CVE-2016-9000 to CVE-2016-9999
136 CVEs with public proof-of-concept exploits.
- CVE-2016-90171 PoCArtifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive…
- CVE-2016-90181 PoCImproper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and crash in…
- CVE-2016-90361 PoCAn exploitable incorrect return value vulnerability exists in the mp_check function of Tarantool's Msgpuck library 1.0.3. A specially…
- CVE-2016-90371 PoCAn exploitable out-of-bounds array access vulnerability exists in the xrow_header_decode function of Tarantool 1.7.2.0-g8e92715. A…
- CVE-2016-90391 PoCAn exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the…
- CVE-2016-90401 PoCAn exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present…
- CVE-2016-90451 PoCA code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe…
- CVE-2016-90481 PoCMultiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web…
- CVE-2016-90491 PoCAn exploitable denial-of-service vulnerability exists in the fabric-worker component of Aerospike Database Server 3.10.0.3. A specially…
- CVE-2016-90501 PoCAn exploitable out-of-bounds read vulnerability exists in the client message-parsing functionality of Aerospike Database Server 3.10.0.3.…
- CVE-2016-90511 PoCAn exploitable out-of-bounds write vulnerability exists in the batch transaction field parsing functionality of Aerospike Database Server…
- CVE-2016-90521 PoCAn exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A…
- CVE-2016-90531 PoCAn exploitable out-of-bounds indexing vulnerability exists within the RW fabric message particle type of Aerospike Database Server…
- CVE-2016-90541 PoCAn exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A…
- CVE-2016-90611 PoCA previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API…
- CVE-2016-90661 PoCA buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming…
- CVE-2016-90781 PoCRedirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This…
- CVE-2016-90797 PoCsKEVA use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the…
- CVE-2016-90861 PoCGitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9,…
- CVE-2016-90912 PoCsBlue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS…
- CVE-2016-91091 PoCArtifex Software MuJS allows attackers to cause a denial of service (crash) via vectors related to incomplete escape sequences. NOTE: this…
- CVE-2016-91112 PoCsIncorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by…
- CVE-2016-91121 PoCFloating Point Exception (aka FPE or divide by zero) in opj_pi_next_cprl function in openjp2/pi.c:523 in OpenJPEG 2.1.2.
- CVE-2016-91131 PoCThere is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a…
- CVE-2016-91141 PoCThere is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned…
- CVE-2016-91151 PoCHeap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a…
- CVE-2016-91161 PoCNULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a…
- CVE-2016-91171 PoCNULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a…
- CVE-2016-91181 PoCHeap Buffer Overflow (WRITE of size 4) in function pnmtoimage of convert.c:1719 in OpenJPEG 2.1.2.
- CVE-2016-91371 PoCUse-after-free vulnerability in the CURLFile implementation in ext/curl/curl_file.c in PHP before 5.6.27 and 7.x before 7.0.12 allows…
- CVE-2016-91501 PoCBuffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15,…
- CVE-2016-91512 PoCsPalo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x before 6.0.15, 6.1.x before 6.1.15, 7.0.x before 7.0.11, and 7.1.x…
- CVE-2016-91761 PoCStack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or…
- CVE-2016-91771 PoCDirectory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
- CVE-2016-91861 PoCUnrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated…
- CVE-2016-91871 PoCUnrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated…
- CVE-2016-91881 PoCCross-site scripting (XSS) vulnerabilities in Moodle CMS on or before 3.1.2 allow remote attackers to inject arbitrary web script or HTML…
- CVE-2016-91921 PoCA vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute…
- CVE-2016-92443 PoCsA BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may leak up to 31…
- CVE-2016-92631 PoCWordPress through 4.8.2, when domain-based flashmediaelement.swf sandboxing is not used, allows remote attackers to conduct cross-domain…
- CVE-2016-92691 PoCRemote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appliance (IWSVA)…
- CVE-2016-92941 PoCArtifex Software, Inc. MuJS before 5008105780c0b0182ea6eda83ad5598f225be3ee allows context-dependent attackers to conduct "denial of…
- CVE-2016-92961 PoCA null pointer dereference bug affects the 16.02 and many old versions of p7zip. A lack of null pointer check for the variable…
- CVE-2016-92994 PoCsThe remoting module in Jenkins before 2.32 and LTS before 2.19.3 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2016-93111 PoCntpd in NTP before 4.2.8p9, when the trap service is enabled, allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2016-93131 PoCsecurity/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful…
- CVE-2016-93141 PoCSensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance…
- CVE-2016-93151 PoCPrivilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan Web Security Virtual…
- CVE-2016-93161 PoCMultiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro…
- CVE-2016-93181 PoClibxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the…
- CVE-2016-93321 PoCAn issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An…
- CVE-2016-93492 PoCsAn issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files…
- CVE-2016-93511 PoCAn issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error allows an attacker…
- CVE-2016-93612 PoCsAn issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions…
- CVE-2016-94451 PoCInteger overflow in the vmnc decoder in the gstreamer allows remote attackers to cause a denial of service (crash) via large width and…
- CVE-2016-94461 PoCThe vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as…
- CVE-2016-94471 PoCThe ROM mappings in the NSF decoder in gstreamer 0.10.x allow remote attackers to cause a denial of service (out-of-bounds read or write)…
- CVE-2016-94591 PoCNextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution vulnerability potentially leading to a…
- CVE-2016-94601 PoCNextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location…
- CVE-2016-94611 PoCNextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions.…
- CVE-2016-94621 PoCNextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The…
- CVE-2016-94632 PoCsNextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass.…
- CVE-2016-94641 PoCNextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as…
- CVE-2016-94651 PoCNextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Stored XSS in CardDAV image export. The CardDAV image…
- CVE-2016-94661 PoCNextcloud Server before 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from Reflected XSS in the Gallery application. The gallery…
- CVE-2016-94671 PoCNextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The…
- CVE-2016-94681 PoCNextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The…
- CVE-2016-94692 PoCsMultiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and…
- CVE-2016-94732 PoCsBrave Browser iOS before 1.2.18 and Brave Browser Android 1.9.56 and earlier suffer from Full Address Bar Spoofing, allowing attackers to…
- CVE-2016-94881 PoCManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
- CVE-2016-95531 PoCThe Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative…
- CVE-2016-95541 PoCThe Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in…
- CVE-2016-95581 PoC(1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact…
- CVE-2016-95603 PoCsStack-based buffer overflow in the jpc_tsfb_getbands2 function in jpc_tsfb.c in JasPer before 1.900.30 allows remote attackers to have…
- CVE-2016-95653 PoCsMagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files…
- CVE-2016-95662 PoCsbase/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a…
- CVE-2016-95681 PoCA security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions.
- CVE-2016-95721 PoCA NULL pointer dereference flaw was found in the way openjpeg 2.1.2 decoded certain input images. Due to a logic error in the code…
- CVE-2016-95731 PoCAn out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to…
- CVE-2016-95801 PoCAn integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.
- CVE-2016-95811 PoCAn infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.
- CVE-2016-95871 PoCAnsible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent from client systems.…
- CVE-2016-95911 PoCJasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on…
- CVE-2016-96341 PoCHeap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2…
- CVE-2016-96351 PoCHeap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2…
- CVE-2016-96361 PoCHeap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2…
- CVE-2016-96512 PoCsA missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to…
- CVE-2016-96821 PoCThe SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web…
- CVE-2016-96831 PoCThe SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web…
- CVE-2016-96841 PoCThe SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web…
- CVE-2016-97222 PoCsIBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by…
- CVE-2016-97933 PoCsThe sock_setsockopt function in net/core/sock.c in the Linux kernel before 4.8.14 mishandles negative values of sk_sndbuf and sk_rcvbuf,…
- CVE-2016-97951 PoCThe casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems…
- CVE-2016-97962 PoCsAlcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP protocol on TCP port…
- CVE-2016-97971 PoCIn BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered…
- CVE-2016-97981 PoCIn BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered…
- CVE-2016-97991 PoCIn BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by…
- CVE-2016-98001 PoCIn BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists…
- CVE-2016-98011 PoCIn BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted…
- CVE-2016-98021 PoCIn BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered…
- CVE-2016-98031 PoCIn BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists…
- CVE-2016-98041 PoCIn BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because…
- CVE-2016-98081 PoCThe FLIC decoder in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a…
- CVE-2016-98131 PoCThe _parse_pat function in the mpegts parser in GStreamer before 1.10.2 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2016-98191 PoClibavcodec/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a…
- CVE-2016-98201 PoClibavcodec/mpegvideo_motion.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift…
- CVE-2016-98211 PoCInteger overflow in libavcodec/mpegvideo_parser.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted…
- CVE-2016-98221 PoCInteger overflow in libavcodec/mpeg12dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
- CVE-2016-98231 PoClibavcodec/x86/mpegvideo.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
- CVE-2016-98241 PoCInteger overflow in libswscale/x86/swscale.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via a crafted file.
- CVE-2016-98251 PoClibswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a…
- CVE-2016-98261 PoClibavcodec/ituh263dec.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a…
- CVE-2016-98272 PoCsThe _iprintf function in outputtxt.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (buffer…
- CVE-2016-98282 PoCsThe dumpBuffer function in read.c in the listswf tool in libming 0.4.7 allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2016-98292 PoCsHeap-based buffer overflow in the parseSWF_DEFINEFONT function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to…
- CVE-2016-98312 PoCsHeap-based buffer overflow in the parseSWF_RGBA function in parser.c in the listswf tool in libming 0.4.7 allows remote attackers to have…
- CVE-2016-98321 PoCPricewaterhouseCoopers (PwC) ACE-ABAP 8.10.304 for SAP Security allows remote authenticated users to conduct ABAP injection attacks and…
- CVE-2016-98341 PoCAn XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam…
- CVE-2016-98361 PoCThe file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions…
- CVE-2016-98382 PoCsAn issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form…
- CVE-2016-98921 PoCThe esets_daemon service in ESET Endpoint Antivirus for macOS before 6.4.168.0 and Endpoint Security for macOS before 6.4.168.0 does not…
- CVE-2016-98992 PoCsUse-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This…
- CVE-2016-99001 PoCExternal resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This…
- CVE-2016-99021 PoCThe Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events.…
- CVE-2016-99171 PoCIn BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by…
- CVE-2016-99181 PoCIn BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be…
- CVE-2016-99202 PoCssteps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is…
- CVE-2016-99361 PoCThe unserialize implementation in ext/standard/var.c in PHP 7.x before 7.0.14 allows remote attackers to cause a denial of service…
- CVE-2016-99492 PoCsAn issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python…
- CVE-2016-99502 PoCsAn issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and "SourcePackage"…
- CVE-2016-99512 PoCsAn issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or…
- CVE-2016-99571 PoCStack-based buffer overflow in game-music-emu before 0.6.1.
- CVE-2016-99581 PoCgame-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
- CVE-2016-99591 PoCgame-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
- CVE-2016-99601 PoCgame-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
- CVE-2016-99611 PoCgame-music-emu before 0.6.1 mishandles unspecified integer values.