LiveActive security incident?Get immediate response
CVE archive

January 2016

Browse CVE records published in January 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1112 matching CVEs · Page 10 of 23.

Unknown · CVSS Not scored

CVE-2016-6897: Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/...

Cross-site request forgery (CSRF) vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress before 4.6 allows remote attackers to hijack the authentication of subscribers for /dev/random read operations by leveraging a late call to the check_ajax_referer function, a related issue to CVE-2016-6896.

Published Jan 18, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6896: Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.p...

Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPress 4.5.3 allows remote authenticated users to cause a denial of service or read certain text files via a .. (dot dot) in the plugin parameter to wp-admin/admin-ajax.php, as demonstrated by /dev/random read operations that deplete the entropy pool.

Published Jan 18, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6908: Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera...

Characters from languages are such as Arabic, Hebrew are displayed from RTL (Right To Left) order in Opera 37.0.2192.105088 for Android, due to mishandling of several unicode characters such as U+FE70, U+0622, U+0623 etc and how they are rendered combined with (first strong character) such as an IP address or alphabet could lead to a spoofed URL. It was noticed that by placing neutral characters such as "/", "?" in filepath causes the URL to be flipped and displayed from Right To Left. However, in order for the URL to be spoofed the URL must begin with an IP address followed by neutral characters as omnibox considers IP address to be combination of punctuation and numbers and since LTR (Left To Right) direction is not properly enforced, this causes the entire URL to be treated and rendered from RTL (Right To Left). However, it doesn't have be an IP address, what matters is that first strong character (generally, alphabetic character) in the URL must be an RTL character.

Published Jan 26, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6780: An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious applic...

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31251496.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6830: The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding...

The "process-execute" and "process-spawn" procedures in CHICKEN Scheme used fixed-size buffers for holding the arguments and environment variables to use in its execve() call. This would allow user-supplied argument/environment variable lists to trigger a buffer overrun. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).

Published Jan 10, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6768: A remote code execution vulnerability in the Framesequence library could enable an attacker using a special...

A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an application that uses the Framesequence library. Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31631842.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6764: A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file t...

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0. Android ID: A-31681434.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6782: An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application t...

An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31224389. References: MT-ALPS02943506.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6789: An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malici...

An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, which are not normally accessible to a third-party application. Product: Android. Versions: Kernel-3.18. Android ID: A-31251973. References: N-CVE-2016-6789.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6779: An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious applic...

An elevation of privilege vulnerability in the HTC sound codec driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-31386004.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6757: An information disclosure vulnerability in Qualcomm components including the camera driver and video driver...

An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-30148242. References: QC-CR#1052821.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6831: The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call f...

The "process-execute" and "process-spawn" procedures did not free memory correctly when the execve() call failed, resulting in a memory leak. This could be abused by an attacker to cause resource exhaustion or a denial of service. This affects all releases of CHICKEN up to and including 4.11 (it will be fixed in 4.12 and 5.0, which are not yet released).

Published Jan 10, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6776: An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application...

An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10. Android ID: A-31680980. References: N-CVE-2016-6776.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6773: An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious...

An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: 6.0, 6.0.1, 7.0. Android ID: A-30481714.

Published Jan 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6791: An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31252384. References: QC-CR#1071809.

Published Jan 12, 2017 · Updated Aug 6, 2024