Skip to main content

Year archive

CVEs published in 2016

Archive summary

6,449 CVEs published in 2016 — 895 Critical, 2,887 High, 2,446 Medium, 221 Low, 0 Unrated.

CVE-2016-6834

Published Dec 10, 2016

The net_tx_pkt_do_sw_fragmentation function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop an…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6833

Published Dec 10, 2016

Use-after-free vulnerability in the vmxnet3_io_bar0_write function in hw/net/vmxnet3.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of servi…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6490

Published Dec 10, 2016

The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU proces…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4964

Published Dec 10, 2016

The mptsas_fetch_requests function in hw/scsi/mptsas.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop, and CPU consu…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5424

Published Dec 9, 2016

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATERO…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-5423

Published Dec 9, 2016

PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 allow remote authenticated users to cause a denial of service (NULL…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9103

Published Dec 9, 2016

The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory information by reading xattrib…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-9102

Published Dec 9, 2016

Memory leak in the v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (memory consumption and…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6501

Published Dec 9, 2016

JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP entry poisoning.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6496

Published Dec 9, 2016

The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serializ…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6321

Published Dec 9, 2016

Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6523

Published Dec 9, 2016

Multiple cross-site scripting (XSS) vulnerabilities in the media manager in Dotclear before 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) q or (2)…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6301

Published Dec 9, 2016

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged NTP pack…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8786

Published Dec 9, 2016

The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_ag…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8858

Published Dec 9, 2016

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate KEXI…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-9120

Published Dec 8, 2016

Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or cause a denial of service (us…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8967

Published Dec 8, 2016

arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and conseq…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 451-475 of 6,449 CVEsPage 19 of 258