CVE-2016-5000 to CVE-2016-5999
73 CVEs with public proof-of-concept exploits.
- CVE-2016-50032 PoCsThe Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a…
- CVE-2016-50051 PoCCross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject…
- CVE-2016-50171 PoCBuffer overflow in the C cli shell in Apache Zookeeper before 3.4.9 and 3.5.x before 3.5.3, when using the "cmd:" batch mode syntax,…
- CVE-2016-50181 PoCIn Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web…
- CVE-2016-50411 PoCdwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging…
- CVE-2016-50633 PoCsThe RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote attackers to bypass…
- CVE-2016-51081 PoCBuffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allows remote…
- CVE-2016-51803 PoCsHeap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of…
- CVE-2016-519599 PoCsKEVRace condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect…
- CVE-2016-52281 PoCStack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba 9.x before 9.3 HF…
- CVE-2016-52372 PoCsValve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to modify the files…
- CVE-2016-52911 PoCA same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird <…
- CVE-2016-52941 PoCThe Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This…
- CVE-2016-52981 PoCA mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when…
- CVE-2016-52991 PoCA previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for…
- CVE-2016-53041 PoCOpen redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote…
- CVE-2016-53091 PoCThe RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email…
- CVE-2016-53101 PoCThe RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email…
- CVE-2016-53122 PoCsDirectory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote authenticated users…
- CVE-2016-53131 PoCSymantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.
- CVE-2016-53142 PoCsBuffer overflow in the PixarLogDecode function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of…
- CVE-2016-53304 PoCsUntrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware…
- CVE-2016-53423 PoCsHeap-based buffer overflow in the wcnss_wlan_write function in drivers/net/wireless/wcnss/wcnss_wlan.c in the wcnss_wlan device driver for…
- CVE-2016-53451 PoCBuffer overflow in the Qualcomm radio driver in Android before 2017-01-05 on Android One devices allows local users to gain privileges via…
- CVE-2016-53461 PoCAn Information Disclosure vulnerability exists in the Google Pixel/Pixel SL Qualcomm Avtimer Driver due to a NULL pointer dereference when…
- CVE-2016-53481 PoCThe GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01…
- CVE-2016-53851 PoCPHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from…
- CVE-2016-53941 PoCIn the XSS Protection API module before 1.0.12 in Apache Sling, the encoding done by the XSSAPI.encodeForJSString() method is not…
- CVE-2016-53994 PoCsThe bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a…
- CVE-2016-54254 PoCsThe Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distributions uses weak…
- CVE-2016-54311 PoCThe PHP JOSE Library by Gree Inc. before version 2.2.1 is vulnerable to key confusion/algorithm substitution in the JWS component…
- CVE-2016-54342 PoCslibalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted…
- CVE-2016-55373 PoCsUnspecified vulnerability in the NetBeans component in Oracle Fusion Middleware 8.1 allows local users to affect confidentiality,…
- CVE-2016-56361 PoCInteger overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2…
- CVE-2016-56392 PoCsDirectory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote…
- CVE-2016-56401 PoCDirectory traversal vulnerability in cgi-bin/rftest.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13 allows remote…
- CVE-2016-56481 PoCAcer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a…
- CVE-2016-56492 PoCsNetgear DGN2200 and DGND3700 disclose the administrator password
- CVE-2016-56744 PoCs__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance…
- CVE-2016-56752 PoCshandle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and…
- CVE-2016-56762 PoCscgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through…
- CVE-2016-56771 PoCNUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a…
- CVE-2016-56781 PoCNUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to…
- CVE-2016-56791 PoCcgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to…
- CVE-2016-56801 PoCStack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows…
- CVE-2016-56821 PoCSwagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
- CVE-2016-56963 PoCsnet/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier…
- CVE-2016-56992 PoCsCRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x…
- CVE-2016-57151 PoCOpen redirect vulnerability in the Console in Puppet Enterprise 2015.x and 2016.x before 2016.4.0 allows remote attackers to redirect…
- CVE-2016-57251 PoCDirectory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP…
- CVE-2016-57346 PoCsphpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the…
- CVE-2016-57401 PoCAn issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical attachments within…
- CVE-2016-57641 PoCMicro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code execution. Fixed in:…
- CVE-2016-57661 PoCInteger overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before…
- CVE-2016-57701 PoCInteger overflow in the SplFileObject::fread function in spl_directory.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23…
- CVE-2016-57711 PoCspl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and…
- CVE-2016-57731 PoCphp_zip.c in the zip extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 improperly interacts with the unserialize…
- CVE-2016-58091 PoCAn issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series,…
- CVE-2016-58101 PoCupAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password…
- CVE-2016-58321 PoCThe customizer in WordPress before 4.5.3 allows remote attackers to bypass intended redirection restrictions via unspecified vectors.
- CVE-2016-58331 PoCCross-site scripting (XSS) vulnerability in the column_title function in wp-admin/includes/class-wp-media-list-table.php in WordPress…
- CVE-2016-58341 PoCCross-site scripting (XSS) vulnerability in the wp_get_attachment_link function in wp-includes/post-template.php in WordPress before 4.5.3…
- CVE-2016-58351 PoCWordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post,…
- CVE-2016-58361 PoCThe oEmbed protocol implementation in WordPress before 4.5.3 allows remote attackers to cause a denial of service via unspecified vectors.
- CVE-2016-58371 PoCWordPress before 4.5.3 allows remote attackers to bypass intended access restrictions and remove a category attribute from a post via…
- CVE-2016-58381 PoCWordPress before 4.5.3 allows remote attackers to bypass intended password-change restrictions by leveraging knowledge of a cookie.
- CVE-2016-58391 PoCWordPress before 4.5.3 allows remote attackers to bypass the sanitize_file_name protection mechanism via unspecified vectors.
- CVE-2016-58401 PoChotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to…
- CVE-2016-58411 PoCInteger overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation…
- CVE-2016-58453 PoCsSAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to cause a denial of…
- CVE-2016-58474 PoCsSAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on…
- CVE-2016-58731 PoCBuffer overflow in the HTTP URL parsing functions in pecl_http before 3.0.1 might allow remote attackers to execute arbitrary code via…
- CVE-2016-59831 PoCIBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty…