CVEs from 2016
Total
8,452
critical
critical 1,164
high
high 3,521
medium
medium 3,173
low
low 248
% Critical
13.8%
% with KEV
0.7%
% with exploit
6.8%
Top vendors
Top products
- phpmyadmin 3,382
- php 1,748
- squid 1,549
- samba 1,093
- drupal 868
- firefox 757
- moodle 700
- openssl 664
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-3488 | medium | 4.4 | 4.4 | 10y ago | Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows local users to affect integrity via unknown vectors. | |||
| CVE-2016-3480 | medium | 4.4 | 4.4 | 10y ago | Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect confidentiality via vectors related to HA for Postgresql. | |||
| CVE-2016-3287 | medium | 4.4 | 4.4 | 10y ago | Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to bypass the Secure Boot protection mechanism by leveraging administrative acc… | |||
| CVE-2016-5087 | medium | 4.4 | 4.4 | 10y ago | Alertus Desktop Notification before 2.9.31.1710 on OS X uses weak permissions for configuration files and unspecified other files, which allows local users to suppress emergency notifications or chan… | |||
| CVE-2016-5238 | medium | 4.4 | 4.4 | 10y ago | The get_cmd function in hw/scsi/esp.c in QEMU might allow local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via vectors related to reading from t… | |||
| CVE-2016-4453 | medium | 4.4 | 4.4 | 10y ago | The vmsvga_fifo_run function in hw/display/vmware_vga.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via a VGA command. | |||
| CVE-2016-0674 | medium | 4.4 | 4.4 | 10y ago | Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality and integrity via vectors related to Email. | |||
| CVE-2016-0667 | medium | 4.4 | 4.4 | 10y ago | Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Locking. | |||
| CVE-2016-0444 | medium | — | 4.4 | 11y ago | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confident… | |||
| CVE-2016-0757 | medium | 4.3 | 4.3 | 4y ago | OpenStack Image Service (Glance) before 2015.1.3 (kilo) and 11.0.x before 11.0.2 (liberty), when show_multiple_locations is enabled, allow remote authenticated users to change image status and upload… | |||
| CVE-2016-6024 | medium | 4.3 | 4.3 | 9y ago | IBM Jazz technology based products might divulge information that might be useful in helping attackers through error messages. IBM X-Force ID: 116868. | |||
| CVE-2016-2976 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936. | |||
| CVE-2016-2966 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847. | |||
| CVE-2016-0358 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928. | |||
| CVE-2016-2977 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937. | |||
| CVE-2016-2969 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime Meeting Server 8.5.2 and 9.0 may send replies that contain emails of people that should not be in these messages. IBM X-Force ID: 113850. | |||
| CVE-2016-2959 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804. | |||
| CVE-2016-10503 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime Meeting Server 8.5.2 and 9.0 could allow an authenticated and invited user of Sametime meeting to lower any or all hands in an e-meeting, thus spoofing results of votes in the meeting. I… | |||
| CVE-2016-2970 | medium | 4.3 | 4.3 | 9y ago | IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851. | |||
| CVE-2016-6018 | medium | 4.3 | 4.3 | 9y ago | IBM Emptoris Contract Management 10.0 and 10.1 reveals detailed error messages in certain features that could cause an attacker to gain additional information to conduct further attacks. IBM X-Force … | |||
| CVE-2016-9700 | medium | 4.3 | 4.3 | 9y ago | IBM Jazz Foundation could allow an authenticated attacker to obtain sensitive information from error message stack traces. IBM X-Force ID: 119528. | |||
| CVE-2016-7823 | medium | 4.3 | 4.3 | 9y ago | Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |||
| CVE-2016-7801 | medium | 4.3 | 4.3 | 9y ago | Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors. | |||
| CVE-2016-4910 | medium | 4.3 | 4.3 | 9y ago | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors. | |||
| CVE-2016-4909 | medium | 4.3 | 4.3 | 9y ago | Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors. | |||
| CVE-2016-4908 | medium | 4.3 | 4.3 | 9y ago | Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors. | |||
| CVE-2016-8987 | medium | 4.3 | 4.3 | 9y ago | IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. | |||
| CVE-2016-3051 | medium | 4.3 | 4.3 | 9y ago | IBM Security Access Manager for Web 9.0.0 could allow an authenticated user to access some privileged functionality of the server. IBM X-Force ID: 114714. | |||
| CVE-2016-4863 | medium | 4.3 | 4.3 | 9y ago | The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series… | |||
| CVE-2016-9735 | medium | 4.3 | 4.3 | 9y ago | IBM Jazz Foundation could allow an authenticated user to obtain sensitive information from stack traces. IBM X-Force ID: 119781, | |||
| CVE-2016-8030 | medium | 4.3 | 4.3 | 9y ago | A memory corruption vulnerability in Scriptscan COM Object in McAfee VirusScan Enterprise 8.8 Patch 8 and earlier allows remote attackers to create a Denial of Service on the active Internet Explorer… | |||
| CVE-2016-4841 | medium | 4.3 | 4.3 | 9y ago | Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers. | |||
| CVE-2016-9978 | medium | 4.3 | 4.3 | 9y ago | IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254. | |||
| CVE-2016-8923 | medium | 4.3 | 4.3 | 9y ago | IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that th… | |||
| CVE-2016-3733 | medium | 4.3 | 4.3 | 9y ago | Moodle Improper Access Control | |||
| CVE-2016-3732 | medium | 4.3 | 4.3 | 9y ago | Moodle sensitive information disclosure | |||
| CVE-2016-4844 | medium | 4.3 | 4.3 | 9y ago | Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks. | |||
| CVE-2016-4842 | medium | 4.3 | 4.3 | 9y ago | Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. | |||
| CVE-2016-1220 | medium | 4.3 | 4.3 | 9y ago | Cybozu Garoon before 4.2.2 does not properly restrict access. | |||
| CVE-2016-4873 | medium | 4.3 | 4.3 | 9y ago | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function. | |||
| CVE-2016-4872 | medium | 4.3 | 4.3 | 9y ago | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail. | |||
| CVE-2016-4868 | medium | 4.3 | 4.3 | 9y ago | Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests. | |||
| CVE-2016-4867 | medium | 4.3 | 4.3 | 9y ago | Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. | |||
| CVE-2016-8926 | medium | 4.3 | 4.3 | 9y ago | IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to read system files or data that is restricted to authorized users. IBM X-Force ID: 118539. | |||
| CVE-2016-8720 | medium | 4.3 | 4.3 | 9y ago | An exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted HTTP request can i… | |||
| CVE-2016-4320 | medium | 4.3 | 4.3 | 9y ago | Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource. | |||
| CVE-2016-10221 | medium | 4.3 | 4.3 | 9y ago | The count_entries function in pdf-layer.c in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted PDF docume… | |||
| CVE-2016-9464 | medium | 4.3 | 4.3 | 9y ago | Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users a… | |||
| CVE-2016-9462 | medium | 4.3 | 4.3 | 9y ago | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying wheth… | |||
| CVE-2016-9461 | medium | 4.3 | 4.3 | 9y ago | Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on… | |||
| CVE-2016-8973 | medium | 4.3 | 4.3 | 9y ago | IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an authenticated user to upload infected malicious files to the server. IBM Reference #: 1999960. | |||
| CVE-2016-2406 | medium | 4.3 | 4.3 | 9y ago | The permission control module in Huawei Document Security Management (aka DSM) before V100R002C05SPC670 allows remote authenticated users to obtain sensitive information from encrypted documents by l… | |||
| CVE-2016-9730 | medium | 4.3 | 4.3 | 9y ago | IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trus… | |||
| CVE-2016-7759 | medium | 4.3 | 4.3 | 9y ago | An issue was discovered in certain Apple products. iOS before 10 is affected. The issue involves the "Springboard" component, which allows physically proximate attackers to obtain sensitive informati… | |||
| CVE-2016-7592 | medium | 4.3 | 4.3 | 9y ago | An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves t… | |||
| CVE-2016-7581 | medium | 4.3 | 4.3 | 9y ago | An issue was discovered in certain Apple products. iOS before 10.1 is affected. The issue involves the "Safari" component, which allows remote web servers to cause a denial of service via a crafted U… | |||
| CVE-2016-6190 | medium | 4.3 | 4.3 | 9y ago | SOGo before 2.3.12 and 3.x before 3.1.1 does not restrict access to the UID and DTSTAMP attributes, which allows remote authenticated users to obtain sensitive information about appointments with the… | |||
| CVE-2016-6189 | medium | 4.3 | 4.3 | 9y ago | Incomplete blacklist in SOGo before 2.3.12 and 3.x before 3.1.1 allows remote authenticated users to obtain sensitive information by reading the fields in the (1) ics or (2) XML calendar feeds. | |||
| CVE-2016-6060 | medium | 4.3 | 4.3 | 9y ago | An undisclosed vulnerability in IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 could allow a JazzGuest user to see project names. IBM Reference #: 1995547. | |||
| CVE-2016-0308 | medium | 4.3 | 4.3 | 9y ago | IBM Connections 5.5 and earlier is vulnerable to possible link manipulation attack that could result in the display of inappropriate background images. | |||
| CVE-2016-0307 | medium | 4.3 | 4.3 | 9y ago | IBM Connections 5.5 and earlier allows remote attackers to obtain sensitive information by reading stack traces in returned responses. | |||
| CVE-2016-9748 | medium | 4.3 | 4.3 | 9y ago | IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. | |||
| CVE-2016-2866 | medium | 4.3 | 4.3 | 9y ago | An unspecified vulnerability in IBM Jazz Team Server may disclose some deployment information to an authenticated user. | |||
| CVE-2016-6094 | medium | 4.3 | 4.3 | 9y ago | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data. | |||
| CVE-2016-10208 | medium | 4.3 | 4.3 | 9y ago | The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of servic… | |||
| CVE-2016-0320 | medium | 4.3 | 4.3 | 10y ago | IBM UrbanCode Deploy could allow an authenticated user to modify Ucd objects due to multiple REST endpoints not properly authorizing users editing UCD objects. This could affect the behavior of legit… | |||
| CVE-2016-8912 | medium | 4.3 | 4.3 | 10y ago | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user. | |||
| CVE-2016-6122 | medium | 4.3 | 4.3 | 10y ago | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users. | |||
| CVE-2016-6044 | medium | 4.3 | 4.3 | 10y ago | IBM Tivoli Storage Manager Operations Center could allow an authenticated attacker to enable or disable the application's REST API, which may let the attacker violate security policy. | |||
| CVE-2016-6028 | medium | 4.3 | 4.3 | 10y ago | IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view. | |||
| CVE-2016-5949 | medium | 4.3 | 4.3 | 10y ago | IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request. | |||
| CVE-2016-5898 | medium | 4.3 | 4.3 | 10y ago | IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attacker could exploit th… | |||
| CVE-2016-2987 | medium | 4.3 | 4.3 | 10y ago | An undisclosed vulnerability in CLM applications may result in some administrative deployment parameters being shown to an attacker. | |||
| CVE-2016-8322 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily ex… | |||
| CVE-2016-8309 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0… | |||
| CVE-2016-8308 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2… | |||
| CVE-2016-8302 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.… | |||
| CVE-2016-8301 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.… | |||
| CVE-2016-5614 | medium | 4.3 | 4.3 | 10y ago | Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2… | |||
| CVE-2016-9221 | medium | 4.3 | 4.3 | 10y ago | A Denial of Service Vulnerability in 802.11 ingress connection authentication handling for the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attack… | |||
| CVE-2016-9220 | medium | 4.3 | 4.3 | 10y ago | A Denial of Service Vulnerability in 802.11 ingress packet processing of the Cisco Mobility Express 2800 and 3800 Access Points (APs) could allow an unauthenticated, adjacent attacker to cause the co… | |||
| CVE-2016-8643 | medium | 4.3 | 4.3 | 10y ago | In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services. | |||
| CVE-2016-9650 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-5225 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-5224 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-5214 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-10148 | medium | 4.3 | 4.3 | 10y ago | The wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 makes a get_plugin_data call before checking the update_plugins capability, which allows remote authen… | |||
| CVE-2016-7428 | medium | 4.3 | 4.3 | 10y ago | ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via the poll interval in a broadcast packet. | |||
| CVE-2016-7427 | medium | 4.3 | 4.3 | 10y ago | The broadcast mode replay prevention functionality in ntpd in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (reject broadcast mode packets) via a crafted broadcast mode pack… | |||
| CVE-2016-6859 | medium | 4.3 | 4.3 | 10y ago | Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace. | |||
| CVE-2016-7284 | medium | 4.3 | 4.3 | 10y ago | Microsoft Internet Explorer 10 and 11 allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability." | |||
| CVE-2016-5193 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-5188 | medium | 4.3 | 4.3 | 10y ago | multiple issues in chromium | |||
| CVE-2016-6852 | medium | 4.3 | 4.3 | 10y ago | An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file ex… | |||
| CVE-2016-4048 | medium | 4.3 | 4.3 | 10y ago | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev11. Custom messages can be shown at the login screen to notify external users about issues with sharing links. This mechanism can … | |||
| CVE-2016-4047 | medium | 4.3 | 4.3 | 10y ago | An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev8. References to external Open XML document type definitions (.dtd resources) can be placed within .docx and .xslx files. Those re… | |||
| CVE-2016-9209 | medium | 4.3 | 4.3 | 10y ago | A vulnerability in TCP processing in Cisco FirePOWER system software could allow an unauthenticated, remote attacker to download files that would normally be blocked. Affected Products: The following… | |||
| CVE-2016-6465 | medium | 4.3 | 4.3 | 10y ago | A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker … | |||
| CVE-2016-6625 | medium | 4.3 | 4.3 | 10y ago | phpMyAdmin allows to detect if user is logged in | |||
| CVE-2016-6610 | medium | 4.3 | 4.3 | 10y ago | A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on the disk. All 4.6.x ve… |