CVE-2016-7000 to CVE-2016-7999
103 CVEs with public proof-of-concept exploits.
- CVE-2016-70441 PoCThe unformat_24bit_color function in the format parsing code in Irssi before 0.8.20, when compiled with true-color enabled, allows remote…
- CVE-2016-70451 PoCThe format_send_to_gui function in the format parsing code in Irssi before 0.8.20 allows remote attackers to cause a denial of service…
- CVE-2016-70541 PoCChaCha20/Poly1305 heap-buffer-overflow
- CVE-2016-70631 PoCA flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.
- CVE-2016-70652 PoCsThe JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to cause a denial of…
- CVE-2016-70671 PoCMonit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to…
- CVE-2016-70831 PoCVMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado ThinPrint virtual…
- CVE-2016-70841 PoCtpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado…
- CVE-2016-70893 PoCsWatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka…
- CVE-2016-70983 PoCsRace condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to…
- CVE-2016-71241 PoCext/standard/var_unserializer.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles certain invalid objects, which allows remote…
- CVE-2016-71251 PoCext/session/session.c in PHP before 5.6.25 and 7.x before 7.0.10 skips invalid session names in a way that triggers incorrect parsing,…
- CVE-2016-71261 PoCThe imagetruecolortopalette function in ext/gd/gd.c in PHP before 5.6.25 and 7.x before 7.0.10 does not properly validate the number of…
- CVE-2016-71331 PoCZend/zend_alloc.c in PHP 7.x before 7.0.10, when open_basedir is enabled, mishandles huge realloc operations, which allows remote…
- CVE-2016-71351 PoCDirectory traversal vulnerability in Plone CMS 5.x through 5.0.6 and 4.2.x through 4.3.11 allows remote administrators to read arbitrary…
- CVE-2016-71361 PoCz3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a…
- CVE-2016-71371 PoCMultiple open redirect vulnerabilities in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers…
- CVE-2016-71381 PoCCross-site scripting (XSS) vulnerability in the URL checking infrastructure in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x…
- CVE-2016-71391 PoCCross-site scripting (XSS) vulnerability in an unspecified page template in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x…
- CVE-2016-71401 PoCMultiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x…
- CVE-2016-71441 PoCThe m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof…
- CVE-2016-71461 PoCMoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach,…
- CVE-2016-71481 PoCMoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a…
- CVE-2016-71631 PoCInteger overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted…
- CVE-2016-71681 PoCCross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1…
- CVE-2016-71691 PoCDirectory traversal vulnerability in the File_Upload_Upgrader class in wp-admin/includes/class-file-upload-upgrader.php in the upgrade…
- CVE-2016-71821 PoCThe Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012…
- CVE-2016-71851 PoCThe kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server…
- CVE-2016-71881 PoCThe Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles library loading, which…
- CVE-2016-71891 PoCThe Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting…
- CVE-2016-71902 PoCsThe Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory…
- CVE-2016-71941 PoCThe Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory…
- CVE-2016-72003 PoCsKEVThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2016-72013 PoCsKEVThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2016-72022 PoCsThe scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or…
- CVE-2016-72031 PoCThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2016-72161 PoCThe kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissions, which allows…
- CVE-2016-72241 PoCVirtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and…
- CVE-2016-72251 PoCVirtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which…
- CVE-2016-72261 PoCVirtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which…
- CVE-2016-72371 PoCLocal Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1,…
- CVE-2016-72401 PoCThe Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2016-72412 PoCsMicrosoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory…
- CVE-2016-725512 PoCsKEVThe kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server…
- CVE-2016-72741 PoCUniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,…
- CVE-2016-72861 PoCThe scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
- CVE-2016-72871 PoCThe scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a…
- CVE-2016-72881 PoCThe scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…
- CVE-2016-73841 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73851 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73861 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73871 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73901 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73911 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-73982 PoCsA type confusion vulnerability in the merge_param() function of php_http_params.c in PHP's pecl-http extension 3.1.0beta2 (PHP 7) and…
- CVE-2016-74001 PoCMultiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2016-74101 PoCThe _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read)…
- CVE-2016-74111 PoCext/standard/var_unserializer.re in PHP before 5.6.26 mishandles object-deserialization failures, which allows remote attackers to cause a…
- CVE-2016-74151 PoCStack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++…
- CVE-2016-74161 PoCext/intl/msgformat/msgformat_format.c in PHP before 5.6.26 and 7.x before 7.0.11 does not properly restrict the locale length provided to…
- CVE-2016-74181 PoCThe php_wddx_push_element function in ext/wddx/wddx.c in PHP before 5.6.26 and 7.x before 7.0.11 allows remote attackers to cause a denial…
- CVE-2016-74191 PoCCross-site scripting (XSS) vulnerability in share.js in the gallery application in ownCloud Server before 9.0.4 and Nextcloud Server…
- CVE-2016-74344 PoCsThe read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.
- CVE-2016-74451 PoCconvert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)…
- CVE-2016-74542 PoCsCSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST…
- CVE-2016-74561 PoCVMware vSphere Data Protection (VDP) 5.5.x though 6.1.x has an SSH private key with a publicly known password, which makes it easier for…
- CVE-2016-74781 PoCZend/zend_exceptions.c in PHP, possibly 5.x before 5.6.28 and 7.x before 7.0.13, allows remote attackers to cause a denial of service…
- CVE-2016-75041 PoCA use-after-free vulnerability was observed in Rp_toString function of Artifex Software, Inc. MuJS before…
- CVE-2016-75051 PoCA buffer overflow vulnerability was observed in divby function of Artifex Software, Inc. MuJS before…
- CVE-2016-75061 PoCAn out-of-bounds read vulnerability was observed in Sp_replace_regexp function of Artifex Software, Inc. MuJS before…
- CVE-2016-75081 PoCMultiple SQL injection vulnerabilities in GLPI 0.90.4 allow an authenticated remote attacker to execute arbitrary SQL commands by using a…
- CVE-2016-75471 PoCA command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the…
- CVE-2016-75522 PoCsOn the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote,…
- CVE-2016-75631 PoCThe chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at…
- CVE-2016-75641 PoCHeap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of…
- CVE-2016-75671 PoCBuffer overflow in the SLPFoldWhiteSpace function in common/slp_compare.c in OpenSLP 2.0 allows remote attackers to have unspecified…
- CVE-2016-75691 PoCDirectory traversal vulnerability in docker2aci before 0.13.0 allows remote attackers to write to arbitrary files via a .. (dot dot) in…
- CVE-2016-76082 PoCsAn issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "IOFireWireFamily" component,…
- CVE-2016-76121 PoCAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is…
- CVE-2016-76173 PoCsAn issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth" component. It…
- CVE-2016-76211 PoCAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is…
- CVE-2016-76261 PoCAn issue was discovered in certain Apple products. iOS before 10.2 is affected. tvOS before 10.1 is affected. watchOS before 3.1.1 is…
- CVE-2016-76331 PoCAn issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory Services"…
- CVE-2016-76373 PoCsAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is…
- CVE-2016-76441 PoCAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is…
- CVE-2016-76601 PoCAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is…
- CVE-2016-76612 PoCsAn issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the…
- CVE-2016-77861 PoCSophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object…
- CVE-2016-77901 PoCExponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the…
- CVE-2016-77911 PoCExponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil…
- CVE-2016-77921 PoCUbiquiti Networks UniFi 5.2.7 does not restrict access to the database, which allows remote attackers to modify the database by directly…
- CVE-2016-77951 PoCThe manager_invoke_notify_message function in systemd 231 and earlier allows local users to cause a denial of service (assertion failure…
- CVE-2016-77961 PoCThe manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message…
- CVE-2016-77981 PoCThe openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes…
- CVE-2016-78341 PoCSONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520,…
- CVE-2016-78511 PoCAdobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulnerability could be…
- CVE-2016-78661 PoCAdobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to…
- CVE-2016-79191 PoCMoodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting…
- CVE-2016-79761 PoCThe PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.
- CVE-2016-79801 PoCCross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack…
- CVE-2016-79811 PoCCross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web…
- CVE-2016-79821 PoCDirectory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files…
- CVE-2016-79981 PoCThe SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading…