CVE-2016-6000 to CVE-2016-6999
86 CVEs with public proof-of-concept exploits.
- CVE-2016-60791 PoCIBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level…
- CVE-2016-61421 PoCSAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors…
- CVE-2016-61671 PoCMultiple untrusted search path vulnerabilities in Putty beta 0.67 allow local users to execute arbitrary code and conduct DLL hijacking…
- CVE-2016-61741 PoCapplications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Board, IPB, or Power…
- CVE-2016-61751 PoCEval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural…
- CVE-2016-61851 PoCThe XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local…
- CVE-2016-61861 PoCCross-site scripting (XSS) vulnerability in the dismissChangeRelatedObjectPopup function in…
- CVE-2016-61873 PoCsThe apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buffer size, which…
- CVE-2016-61954 PoCsSQL injection vulnerability in forumrunner/includes/moderation.php in vBulletin before 4.2.2 Patch Level 5 and 4.2.3 before Patch Level 1…
- CVE-2016-61991 PoCObjectSocketWrapper.java in Gradle 2.12 allows remote attackers to execute arbitrary code via a crafted serialized object.
- CVE-2016-62011 PoCCross-site scripting (XSS) vulnerability in Ektron Content Management System (CMS) before 9.1.0.184 SP3 (9.1.0.184.3.127) allows remote…
- CVE-2016-621011 PoCssshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the…
- CVE-2016-62321 PoCDirectory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files…
- CVE-2016-62535 PoCsmail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or append data to…
- CVE-2016-62552 PoCsPortable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request…
- CVE-2016-62562 PoCsSAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request…
- CVE-2016-62661 PoCccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows…
- CVE-2016-62672 PoCsSnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote…
- CVE-2016-62681 PoCTrend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to…
- CVE-2016-62691 PoCMultiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0…
- CVE-2016-62701 PoCThe handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure…
- CVE-2016-62711 PoCThe Bzrtp library (aka libbzrtp) 1.0.x before 1.0.4 allows man-in-the-middle attackers to conduct spoofing attacks by leveraging a missing…
- CVE-2016-62722 PoCsXPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display…
- CVE-2016-62776 PoCsKEVNETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.Beta, R7100LG…
- CVE-2016-62831 PoCCross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitrary web script or…
- CVE-2016-62851 PoCCross-site scripting (XSS) vulnerability in includes/decorators/global-translations.jsp in Atlassian JIRA before 7.2.2 allows remote…
- CVE-2016-62891 PoCInteger overflow in the virtual_file_ex function in TSRM/tsrm_virtual_cwd.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before…
- CVE-2016-62951 PoCext/snmp/snmp.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 improperly interacts with the unserialize implementation…
- CVE-2016-62961 PoCInteger signedness error in the simplestring_addn function in simplestring.c in xmlrpc-epi through 0.54.2, as used in PHP before 5.5.38,…
- CVE-2016-63041 PoCMultiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a…
- CVE-2016-63171 PoCAction Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record…
- CVE-2016-63211 PoCDirectory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an…
- CVE-2016-63281 PoCA vulnerability was found in libexif. An integer overflow when parsing the MNOTE entry data of the input file. This can cause…
- CVE-2016-63502 PoCsOpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path…
- CVE-2016-63667 PoCsKEVBuffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA…
- CVE-2016-63672 PoCsKEVCisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain…
- CVE-2016-64152 PoCsKEVThe server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through…
- CVE-2016-64333 PoCsThe Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users to execute…
- CVE-2016-64341 PoCCisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive information by…
- CVE-2016-64352 PoCsThe web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted…
- CVE-2016-64832 PoCsThe media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Level 1, 4.x before…
- CVE-2016-64912 PoCsBuffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows…
- CVE-2016-64921 PoCThe MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted…
- CVE-2016-65031 PoCThe CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler…
- CVE-2016-65041 PoCepan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data…
- CVE-2016-65051 PoCepan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allows remote…
- CVE-2016-65121 PoCepan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote…
- CVE-2016-65154 PoCsThe auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication,…
- CVE-2016-65161 PoCRace condition in the ioctl_file_dedupe_range function in fs/ioctl.c in the Linux kernel through 4.7 allows local users to cause a denial…
- CVE-2016-65211 PoCCross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and…
- CVE-2016-65633 PoCsD-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
- CVE-2016-65641 PoCRagentek Android software contains an over-the-air update mechanism that communicates over an unencrypted channel, which can allow a…
- CVE-2016-65661 PoCThe Sungard eTRAKiT3 software version 3.2.1.17 may be vulnerable to SQL injection which may allow a remote unauthenticated attacker to run…
- CVE-2016-65931 PoCA code-execution vulnerability exists during startup in jhi.dll and otpiha.dll in Symantec VIP Access Desktop before 2.2.2, which could…
- CVE-2016-65984 PoCsBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This…
- CVE-2016-65994 PoCsBMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010.…
- CVE-2016-66004 PoCsDirectory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to…
- CVE-2016-66015 PoCsDirectory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to…
- CVE-2016-66023 PoCsZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to…
- CVE-2016-66034 PoCsZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName…
- CVE-2016-66341 PoCCross-site scripting (XSS) vulnerability in the network settings page in WordPress before 4.5 allows remote attackers to inject arbitrary…
- CVE-2016-66351 PoCCross-site request forgery (CSRF) vulnerability in the wp_ajax_wp_compression_test function in wp-admin/includes/ajax-actions.php in…
- CVE-2016-66521 PoCSQL injection vulnerability in Pivotal Spring Data JPA before 1.9.6 (Gosling SR6) and 1.10.x before 1.10.4 (Hopper SR4), when used with a…
- CVE-2016-66626 PoCsOracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x…
- CVE-2016-66635 PoCsRace condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52,…
- CVE-2016-66645 PoCsmysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2,…
- CVE-2016-66891 PoCBinder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted…
- CVE-2016-67071 PoCAn elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local…
- CVE-2016-67542 PoCsA remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable…
- CVE-2016-67721 PoCAn elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context…
- CVE-2016-67981 PoCIn the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the…
- CVE-2016-68011 PoCCross-site request forgery (CSRF) vulnerability in the CSRF content-type check in Jackrabbit-Webdav in Apache Jackrabbit 2.4.x before…
- CVE-2016-68081 PoCBuffer overflow in Apache Tomcat Connectors (mod_jk) before 1.2.42.
- CVE-2016-68121 PoCThe HTTP transport module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 uses FormattedServiceListWriter to provide an HTML page…
- CVE-2016-68161 PoCThe code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the…
- CVE-2016-68281 PoCThe tcp_check_send_head function in include/net/tcp.h in the Linux kernel before 4.7.5 does not properly maintain certain SACK state after…
- CVE-2016-68401 PoCCross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote…
- CVE-2016-68512 PoCsAn issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX Guard guest reader…
- CVE-2016-68532 PoCsAn issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can be injected to the…
- CVE-2016-68542 PoCsAn issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline PGP signature…
- CVE-2016-68552 PoCsEye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow…
- CVE-2016-68963 PoCsDirectory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows…
- CVE-2016-68973 PoCsCross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress…
- CVE-2016-69092 PoCsBuffer overflow in the Cookie parser in Fortinet FortiOS 4.x before 4.1.11, 4.2.x before 4.2.13, and 4.3.x before 4.3.9 and FortiSwitch…
- CVE-2016-69131 PoCCross-site scripting (XSS) vulnerability in AlienVault OSSIM before 5.3 and USM before 5.3 allows remote attackers to inject arbitrary web…
- CVE-2016-69142 PoCsUbiquiti UniFi Video before 3.8.0 for Windows uses weak permissions for the installation directory, which allows local users to gain…