Latest CVE Feed
-
4.4
MEDIUMCVE-2016-7397
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.... Read more
Affected Products : unified_threat_management_software- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5700
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile... Read more
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3658
The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3634
The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3633
The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3631
The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the bytecounts[] array variable.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-3625
tif_read.c in the tiff2bw tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted TIFF image.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3624
The cvtClump function in the rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) by setting the "-v" option to -1.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3623
The rgb2ycbcr tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero) by setting the (1) v or (2) h parameter to 0.... Read more
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-3622
The fpAcc function in tif_predict.c in the tiff2rgba tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted TIFF image.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-3621
The LZWEncode function in tif_lzw.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c lzw" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3620
The ZIPEncode function in tif_zip.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c zip" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-3619
The DumpModeEncode function in tif_dumpmode.c in the bmp2tiff tool in LibTIFF 4.0.6 and earlier, when the "-c none" option is used, allows remote attackers to cause a denial of service (buffer over-read) via a crafted BMP image.... Read more
Affected Products : libtiff- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5180
Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot.... Read more
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4436
Apache Struts 2 before 2.3.29 and 2.5.x before 2.5.1 allow attackers to have unspecified impact via vectors related to improper action name clean up.... Read more
Affected Products : struts- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1240
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java pac... Read more
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.3
HIGHCVE-2016-5995
Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local users to gain privileges via a Trojan horse library that is accessed by a setuid or setgid program.... Read more
- Published: Oct. 01, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5986
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16.0.0.3 mishandles responses, which allows remote attackers to obtain sensitive information via unspecified... Read more
Affected Products : websphere_application_server- Published: Oct. 01, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3042
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Application Server (WAS) Liberty before 16.0.0.3 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving OpenID Connect clients.... Read more
Affected Products : websphere_application_server- Published: Oct. 01, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-0617
Unspecified vulnerability in the kernel-uek component in Oracle Linux 6 allows local users to affect availability via unknown vectors.... Read more
- Published: Sep. 30, 2016
- Modified: Apr. 12, 2025