Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-6616

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6615

Published Dec 11, 2016

XSS issues were discovered in phpMyAdmin. This affects navigation pane and database/table hiding feature (a specially-crafted database name can be used to trigger an XSS attack);…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6614

Published Dec 11, 2016

An issue was discovered in phpMyAdmin involving the %u username replacement functionality of the SaveDir and UploadDir features. When the username substitution is configured, a sp…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6613

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is not, which phpMyAdmin will the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6612

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. All 4.6.x versions (prior to 4.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6611

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A specially crafted database and/or table name can be used to trigger an SQL injection attack through the export functionality. All 4.6.x ve…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6610

Published Dec 11, 2016

A full path disclosure vulnerability was discovered in phpMyAdmin where a user can trigger a particular error in the export mechanism to discover the full path of phpMyAdmin on th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6609

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A specially crafted database name could be used to run arbitrary PHP commands through the array export feature. All 4.6.x versions (prior to…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6608

Published Dec 11, 2016

XSS issues were discovered in phpMyAdmin. This affects the database privilege check and the "Remove partitioning" functionality. Specially crafted database names can trigger the X…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6607

Published Dec 11, 2016

XSS issues were discovered in phpMyAdmin. This affects Zoom search (specially crafted column content can be used to trigger an XSS attack); GIS editor (certain fields in the graph…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6606

Published Dec 11, 2016

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This can allow an attacker who has ac…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-4412

Published Dec 11, 2016

An issue was discovered in phpMyAdmin. A user can be tricked into following a link leading to phpMyAdmin, which after authentication redirects to another malicious site. The attac…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9832

Published Dec 10, 2016

PricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and execute arbitrary code via (1) SAPGUI or (2…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-7995

Published Dec 10, 2016

Memory leak in the ehci_process_itd function in hw/usb/hcd-ehci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumptio…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7994

Published Dec 10, 2016

Memory leak in the virtio_gpu_resource_create_2d function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7421

Published Dec 10, 2016

The pvscsi_ring_pop_req_descr function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QE…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7157

Published Dec 10, 2016

The (1) mptsas_config_manufacturing_1 and (2) mptsas_config_ioc_0 functions in hw/scsi/mptconfig.c in QEMU (aka Quick Emulator) allow local guest OS administrators to cause a deni…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7156

Published Dec 10, 2016

The pvscsi_convert_sglist function in hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU p…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7155

Published Dec 10, 2016

hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash)…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7116

Published Dec 10, 2016

Directory traversal vulnerability in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to access host files outside the export path via a .. (dot dot)…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6836

Published Dec 10, 2016

The vmxnet3_complete_packet function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host memory information by leveragin…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 426-450 of 6,449 CVEsPage 18 of 258