CVE-2016-2000 to CVE-2016-2999
71 CVEs with public proof-of-concept exploits.
- CVE-2016-20045 PoCsHPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified…
- CVE-2016-20312 PoCsMultiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and…
- CVE-2016-20322 PoCsA vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system…
- CVE-2016-20463 PoCsCross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web…
- CVE-2016-20551 PoCxymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the…
- CVE-2016-20562 PoCsxymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell…
- CVE-2016-20671 PoCdrivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC)…
- CVE-2016-20872 PoCsDirectory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary files via a ..…
- CVE-2016-209815 PoCsAction Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary…
- CVE-2016-21073 PoCsThe AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding…
- CVE-2016-21181 PoCThe MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle…
- CVE-2016-21477 PoCsInteger overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to cause a denial of service (crash) via a…
- CVE-2016-21487 PoCsHeap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via…
- CVE-2016-21731 PoCorg.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
- CVE-2016-21831 PoCThe DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of…
- CVE-2016-21841 PoCThe create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows…
- CVE-2016-21851 PoCThe ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers…
- CVE-2016-21861 PoCThe powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to…
- CVE-2016-21882 PoCsThe iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to…
- CVE-2016-22033 PoCsThe management console on Symantec Messaging Gateway (SMG) Appliance devices before 10.6.1 allows local users to discover an encrypted AD…
- CVE-2016-22071 PoCThe AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through…
- CVE-2016-22081 PoCThe kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or…
- CVE-2016-22091 PoCBuffer overflow in Dec2SS.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center…
- CVE-2016-22101 PoCBuffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center…
- CVE-2016-22211 PoCOpen redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote…
- CVE-2016-22221 PoCThe wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request…
- CVE-2016-22261 PoCInteger overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a…
- CVE-2016-22333 PoCsStack-based buffer overflow in the inbound_cap_ls function in common/inbound.c in HexChat 2.10.2 allows remote IRC servers to cause a…
- CVE-2016-22421 PoCExponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
- CVE-2016-22781 PoCSchneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows remote…
- CVE-2016-22791 PoCCross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows…
- CVE-2016-22881 PoCCogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file.
- CVE-2016-22961 PoCMeteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows…
- CVE-2016-23341 PoCHeap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers…
- CVE-2016-23351 PoCThe CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a…
- CVE-2016-23361 PoCType confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of…
- CVE-2016-23371 PoCType confusion exists in _cancel_eval Ruby's TclTkIp class method. Attacker passing different type of object than String as "retval"…
- CVE-2016-23382 PoCsAn exploitable heap overflow vulnerability exists in the Psych::Emitter start_document function of Ruby. In Psych::Emitter start_document…
- CVE-2016-23391 PoCAn exploitable heap overflow vulnerability exists in the Fiddle::Function.new "initialize" function functionality of Ruby. In…
- CVE-2016-23451 PoCStack-based buffer overflow in dwrcs.exe in the dwmrcs daemon in SolarWinds DameWare Mini Remote Control 12.0 allows remote attackers to…
- CVE-2016-23471 PoCInteger underflow in the decode_level3_header function in lib/lha_file_header.c in Lhasa before 0.3.1 allows remote attackers to execute…
- CVE-2016-23561 PoCMilesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
- CVE-2016-23571 PoCMilesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
- CVE-2016-23581 PoCMilesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are…
- CVE-2016-23591 PoCMilesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by…
- CVE-2016-23601 PoCMilesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers'…
- CVE-2016-23842 PoCsDouble free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically…
- CVE-2016-23851 PoCHeap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before…
- CVE-2016-23866 PoCsKEVSQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands…
- CVE-2016-23885 PoCsKEVThe Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a…
- CVE-2016-23892 PoCsDirectory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0…
- CVE-2016-23993 PoCsInteger overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of…
- CVE-2016-24021 PoCOkHttp before 2.7.4 and 3.x before 3.1.2 allows man-in-the-middle attackers to bypass certificate pinning by sending a certificate chain…
- CVE-2016-24171 PoCmedia/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does…
- CVE-2016-24313 PoCsThe Qualcomm TrustZone component in Android before 2016-05-01 on Nexus 5, Nexus 6, Nexus 7 (2013), and Android One devices allows…
- CVE-2016-24344 PoCsThe NVIDIA video driver in Android before 2016-05-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka…
- CVE-2016-24681 PoCThe Qualcomm GPU driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 devices allows attackers to gain privileges via a…
- CVE-2016-24941 PoCOff-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows…
- CVE-2016-25102 PoCsBeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote…
- CVE-2016-25392 PoCsCross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to hijack the…
- CVE-2016-25556 PoCsSQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands…
- CVE-2016-25631 PoCStack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows remote servers to…
- CVE-2016-25691 PoCSquid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a…
- CVE-2016-27766 PoCsbuffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct…
- CVE-2016-27821 PoCThe treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a…
- CVE-2016-27841 PoCCMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning…
- CVE-2016-28191 PoCHeap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary…
- CVE-2016-28512 PoCsInteger overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory…
- CVE-2016-28531 PoCThe aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain…
- CVE-2016-28541 PoCThe aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain…
- CVE-2016-28561 PoCpt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and…