Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-9480 | 1 Libdwarf Project | 1 Libdwarf | 2016-12-22 | 6.4 MEDIUM | 9.1 CRITICAL |
libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006. | |||||
CVE-2016-9214 | 1 Cisco | 1 Identity Services Engine Software | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Cisco Identity Services Engine (ISE) contains a vulnerability that could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvb86332 CSCvb86760. Known Affected Releases: 2.0(101.130). | |||||
CVE-2016-9215 | 1 Cisco | 1 Ios Xr | 2016-12-22 | 7.2 HIGH | 7.8 HIGH |
A vulnerability in Cisco IOS XR Software could allow an authenticated, local attacker to log in to the device with the privileges of the root user. More Information: CSCva38434. Known Affected Releases: 6.1.1.BASE. | |||||
CVE-2016-9201 | 1 Cisco | 1 Ios | 2016-12-22 | 5.0 MEDIUM | 7.5 HIGH |
A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass traffic that should otherwise have been dropped based on the configuration. More Information: CSCuz21015. Known Affected Releases: 15.3(3)M3. Known Fixed Releases: 15.6(2)T0.1 15.6(2.0.1a)T0 15.6(2.19)T 15.6(3)M. | |||||
CVE-2016-9202 | 1 Cisco | 1 Email Security Appliance | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) Switches could allow an unauthenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the affected interface on an affected device. More Information: CSCvb37346. Known Affected Releases: 9.1.1-036 9.7.1-066. | |||||
CVE-2016-9965 | 1 Samsung | 1 Samsung Mobile | 2016-12-22 | 10.0 HIGH | 9.8 CRITICAL |
Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a possible DoS attack, or possibly gain privileges. The Samsung ID is SVE-2016-7119. | |||||
CVE-2016-9200 | 1 Cisco | 1 Prime Collaboration Assurance | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
A vulnerability in the web framework code of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface. More Information: CSCut43268. Known Affected Releases: 10.5(1) 10.6. | |||||
CVE-2016-9966 | 1 Samsung | 1 Samsung Mobile | 2016-12-22 | 10.0 HIGH | 9.8 CRITICAL |
Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a possible DoS attack, or possibly gain privileges. The Samsung ID is SVE-2016-7120. | |||||
CVE-2016-9967 | 1 Samsung | 1 Samsung Mobile | 2016-12-22 | 10.0 HIGH | 9.8 CRITICAL |
Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a possible DoS attack, or possibly gain privileges. The Samsung ID is SVE-2016-7121. | |||||
CVE-2016-9199 | 1 Cisco | 1 Iox | 2016-12-22 | 6.8 MEDIUM | 6.5 MEDIUM |
A vulnerability in the Cisco application-hosting framework (CAF) of Cisco IOx could allow an authenticated, remote attacker to read arbitrary files on a targeted system. Affected Products: This vulnerability affects specific releases of the Cisco IOx subsystem of Cisco IOS and IOS XE Software. More Information: CSCvb23331. Known Affected Releases: 15.2(6.0.57i)E CAF-1.1.0.0. | |||||
CVE-2016-9198 | 1 Cisco | 1 Identity Services Engine | 2016-12-22 | 5.0 MEDIUM | 7.5 HIGH |
A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to perform a denial of service (DoS) attack. More Information: CSCuw15041. Known Affected Releases: 1.2(1.199). | |||||
CVE-2016-6657 | 1 Pivotal Software | 2 Cloud Foundry Elastic Runtime, Cloud Foundry Ops Manager | 2016-12-22 | 5.8 MEDIUM | 7.4 HIGH |
An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runtime 1.8.x versions to 1.8.12 or later. Upgrade PCF Ops Manager 1.7.x versions to 1.7.18 or later and 1.8.x versions to 1.8.10 or later. | |||||
CVE-2016-9837 | 1 Joomla | 1 Joomla\! | 2016-12-22 | 5.0 MEDIUM | 7.5 HIGH |
An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request. | |||||
CVE-2016-0618 | 1 Oracle | 1 Solaris | 2016-12-22 | 1.4 LOW | N/A |
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones. | |||||
CVE-2016-0868 | 1 Rockwellautomation | 9 1763-l16awa Series A, 1763-l16awa Series B, 1763-l16bbb Series A and 6 more | 2016-12-22 | 10.0 HIGH | 9.8 CRITICAL |
Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers to execute arbitrary code via a crafted web request. | |||||
CVE-2016-1000003 | 1 Mirror Manager Project | 1 Mirror Manager | 2016-12-22 | 7.5 HIGH | 9.8 CRITICAL |
Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code. | |||||
CVE-2016-1000142 | 1 Parsi-font Project | 1 Parsi-font | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin parsi-font v4.2.5 | |||||
CVE-2016-1000145 | 1 Pondol-carousel Project | 1 Pondol-carousel | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin pondol-carousel v1.0 | |||||
CVE-2016-1000155 | 1 Wpsolr | 1 Wpsolr-search-engine | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin wpsolr-search-engine v7.6 | |||||
CVE-2016-1000217 | 1 Zotpress Project | 1 Zotpress | 2016-12-22 | 7.5 HIGH | 9.8 CRITICAL |
Zotpress plugin for WordPress SQLi in zp_get_account() |