    7.8
    High

    CVE-2016-1886

    Last Modified: 28 Feb 2018

    Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a negative value in the flen structure member in the arg argument in a SETFKEY ioctl call, which triggers a "two way heap and stack overflow."

    Source:CTurt
    Published:25 May 2016
    6.2
    Medium

    CVE-2016-1885

    Last Modified: 4 Oct 2017

    Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based buffer overflow.

    Source:Core Security
    Published:8 Apr 2016
    7.5
    High

    CVE-2016-1879

    Last Modified: 25 Jan 2016

    The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet.

    Source:ptsecurity
    Published:29 Jan 2016
    7.8
    High

    CVE-2016-1863

    Last Modified: 2 Nov 2016

    The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4582 and CVE-2016-4653.

    Source:Google Security Research
    Published:22 Jul 2016
    7.8
    High

    CVE-2016-1861

    Last Modified: 10 Jun 2016

    The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1846.

    Source:Google Security Research
    Published:19 Jun 2016
    7.8
    High

    CVE-2016-1848

    Last Modified: 11 Nov 2016

    QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.

    Source:Francis Provencher
    Published:20 May 2016
    7.8
    High

    CVE-2016-1846

    Last Modified: 10 Jun 2016

    The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference and memory corruption) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    5.5
    Medium

    CVE-2016-1839

    Last Modified: 24 Feb 2016

    The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

    Source:Google Security Research
    Published:20 May 2016
    5.5
    Medium

    CVE-2016-1838

    Last Modified: 24 Feb 2016

    The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted XML document.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1828

    Last Modified: 3 Mar 2018

    The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1827, CVE-2016-1829, and CVE-2016-1830.

    Source:Brandon Azad
    Published:20 May 2016
    7.8
    High

    CVE-2016-1827

    Last Modified: 3 Mar 2018

    The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1828, CVE-2016-1829, and CVE-2016-1830.

    Source:Brandon Azad
    Published:20 May 2016
    7.8
    High

    CVE-2016-1825

    Last Modified: 3 Mar 2018

    IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Brandon Azad
    Published:20 May 2016
    7.8
    High

    CVE-2016-1823

    Last Modified: 10 Jun 2016

    The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (out-of-bounds read and memory corruption) via a crafted IOHIDReportType enum, which triggers an incorrect cast, a different vulnerability than CVE-2016-1824.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1821

    Last Modified: 10 Jun 2016

    IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1819

    Last Modified: 10 Jun 2016

    Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1817 and CVE-2016-1818.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1813

    Last Modified: 10 Jun 2016

    The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    5.1
    Medium

    CVE-2016-1807

    Last Modified: 10 Jun 2016

    Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows local users to obtain sensitive information from kernel memory via unspecified vectors.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1803

    Last Modified: 10 Jun 2016

    CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1794

    Last Modified: 10 Jun 2016

    The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1793

    Last Modified: 10 Jun 2016

    AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.

    Source:Google Security Research
    Published:20 May 2016
    7.8
    High

    CVE-2016-1769

    Last Modified: 30 Mar 2016

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Photoshop file.

    Source:Francis Provencher
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1768

    Last Modified: 30 Mar 2016

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1767.

    Source:Francis Provencher
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1767

    Last Modified: 30 Mar 2016

    QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted FlashPix image, a different vulnerability than CVE-2016-1768.

    Source:Francis Provencher
    Published:24 Mar 2016
    4.3
    Medium

    CVE-2016-1764

    Last Modified: 12 Apr 2025

    The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL.

    Published:24 Mar 2016
    7
    High

    CVE-2016-1757

    Last Modified: 23 Mar 2016

    Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context via a crafted app.

    Source:Google Security Research
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1755

    Last Modified: 23 Mar 2016

    The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754.

    Source:Google Security Research
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1749

    Last Modified: 23 Mar 2016

    IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1744

    Last Modified: 23 Mar 2016

    The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1743.

    Source:Google Security Research
    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1743

    Last Modified: 2 Nov 2016

    The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1744.

    Source:Piotr Bania
    Published:24 Mar 2016
    9.8
    Critical

    CVE-2016-1741

    Last Modified: 23 Mar 2016

    The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Source:Google Security Research
    Published:24 Mar 2016
    6.8
    Medium

    CVE-2016-1734

    Last Modified: 12 Apr 2025

    AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted USB device.

    Published:24 Mar 2016
    7.8
    High

    CVE-2016-1721

    Last Modified: 28 Jan 2016

    The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:1 Feb 2016
    7.8
    High

    CVE-2016-1720

    Last Modified: 28 Jan 2016

    IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:1 Feb 2016
    7.8
    High

    CVE-2016-1719

    Last Modified: 28 Jan 2016

    The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 10.11.3, and tvOS before 9.1.1 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors.

    Source:Google Security Research
    Published:1 Feb 2016
    7.3
    High

    CVE-2016-1713

    Last Modified: 31 Jul 2018

    Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted image file with an executable extension, then accessing it via a direct request to the file in test/logo/. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-6000.

    Source:Touhid M.Shaikh
    Published:14 Apr 2017
    7.8
    High

    CVE-2016-1611

    Last Modified: 25 Jul 2016

    Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.

    Source:SEC Consult
    Published:1 Aug 2016
    7.5
    High

    CVE-2016-1610

    Last Modified: 25 Jul 2016

    Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a .. (dot dot) in a blob name.

    Source:SEC Consult
    Published:1 Aug 2016
    5.4
    Medium

    CVE-2016-1609

    Last Modified: 25 Jul 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attribute of an IMG element in the phone field of a user profile.

    Source:SEC Consult
    Published:1 Aug 2016
    8.8
    High

    CVE-2016-1608

    Last Modified: 25 Jul 2016

    vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.

    Source:SEC Consult
    Published:1 Aug 2016
    7.2
    High

    CVE-2016-1607

    Last Modified: 25 Jul 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring time settings via a vaconfig/time request.

    Source:SEC Consult
    Published:1 Aug 2016