CVEs from 2016
Total
8,461
critical
critical 1,164
high
high 3,521
medium
medium 3,173
low
low 248
% Critical
13.8%
% with KEV
0.7%
% with exploit
6.8%
Top vendors
Top products
- phpmyadmin 3,382
- php 1,748
- squid 1,549
- samba 1,093
- drupal 868
- firefox 757
- moodle 700
- openssl 664
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-2392 | medium | 6.5 | 6.5 | 10y ago | The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administr… | |||
| CVE-2016-3226 | medium | 6.5 | 6.5 | 10y ago | Active Directory in Microsoft Windows Server 2008 R2 SP1 and Server 2012 Gold and R2 allows remote authenticated users to cause a denial of service (service hang) by creating many machine accounts, a… | |||
| CVE-2016-3201 | medium | 6.5 | 6.5 | 10y ago | Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive information from process memory via a crafted PDF docum… | |||
| CVE-2016-3198 | medium | 6.5 | 6.5 | 10y ago | Microsoft Edge allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via a crafted document, aka "Microsoft Edge Security Feature Bypass." | |||
| CVE-2016-10362 | medium | 6.5 | 6.5 | 10y ago | Logstash Logs Sensitive Information | |||
| CVE-2016-3677 | medium | 6.5 | 6.5 | 10y ago | The Huawei Wear App application before 15.0.0.307 for Android does not validate SSL certificates, which allows local users to have unspecified impact via unknown vectors, aka HWPSIRT-2016-03008. | |||
| CVE-2016-2829 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or… | |||
| CVE-2016-2825 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL. | |||
| CVE-2016-2822 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. | |||
| CVE-2016-3085 | medium | 6.5 | 6.5 | 10y ago | Apache CloudStack 4.5.x before 4.5.2.1, 4.6.x before 4.6.2.1, 4.7.x before 4.7.1.1, and 4.8.x before 4.8.0.1, when SAML-based authentication is enabled and used, allow remote attackers to bypass auth… | |||
| CVE-2016-4524 | medium | 6.5 | 6.5 | 10y ago | ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sensitive information via unknown vectors. | |||
| CVE-2016-2149 | medium | 6.5 | 6.5 | 10y ago | Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously deleted namespace when creating a new namespace. | |||
| CVE-2016-1702 | medium | 6.5 | 6.5 | 10y ago | The SkRegion::readFromMemory function in core/SkRegion.cpp in Skia, as used in Google Chrome before 51.0.2704.79, does not validate the interval count, which allows remote attackers to cause a denial… | |||
| CVE-2016-1699 | medium | 6.5 | 6.5 | 10y ago | WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, does not ensure that the remoteFrontendUrl paramet… | |||
| CVE-2016-1698 | medium | 6.5 | 6.5 | 10y ago | The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not validate module types, which might allow attackers to… | |||
| CVE-2016-1689 | medium | 6.5 | 6.5 | 10y ago | Heap-based buffer overflow in content/renderer/media/canvas_capture_handler.cc in Google Chrome before 51.0.2704.63 allows remote attackers to cause a denial of service or possibly have unspecified o… | |||
| CVE-2016-1688 | medium | 6.5 | 6.5 | 10y ago | The regexp (aka regular expression) implementation in Google V8 before 5.0.71.40, as used in Google Chrome before 51.0.2704.63, mishandles external string sizes, which allows remote attackers to caus… | |||
| CVE-2016-1687 | medium | 6.5 | 6.5 | 10y ago | The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers to obtain sensitive information via vectors relat… | |||
| CVE-2016-1686 | medium | 6.5 | 6.5 | 10y ago | The CPDF_DIBSource::CreateDecoder function in core/fpdfapi/fpdf_render/fpdf_render_loadimage.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, mishandles decoder-initialization failure, wh… | |||
| CVE-2016-1685 | medium | 6.5 | 6.5 | 10y ago | core/fxge/ge/fx_ge_text.cpp in PDFium, as used in Google Chrome before 51.0.2704.63, miscalculates certain index values, which allows remote attackers to cause a denial of service (out-of-bounds read… | |||
| CVE-2016-1677 | medium | 6.5 | 6.5 | 10y ago | uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeU… | |||
| CVE-2016-0288 | medium | 6.5 | 6.5 | 10y ago | IBM Security AppScan Standard 8.7.x, 8.8.x, and 9.x before 9.0.3.2 and Security AppScan Enterprise allow remote authenticated users to read arbitrary files via an XML document containing an external … | |||
| CVE-2016-2311 | medium | 6.5 | 6.5 | 10y ago | Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior with PoE with firmware before SP473, and AlertWerks S… | |||
| CVE-2016-1413 | medium | 6.5 | 6.5 | 10y ago | The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517. | |||
| CVE-2016-1379 | medium | 6.5 | 6.5 | 10y ago | Cisco Adaptive Security Appliance (ASA) Software 9.0 through 9.5.1 mishandles IPsec error processing, which allows remote authenticated users to cause a denial of service (memory consumption) via cra… | |||
| CVE-2016-1385 | medium | 6.5 | 6.5 | 10y ago | The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (instability, memory consumption, or device reload) by … | |||
| CVE-2016-4020 | medium | 6.5 | 6.5 | 10y ago | The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory … | |||
| CVE-2016-4578 | medium | 5.5 | 6.5 | 10y ago | sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive information from kernel stack memory via crafted use of… | |||
| CVE-2016-1858 | medium | 6.5 | 6.5 | 10y ago | WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attackers to obtain sensitive information via a crafted … | |||
| CVE-2016-1839 | medium | 5.5 | 6.5 | 10y ago | The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to cause a denial o… | |||
| CVE-2016-1838 | medium | 5.5 | 6.5 | 10y ago | The xmlPArserPrintFileContextInternal function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1, allows remote attackers to… | |||
| CVE-2016-1811 | medium | 6.5 | 6.5 | 10y ago | ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image. | |||
| CVE-2016-4425 | medium | 6.5 | 6.5 | 10y ago | Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JSON data. | |||
| CVE-2016-3724 | medium | 6.5 | 6.5 | 10y ago | Jenkins Exposes Sensitive Information from Job Configuration | |||
| CVE-2016-0323 | medium | 6.5 | 6.5 | 10y ago | The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS… | |||
| CVE-2016-1665 | medium | 6.5 | 6.5 | 10y ago | The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sen… | |||
| CVE-2016-2860 | medium | 6.5 | 6.5 | 10y ago | The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intended access restrictions and create arbitrary groups … | |||
| CVE-2016-2013 | medium | 6.5 | 6.5 | 10y ago | HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||
| CVE-2016-2012 | medium | 6.5 | 6.5 | 10y ago | HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote attackers to bypass authentication via unspecified vectors. | |||
| CVE-2016-3717 | medium | 5.5 | 6.5 | 10y ago | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | |||
| CVE-2016-2168 | medium | 6.5 | 6.5 | 10y ago | The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service … | |||
| CVE-2016-2816 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type. | |||
| CVE-2016-2813 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's phys… | |||
| CVE-2016-2300 | medium | 6.5 | 6.5 | 10y ago | Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors. | |||
| CVE-2016-0684 | medium | 6.5 | 6.5 | 10y ago | Unspecified vulnerability in the Oracle Retail MICROS ARS POS component in Oracle Retail Applications 1.5 allows remote authenticated users to affect confidentiality via vectors related to POS. | |||
| CVE-2016-0407 | medium | 6.5 | 6.5 | 10y ago | Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusio… | |||
| CVE-2016-3688 | medium | 6.5 | 6.5 | 10y ago | SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/plaincall/UserAjax.getUsersList.dwr. | |||
| CVE-2016-3950 | medium | 6.5 | 6.5 | 10y ago | Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted packets. | |||
| CVE-2016-1654 | medium | 6.5 | 6.5 | 10y ago | The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a denial of service (invalid read operation) via unk… | |||
| CVE-2016-2411 | medium | 6.5 | 6.5 | 10y ago | A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages root access, aka internal bug 26866053. | |||
| CVE-2016-2191 | medium | 6.5 | 6.5 | 10y ago | The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a craf… | |||
| CVE-2016-0775 | medium | 6.5 | 6.5 | 10y ago | Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file. | |||
| CVE-2016-0740 | medium | 6.5 | 6.5 | 10y ago | Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file. | |||
| CVE-2016-0161 | medium | 6.5 | 6.5 | 10y ago | Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-015… | |||
| CVE-2016-0158 | medium | 6.5 | 6.5 | 10y ago | Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-016… | |||
| CVE-2016-2166 | medium | 6.5 | 6.5 | 10y ago | Moderate severity vulnerability that affects org.apache.qpid:proton-j | |||
| CVE-2016-3985 | medium | 6.5 | 6.5 | 10y ago | The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access re… | |||
| CVE-2016-2858 | medium | 6.5 | 6.5 | 10y ago | QEMU, when built with the Pseudo Random Number Generator (PRNG) back-end support, allows local guest OS users to cause a denial of service (process crash) via an entropy request, which triggers arbit… | |||
| CVE-2016-2292 | medium | 6.5 | 6.5 | 10y ago | Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitra… | |||
| CVE-2016-2291 | medium | 6.5 | 6.5 | 10y ago | Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers to execute arbitrary code or cause a denial of ser… | |||
| CVE-2016-3118 | medium | 6.5 | 6.5 | 10y ago | CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 allows remote attackers to have an unspecified imp… | |||
| CVE-2016-1366 | medium | 6.5 | 6.5 | 10y ago | The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which allows remote authenticated users to cause a denia… | |||
| CVE-2016-1785 | medium | 6.5 | 6.5 | 10y ago | The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, which allows remote attackers to bypass the Same Or… | |||
| CVE-2016-1784 | medium | 6.5 | 6.5 | 10y ago | The History implementation in WebKit in Apple iOS before 9.3, Safari before 9.1, and tvOS before 9.2 allows remote attackers to cause a denial of service (resource consumption and application crash) … | |||
| CVE-2016-1782 | medium | 6.5 | 6.5 | 10y ago | WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attackers to bypass intended port restrictions via a craf… | |||
| CVE-2016-1779 | medium | 6.5 | 6.5 | 10y ago | WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a crafted geolocation request. | |||
| CVE-2016-1771 | medium | 6.5 | 6.5 | 10y ago | The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site. | |||
| CVE-2016-1770 | medium | 6.5 | 6.5 | 10y ago | The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing action via a tel: URL. | |||
| CVE-2016-1994 | medium | 6.5 | 6.5 | 10y ago | HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||
| CVE-2016-1992 | medium | 6.5 | 6.5 | 10y ago | HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||
| CVE-2016-2846 | medium | 6.5 | 6.5 | 10y ago | Siemens SIMATIC S7-1200 CPU devices before 4.0 allow remote attackers to bypass a "user program block" protection mechanism via unspecified vectors. | |||
| CVE-2016-1967 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive inform… | |||
| CVE-2016-1956 | medium | 6.5 | 6.5 | 10y ago | Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a W… | |||
| CVE-2016-0830 | medium | 6.5 | 6.5 | 10y ago | btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of config… | |||
| CVE-2016-1338 | medium | 6.5 | 6.5 | 10y ago | Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) via a crafted SIP message, aka Bug ID CSCuu43026. | |||
| CVE-2016-1637 | medium | 6.5 | 6.5 | 10y ago | The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain se… | |||
| CVE-2016-2232 | medium | 6.5 | 6.5 | 10y ago | Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3 allow remote authenticated users to ca… | |||
| CVE-2016-2037 | medium | 6.5 | 6.5 | 10y ago | The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file. | |||
| CVE-2016-2398 | medium | 6.5 | 6.5 | 10y ago | Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 G… | |||
| CVE-2016-1333 | medium | 6.5 | 6.5 | 10y ago | Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OI… | |||
| CVE-2016-1153 | medium | 6.5 | 6.5 | 10y ago | customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489. | |||
| CVE-2016-1330 | medium | 6.5 | 6.5 | 10y ago | Cisco IOS 15.2(4)E on Industrial Ethernet 2000 devices allows remote attackers to cause a denial of service (device reload) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuy27746. | |||
| CVE-2016-1523 | medium | 6.5 | 6.5 | 10y ago | The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows… | |||
| CVE-2016-2073 | medium | 6.5 | 6.5 | 10y ago | The htmlParseNameComplex function in HTMLparser.c in libxml2 allows attackers to cause a denial of service (out-of-bounds read) via a crafted XML document. | |||
| CVE-2016-0881 | medium | 6.5 | 6.5 | 10y ago | EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository informati… | |||
| CVE-2016-2089 | medium | 6.5 | 6.5 | 10y ago | The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted JPEG 2000 image. | |||
| CVE-2016-1308 | medium | 6.5 | 6.5 | 11y ago | SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCux99227. | |||
| CVE-2016-2213 | medium | 6.5 | 6.5 | 11y ago | The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.6 allows remote attackers to cause a denial of service (out-of-bounds array read access) via crafted JPEG 2000 data. | |||
| CVE-2016-1938 | medium | 6.5 | 6.5 | 11y ago | The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier fo… | |||
| CVE-2016-1933 | medium | 6.5 | 6.5 | 11y ago | Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted G… | |||
| CVE-2016-1924 | medium | 6.5 | 6.5 | 11y ago | The opj_tgt_reset function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image. | |||
| CVE-2016-1923 | medium | 6.5 | 6.5 | 11y ago | Heap-based buffer overflow in the opj_j2k_update_image_data function in OpenJpeg 2016.1.18 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafte… | |||
| CVE-2016-1618 | medium | 6.5 | 6.5 | 11y ago | Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat … | |||
| CVE-2016-1615 | medium | 6.5 | 6.5 | 11y ago | The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors. | |||
| CVE-2016-0502 | medium | 6.5 | 6.5 | 11y ago | Unspecified vulnerability in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer. | |||
| CVE-2016-0489 | medium | — | 6.5 | 11y ago | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality… | |||
| CVE-2016-0442 | medium | — | 6.5 | 11y ago | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote authenticated users to affect confidentiality… | |||
| CVE-2016-1867 | medium | 6.5 | 6.5 | 11y ago | The jpc_pi_nextcprl function in JasPer 1.900.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG 2000 image. | |||
| CVE-2016-0777 | medium | 6.5 | 6.5 | 11y ago | The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmiss… | |||
| CVE-2016-1569 | medium | 6.5 | 6.5 | 11y ago | FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with an invalid parameter. |