7.5
    High

    CVE-2016-0108

    Last Modified: 14 Mar 2016

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0102, CVE-2016-0103, CVE-2016-0106, CVE-2016-0109, and CVE-2016-0114.

    Source:Google Security Research
    Published:9 Mar 2016
    8.4
    High

    CVE-2016-0100

    Last Modified: 23 Mar 2017

    Microsoft Windows Vista SP2 and Server 2008 SP2 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Library Loading Input Validation Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:9 Mar 2016
    7.8
    High

    CVE-2016-0099

    Last Modified: 12 May 2016

    The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via a crafted application, aka "Secondary Logon Elevation of Privilege Vulnerability."

    Source:fdiskyou
    Published:9 Mar 2016
    7.8
    High

    CVE-2016-0095

    Last Modified: 12 Apr 2025

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.

    Published:9 Mar 2016
    7.8
    High

    CVE-2016-0094

    Last Modified: 1 Apr 2016

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0095, and CVE-2016-0096.

    Source:Nils Sommer
    Published:9 Mar 2016
    7.8
    High

    CVE-2016-0093

    Last Modified: 1 Apr 2016

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0094, CVE-2016-0095, and CVE-2016-0096.

    Source:Nils Sommer
    Published:9 Mar 2016
    5
    Medium

    CVE-2016-0079

    Last Modified: 31 Oct 2016

    The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2016
    5.5
    Medium

    CVE-2016-0075

    Last Modified: 21 Oct 2016

    The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0073.

    Source:Google Security Research
    Published:14 Oct 2016
    5
    Medium

    CVE-2016-0073

    Last Modified: 21 Oct 2016

    The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0075.

    Source:Google Security Research
    Published:14 Oct 2016
    5.5
    Medium

    CVE-2016-0070

    Last Modified: 21 Oct 2016

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to access sensitive information in the registry, aka "Windows Kernel Local Elevation of Privilege Vulnerability."

    Source:Google Security Research
    Published:14 Oct 2016
    8.8
    High

    CVE-2016-0063

    Last Modified: 2 Dec 2016

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0061, CVE-2016-0067, and CVE-2016-0072.

    Source:Skylined
    Published:10 Feb 2016
    7.8
    High

    CVE-2016-0051

    Last Modified: 10 Oct 2016

    The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "WebDAV Elevation of Privilege Vulnerability."

    Source:hex0r
    Published:10 Feb 2016
    6.2
    Medium

    CVE-2016-0049

    Last Modified: 15 Feb 2016

    Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 does not properly validate password changes, which allows remote attackers to bypass authentication by deploying a crafted Key Distribution Center (KDC) and then performing a sign-in action, aka "Windows Kerberos Security Feature Bypass."

    Source:Nabeel Ahmed
    Published:10 Feb 2016
    7.8
    High

    CVE-2016-0041

    Last Modified: 23 Mar 2017

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold and 1511, and Internet Explorer 10 and 11 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."

    Source:Metasploit
    Published:10 Feb 2016
    7.8
    High

    CVE-2016-0040

    Last Modified: 18 May 2018

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

    Source:Metasploit
    Published:10 Feb 2016
    7.8
    High

    CVE-2016-0016

    Last Modified: 6 Sept 2016

    Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandle DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:13 Jan 2016
    7.8
    High

    CVE-2016-0015

    Last Modified: 3 May 2018

    DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted file, aka "DirectShow Heap Corruption Remote Code Execution Vulnerability."

    Source:Google Security Research
    Published:13 Jan 2016
    7.8
    High

    CVE-2016-0007

    Last Modified: 25 Jan 2016

    The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0006.

    Source:Google Security Research
    Published:13 Jan 2016
    7.3
    High

    CVE-2016-0006

    Last Modified: 25 Jan 2016

    The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 Gold and 1511 mishandles reparse points, which allows local users to gain privileges via a crafted application, aka "Windows Mount Point Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0007.

    Source:Google Security Research
    Published:13 Jan 2016
    Unknown

    CVE-2015-57115

    https://github.com/TrixSec/CVE-2015-57115

    7.6
    High

    CVE-2015-20107

    Last Modified: 3 Nov 2025

    In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9

    Published:2 Aug 2015
    9.3
    Critical

    CVE-2015-10141

    Last Modified: 15 Apr 2026

    An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension developed by Derick Rethans. When remote debugging is enabled, Xdebug listens on port 9000 and accepts debugger protocol commands without authentication. An attacker can send a crafted eval command over this interface to execute arbitrary PHP code, which may invoke system-level functions such as system() or passthru(). This results in full compromise of the host under the privileges of the web server user.

    Published:23 Jul 2025
    9.8
    Critical

    CVE-2015-10137

    Last Modified: 8 Apr 2026

    The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

    Published:22 Jul 2025
    5.5
    Medium

    CVE-2015-10034

    Last Modified: 21 Nov 2024

    A vulnerability has been found in j-nowak workout-organizer and classified as critical. This vulnerability affects unknown code. The manipulation leads to sql injection. The patch is identified as 13cd6c3d1210640bfdb39872b2bb3597aa991279. It is recommended to apply a patch to fix this issue. VDB-217714 is the identifier assigned to this vulnerability.

    Published:9 Jan 2023
    6.1
    Medium

    CVE-2015-9357

    Last Modified: 21 Nov 2024

    The akismet plugin before 3.1.5 for WordPress has XSS.

    Published:28 Aug 2019
    7.5
    High

    CVE-2015-9331

    Last Modified: 21 Nov 2024

    The wp-all-import plugin before 3.2.4 for WordPress has no prevention of unauthenticated requests to adminInit.

    Published:20 Aug 2019
    9.8
    Critical

    CVE-2015-9323

    Last Modified: 2 Feb 2022

    The 404-to-301 plugin before 2.0.3 for WordPress has SQL injection.

    Source:Ron Jost
    Published:16 Aug 2019
    9.8
    Critical

    CVE-2015-9266

    Last Modified: 1 Feb 2019

    The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

    Source:93c08539
    Published:5 Sept 2018
    6.1
    Medium

    CVE-2015-9251

    Last Modified: 21 Nov 2024

    jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.

    Published:27 Jun 2015
    5.3
    Medium

    CVE-2015-9238

    Last Modified: 21 Nov 2024

    secure-compare 3.0.0 and below do not actually compare two strings properly. compare was actually comparing the first argument with itself, meaning the check passed for any two strings of the same length.

    Published:31 May 2018
    9.8
    Critical

    CVE-2015-9235

    Last Modified: 21 Nov 2024

    In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

    Published:31 Mar 2018
    7.5
    High

    CVE-2015-9222

    Last Modified: 27 Apr 2016

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 835, SD 845, SDM630, SDM636, SDM660, and Snapdragon_High_Med_2016, processing erroneous bitstreams may result in a HW freeze. FW should detect the HW freeze based on watchdog timer, but because the watchdog timer is not enabled, an infinite loop occurs, resulting in a device freeze.

    Source:Milad Doorbash
    Published:18 Apr 2018
    9.8
    Critical

    CVE-2015-9098

    Last Modified: 14 Aug 2017

    In Redgate SQL Monitor before 3.10 and 4.x before 4.2, a remote attacker can gain unauthenticated access to the Base Monitor, resulting in the ability to execute arbitrary SQL commands on any monitored Microsoft SQL Server machines. If the Base Monitor is connecting to these machines using an account with SQL admin privileges, then code execution on the operating system can result in full system compromise (if Microsoft SQL Server is running with local administrator privileges).

    Source:Paul Taylor
    Published:22 Jun 2017
    7.5
    High

    CVE-2015-8770

    Last Modified: 28 Dec 2016

    Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before 1.0.8 and 1.1.x before 1.1.4 allows remote authenticated users with certain permissions to read arbitrary files or possibly execute arbitrary code via a .. (dot dot) in the _skin parameter to index.php.

    Source:High-Tech Bridge SA
    Published:29 Jan 2016
    5.3
    Medium

    CVE-2015-8740

    Last Modified: 16 Dec 2015

    The dissect_tds7_colmetadata_token function in epan/dissectors/packet-tds.c in the TDS dissector in Wireshark 2.0.x before 2.0.1 does not validate the number of columns, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8739

    Last Modified: 16 Dec 2015

    The ipmi_fmt_udpport function in epan/dissectors/packet-ipmi.c in the IPMI dissector in Wireshark 2.0.x before 2.0.1 improperly attempts to access a packet scope, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8736

    Last Modified: 16 Dec 2015

    The mp2t_find_next_pcr function in wiretap/mp2t.c in the MP2T file parser in Wireshark 2.0.x before 2.0.1 does not reserve memory for a trailer, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted file.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8735

    Last Modified: 16 Dec 2015

    The get_value function in epan/dissectors/packet-btatt.c in the Bluetooth Attribute (aka BT ATT) dissector in Wireshark 2.0.x before 2.0.1 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (invalid write operation and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8733

    Last Modified: 22 Dec 2015

    The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8732

    Last Modified: 16 Dec 2015

    The dissect_zcl_pwr_prof_pwrprofstatersp function in epan/dissectors/packet-zbee-zcl-general.c in the ZigBee ZCL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the Total Profile Number field, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8731

    Last Modified: 16 Dec 2015

    The dissct_rsl_ipaccess_msg function in epan/dissectors/packet-rsl.c in the RSL dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not reject unknown TLV types, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8730

    Last Modified: 16 Dec 2015

    epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the number of items, which allows remote attackers to cause a denial of service (invalid read operation and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8729

    Last Modified: 16 Dec 2015

    The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a '\0' character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8728

    Last Modified: 16 Dec 2015

    The Mobile Identity parser in (1) epan/dissectors/packet-ansi_a.c in the ANSI A dissector and (2) epan/dissectors/packet-gsm_a_common.c in the GSM A dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 improperly uses the tvb_bcd_dig_to_wmem_packet_str function, which allows remote attackers to cause a denial of service (buffer overflow and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8727

    Last Modified: 16 Dec 2015

    The dissect_rsvp_common function in epan/dissectors/packet-rsvp.c in the RSVP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not properly maintain request-key data, which allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8726

    Last Modified: 16 Dec 2015

    wiretap/vwr.c in the VeriWave file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate certain signature and Modulation and Coding Scheme (MCS) data, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8725

    Last Modified: 16 Dec 2015

    The dissect_diameter_base_framed_ipv6_prefix function in epan/dissectors/packet-diameter.c in the DIAMETER dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the IPv6 prefix length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8724

    Last Modified: 22 Dec 2015

    The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not verify the WPA broadcast key length, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    5.5
    Medium

    CVE-2015-8723

    Last Modified: 16 Dec 2015

    The AirPDcapPacketProcess function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationship between the total length and the capture length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) via a crafted packet.

    Source:Google Security Research
    Published:29 Dec 2015
    9.8
    Critical

    CVE-2015-8710

    Last Modified: 12 Apr 2025

    The htmlParseComment function in HTMLparser.c in libxml2 allows attackers to obtain sensitive information, cause a denial of service (out-of-bounds heap memory access and application crash), or possibly have unspecified other impact via an unclosed HTML comment.

    Published:19 Apr 2015