CVE-2016-4000 to CVE-2016-4999
109 CVEs with public proof-of-concept exploits.
- CVE-2016-40041 PoCDirectory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated administrators to read…
- CVE-2016-40106 PoCsMagento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via…
- CVE-2016-40143 PoCsXML external entity (XXE) vulnerability in the UDDI component in SAP NetWeaver JAVA AS 7.4 allows remote attackers to cause a denial of…
- CVE-2016-40162 PoCsCross-site scripting (XSS) vulnerability in SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) 15 allows remote…
- CVE-2016-40291 PoCWordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote…
- CVE-2016-40301 PoCSamsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4…
- CVE-2016-40311 PoCSamsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4…
- CVE-2016-40321 PoCSamsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4…
- CVE-2016-40551 PoCThe duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU…
- CVE-2016-40711 PoCFormat string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before…
- CVE-2016-40751 PoCOpera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the…
- CVE-2016-41081 PoCUnspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsoft Internet…
- CVE-2016-41172 PoCsKEVAdobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the…
- CVE-2016-41351 PoCUnspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet…
- CVE-2016-41361 PoCUnspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet…
- CVE-2016-41371 PoCUnspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet…
- CVE-2016-41381 PoCUnspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet…
- CVE-2016-41751 PoCAdobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows…
- CVE-2016-41761 PoCAdobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows…
- CVE-2016-41771 PoCAdobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows…
- CVE-2016-41791 PoCAdobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows…
- CVE-2016-42011 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42031 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42041 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42051 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42061 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42071 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42081 PoCAdobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC…
- CVE-2016-42261 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42271 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42281 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42291 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42301 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42311 PoCUse-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and…
- CVE-2016-42321 PoCAdobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632 on Linux allows…
- CVE-2016-42642 PoCsThe Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read…
- CVE-2016-42711 PoCAdobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows…
- CVE-2016-42731 PoCAdobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows…
- CVE-2016-42751 PoCAdobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635 on Linux allows…
- CVE-2016-42891 PoCA stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2.1.19357…
- CVE-2016-42931 PoCMultiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office…
- CVE-2016-42941 PoCWhen opening a Hangul Hcell Document (.cell) and processing a property record within the Workbook stream, Hancom Office 2014 will attempt…
- CVE-2016-42951 PoCWhen opening a Hangul Hcell Document (.cell) and processing a particular record within the Workbook stream, an index miscalculation…
- CVE-2016-42961 PoCWhen opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for…
- CVE-2016-42981 PoCWhen opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will attempt to allocate…
- CVE-2016-43011 PoCStack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote…
- CVE-2016-43031 PoCThe parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of…
- CVE-2016-43041 PoCA denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A…
- CVE-2016-43051 PoCA denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially…
- CVE-2016-43061 PoCMultiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL…
- CVE-2016-43071 PoCA denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially…
- CVE-2016-43092 PoCsSession fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web…
- CVE-2016-43113 PoCsCross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack…
- CVE-2016-43123 PoCsXML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows…
- CVE-2016-43132 PoCsDirectory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a ..…
- CVE-2016-43142 PoCsDirectory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read…
- CVE-2016-43152 PoCsCross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged…
- CVE-2016-43162 PoCsMultiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via…
- CVE-2016-43271 PoCCross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote…
- CVE-2016-43291 PoCA local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software.…
- CVE-2016-43301 PoCIn the HDF5 1.8.16 library's failure to check if the number of dimensions for an array read from the file is within the bounds of the…
- CVE-2016-43311 PoCWhen decoding data out of a dataset encoded with the H5Z_NBIT decoding, the HDF5 1.8.16 library will fail to ensure that the precision is…
- CVE-2016-43321 PoCThe library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an…
- CVE-2016-43331 PoCThe HDF5 1.8.16 library allocating space for the array using a value from the file has an impact within the loop for initializing said…
- CVE-2016-43351 PoCAn exploitable buffer overflow exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted…
- CVE-2016-43361 PoCAn exploitable out-of-bounds write exists in the Bzip2 parsing of the Lexmark Perspective Document Filters conversion functionality. A…
- CVE-2016-43372 PoCsSQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary…
- CVE-2016-43383 PoCsThe mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and…
- CVE-2016-43402 PoCsThe impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0…
- CVE-2016-43431 PoCThe phar_make_dirstream function in ext/phar/dirstream.c in PHP before 5.6.18 and 7.x before 7.0.3 mishandles zero-size ././@LongLink…
- CVE-2016-43441 PoCInteger overflow in the xml_utf8_encode function in ext/xml/xml.c in PHP before 7.0.4 allows remote attackers to cause a denial of service…
- CVE-2016-43451 PoCInteger overflow in the php_filter_encode_url function in ext/filter/sanitizing_filters.c in PHP before 7.0.4 allows remote attackers to…
- CVE-2016-43461 PoCInteger overflow in the str_pad function in ext/standard/string.c in PHP before 7.0.4 allows remote attackers to cause a denial of service…
- CVE-2016-43721 PoCHPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before…
- CVE-2016-44012 PoCsAruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.
- CVE-2016-443711 PoCsKEVApache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute…
- CVE-2016-44382 PoCsThe REST plugin in Apache Struts 2 2.3.19 through 2.3.28.1 allows remote attackers to execute arbitrary code via a crafted expression.
- CVE-2016-44631 PoCStack-based buffer overflow in Apache Xerces-C++ before 3.1.4 allows context-dependent attackers to cause a denial of service via a deeply…
- CVE-2016-44692 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to hijack the…
- CVE-2016-44841 PoCThe Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via…
- CVE-2016-44861 PoCThe rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure,…
- CVE-2016-44871 PoCUse-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a…
- CVE-2016-45341 PoCThe McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows…
- CVE-2016-45351 PoCInteger signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of…
- CVE-2016-45441 PoCThe exif_process_TIFF_in_JPEG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not…
- CVE-2016-45574 PoCsThe replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data…
- CVE-2016-45581 PoCThe BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a denial of service…
- CVE-2016-45662 PoCsCross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote…
- CVE-2016-45671 PoCCross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before…
- CVE-2016-45781 PoCsound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain…
- CVE-2016-46223 PoCsWebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a…
- CVE-2016-46252 PoCsUse-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspecified vectors.
- CVE-2016-46311 PoCImageIO in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to execute…
- CVE-2016-46556 PoCsKEVThe kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
- CVE-2016-46566 PoCsKEVThe kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service…
- CVE-2016-46578 PoCsKEVWebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a…
- CVE-2016-46693 PoCsAn issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is…
- CVE-2016-47932 PoCsThe clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.
- CVE-2016-48062 PoCsWeb2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access…
- CVE-2016-48072 PoCsWeb2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS attack on logged…
- CVE-2016-48082 PoCsWeb2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attacker to trick a…
- CVE-2016-48251 PoCThe Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and…
- CVE-2016-48451 PoCCross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0,…
- CVE-2016-48611 PoCThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL…
- CVE-2016-49716 PoCsGNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
- CVE-2016-49751 PoCmod_userdir CRLF injection
- CVE-2016-49775 PoCsWhen processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the…
- CVE-2016-49973 PoCsThe compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux kernel before…
- CVE-2016-49981 PoCThe IPT_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel before 4.6 allows local users to cause a…