Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-9942

Published Dec 31, 2016

Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbi…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9941

Published Dec 31, 2016

Heap-based buffer overflow in rfbproto.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6859

Published Dec 31, 2016

Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6858

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6857

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris before 5.2.0.13, 5.3.x before 5.3.0.11, 5.4.x before 5.4.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6856

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to inject arbitrary web sc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10074

Published Dec 30, 2016

The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently exec…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-10034

Published Dec 30, 2016

The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote at…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10088

Published Dec 30, 2016

The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10085

Published Dec 30, 2016

admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10084

Published Dec 30, 2016

admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-10083

Published Dec 30, 2016

Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-10082

Published Dec 30, 2016

include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-9916

Published Dec 29, 2016

Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU proce…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9915

Published Dec 29, 2016

Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU proc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9914

Published Dec 29, 2016

Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process cra…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9913

Published Dec 29, 2016

Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host mem…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9846

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9845

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPS…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9776

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2198

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-2197

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1981

Published Dec 29, 2016

QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descript…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 6,449 CVEsPage 1 of 258