Latest CVE Feed
-
9.8
CRITICALCVE-2016-10045
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping ... Read more
- EPSS Score: %93.56
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execut... Read more
- EPSS Score: %82.32
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.... Read more
- Actively Exploited
- EPSS Score: %94.36
- Published: Dec. 30, 2016
- Modified: Jul. 08, 2025
-
7.0
HIGHCVE-2016-10088
The sg implementation in the Linux kernel through 4.9 does not properly restrict write operations in situations where the KERNEL_DS option is set, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service ... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-10085
admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.... Read more
Affected Products : piwigo- EPSS Score: %2.05
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-10084
admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).... Read more
Affected Products : piwigo- EPSS Score: %2.05
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-10083
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.... Read more
Affected Products : piwigo- EPSS Score: %0.34
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-10082
include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() ... Read more
Affected Products : serendipity- EPSS Score: %1.53
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9916
Memory leak in hw/9pfs/9p-proxy.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the proxy backend.... Read more
- EPSS Score: %0.07
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9915
Memory leak in hw/9pfs/9p-handle.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in the handle backend.... Read more
- EPSS Score: %0.07
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9914
Memory leak in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) by leveraging a missing cleanup operation in FileOperations.... Read more
- EPSS Score: %0.07
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9913
Memory leak in the v9fs_device_unrealize_common function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local privileged guest OS users to cause a denial of service (host memory consumption and possibly QEMU process crash) via vectors involving the o... Read more
Affected Products : qemu- EPSS Score: %0.07
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9846
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to a memory leakage issue. It could occur while updating the cursor data in update_cursor_data_virgl. A guest user/process could use this flaw to leak host memory by... Read more
Affected Products : qemu- EPSS Score: %0.08
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9845
QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while processing 'VIRTIO_GPU_CMD_GET_CAPSET_INFO' command. A guest user/process could use this flaw to leak contents ... Read more
Affected Products : qemu- EPSS Score: %0.10
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-9776
QEMU (aka Quick Emulator) built with the ColdFire Fast Ethernet Controller emulator support is vulnerable to an infinite loop issue. It could occur while receiving packets in 'mcf_fec_receive'. A privileged user/process inside guest could use this issue t... Read more
- EPSS Score: %0.10
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2198
QEMU (aka Quick Emulator) built with the USB EHCI emulation support is vulnerable to a null pointer dereference flaw. It could occur when an application attempts to write to EHCI capabilities registers. A privileged user inside quest could use this flaw t... Read more
- EPSS Score: %0.10
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2197
QEMU (aka Quick Emulator) built with an IDE AHCI emulation support is vulnerable to a null pointer dereference flaw. It occurs while unmapping the Frame Information Structure (FIS) and Command List Block (CLB) entries. A privileged user inside guest could... Read more
Affected Products : qemu- EPSS Score: %0.11
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1981
QEMU (aka Quick Emulator) built with the e1000 NIC emulation support is vulnerable to an infinite loop issue. It could occur while processing data via transmit or receive descriptors, provided the initial receive/transmit descriptor head (TDH/RDH) is set ... Read more
- EPSS Score: %0.06
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1922
QEMU (aka Quick Emulator) built with the TPR optimization for 32-bit Windows guests support is vulnerable to a null pointer dereference flaw. It occurs while doing I/O port write operations via hmp interface. In that, 'current_cpu' remains null, which lea... Read more
- EPSS Score: %0.08
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-8818
The cpu_physical_memory_write_rom_internal function in exec.c in QEMU (aka Quick Emulator) does not properly skip MMIO regions, which allows local privileged guest users to cause a denial of service (guest crash) via unspecified vectors.... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Dec. 29, 2016
- Modified: Apr. 12, 2025