CVE-2016-8000 to CVE-2016-8999
90 CVEs with public proof-of-concept exploits.
- CVE-2016-80071 PoCAuthentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users…
- CVE-2016-80161 PoCInformation exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to…
- CVE-2016-80171 PoCSpecial element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated…
- CVE-2016-80181 PoCCross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows…
- CVE-2016-80191 PoCCross-site scripting (XSS) vulnerability in attributes in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows…
- CVE-2016-80201 PoCImproper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote…
- CVE-2016-80211 PoCImproper verification of cryptographic signature vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)…
- CVE-2016-80221 PoCAuthentication bypass by spoofing vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote…
- CVE-2016-80231 PoCAuthentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)…
- CVE-2016-80241 PoCImproper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and…
- CVE-2016-80251 PoCSQL injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to…
- CVE-2016-83661 PoCWebvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI…
- CVE-2016-83711 PoCThe web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.
- CVE-2016-83771 PoCAn issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vulnerability exists…
- CVE-2016-83801 PoCThe web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.
- CVE-2016-83851 PoCAn exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus. When it attempts…
- CVE-2016-83861 PoCAn exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a PDF containing a malformed font to XML, the…
- CVE-2016-83881 PoCAn exploitable arbitrary heap-overwrite vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it…
- CVE-2016-83891 PoCAn exploitable integer-overflow vulnerability exists within Iceni Argus. When it attempts to convert a malformed PDF to XML, it will…
- CVE-2016-84621 PoCAn information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level.…
- CVE-2016-85231 PoCA Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
- CVE-2016-85261 PoCAruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML…
- CVE-2016-85272 PoCsAruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is…
- CVE-2016-85802 PoCsPHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow…
- CVE-2016-85812 PoCsA persistent XSS vulnerability exists in the User-Agent header of the login process of AlienVault OSSIM and USM before 5.3.2 that allows…
- CVE-2016-85822 PoCsA vulnerability exists in gauge.php of AlienVault OSSIM and USM before 5.3.2 that allows an attacker to execute an arbitrary SQL query and…
- CVE-2016-85841 PoCTrend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass…
- CVE-2016-85852 PoCsadmin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary…
- CVE-2016-85861 PoCdetected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute…
- CVE-2016-85871 PoCdlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute…
- CVE-2016-85881 PoCThe hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute…
- CVE-2016-85891 PoClog_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary…
- CVE-2016-85901 PoClog_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary…
- CVE-2016-85911 PoClog_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code…
- CVE-2016-85921 PoClog_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute…
- CVE-2016-85931 PoCDirectory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote…
- CVE-2016-86002 PoCsIn dotCMS 3.2.1, attacker can load captcha once, fill it with correct value and then this correct value is ok for forms with captcha check…
- CVE-2016-86101 PoCA denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined…
- CVE-2016-86411 PoCA privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary files and insecurely…
- CVE-2016-86541 PoCA heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper…
- CVE-2016-865515 PoCsRace condition in net/packet/af_packet.c in the Linux kernel through 4.8.12 allows local users to gain privileges or cause a denial of…
- CVE-2016-87041 PoCAn integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of…
- CVE-2016-87051 PoCMultiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached…
- CVE-2016-87062 PoCsAn integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary…
- CVE-2016-87121 PoCAn exploitable nonce reuse vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless AP running firmware 1.1.…
- CVE-2016-87141 PoCAn exploitable buffer overflow vulnerability exists in the LoadEncoding functionality of the R programming language version 3.3.0. A…
- CVE-2016-87181 PoCAn exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access…
- CVE-2016-87191 PoCAn exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access…
- CVE-2016-87201 PoCAn exploitable HTTP Header Injection vulnerability exists in the Web Application functionality of the Moxa AWK-3131A Wireless Access Point…
- CVE-2016-87211 PoCAn exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access…
- CVE-2016-87221 PoCAn exploitable Information Disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Series Industrial IEEE…
- CVE-2016-87231 PoCAn exploitable null pointer dereference exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running…
- CVE-2016-87241 PoCAn exploitable information disclosure vulnerability exists in the serviceAgent functionality of Moxa AWK-3131A Wireless Access Point…
- CVE-2016-87251 PoCAn exploitable information disclosure vulnerability exists in the Web Application functionality of the Moxa AWK-3131A wireless access…
- CVE-2016-87261 PoCAn exploitable null pointer dereference vulnerability exists in the Web Application /forms/web_runScript iw_filename functionality of Moxa…
- CVE-2016-87271 PoCAn exploitable information disclosure vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point.…
- CVE-2016-87321 PoCMultiple security flaws exists in InvProtectDrv.sys which is a part of Invincea Dell Protected Workspace 5.1.1-22303. Weak restrictions on…
- CVE-2016-87356 PoCsKEVRemote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x…
- CVE-2016-87402 PoCsThe mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not…
- CVE-2016-87421 PoCThe Windows installer that the Apache CouchDB team provides was vulnerable to local privilege escalation. All files in the install inherit…
- CVE-2016-87441 PoCApache Brooklyn uses the SnakeYAML library for parsing YAML inputs. SnakeYAML allows the use of YAML tags to indicate that SnakeYAML…
- CVE-2016-87691 PoCHuawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS…
- CVE-2016-87762 PoCsHuawei P9 phones with software EVA-AL10C00,EVA-CL10C00,EVA-DL10C00,EVA-TL10C00 and P9 Lite phones with software VNS-L21C185 allow…
- CVE-2016-88051 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88061 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88071 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88081 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88091 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88101 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88111 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a…
- CVE-2016-88121 PoCFor the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before GFE 3.1.0.52…
- CVE-2016-88231 PoCAll versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where the size…
- CVE-2016-88552 PoCsCross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience Platform 8.1 rev.…
- CVE-2016-88581 PoCThe kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory…
- CVE-2016-88631 PoCHeap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows…
- CVE-2016-88661 PoCThe AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified…
- CVE-2016-88696 PoCsThe register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4 allows…
- CVE-2016-88706 PoCsThe register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when…
- CVE-2016-88971 PoCExponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.
- CVE-2016-88981 PoCExponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.
- CVE-2016-88991 PoCExponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php…
- CVE-2016-89001 PoCExponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php…
- CVE-2016-89021 PoCSQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute…
- CVE-2016-89032 PoCsSQL injection vulnerability in the "Site Browser > Templates pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to…
- CVE-2016-89042 PoCsSQL injection vulnerability in the "Site Browser > Containers pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers…
- CVE-2016-89052 PoCsSQL injection vulnerability in the JSONTags servlet in dotCMS before 3.3.1 allows remote authenticated attackers to execute arbitrary SQL…
- CVE-2016-89062 PoCsSQL injection vulnerability in the "Site Browser > Links pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to…
- CVE-2016-89072 PoCsSQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.3.1 allows remote authenticated attackers to…
- CVE-2016-89082 PoCsSQL injection vulnerability in the "Site Browser > HTML pages" screen in dotCMS before 3.3.1 allows remote authenticated attackers to…
- CVE-2016-89721 PoCIBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client.…