LiveActive security incident?Get immediate response
CVE archive

March 2016

Browse CVE records published in March 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 729 matching CVEs · Page 6 of 15.

Unknown · CVSS Not scored

CVE-2016-9122: go-jose before 1.0.4 suffers from multiple signatures exploitation.

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead to confusion. For example, users of the library might mistakenly read protected header values from an attached signature that was different from the one originally validated.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9129: Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy.

Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed by the password recovery system. Such information cannot however be used directly to log in to the system, which requires a username.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9128: Revive Adserver before 3.2.3 suffers from reflected XSS.

Revive Adserver before 3.2.3 suffers from reflected XSS. The affiliate-preview.php script in www/admin is vulnerable to a reflected XSS attack. This vulnerability could be used by an attacker to steal the session ID of an authenticated user, by tricking them into visiting a specifically crafted URL.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9130: Revive Adserver before 3.2.3 suffers from Persistent XSS.

Revive Adserver before 3.2.3 suffers from Persistent XSS. A vector for persistent XSS attacks via the Revive Adserver user interface exists, requiring a trusted (non-admin) account. The website name wasn't properly escaped when displayed in the campaign-zone.php script.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9126: Revive Adserver before 3.2.3 suffers from persistent XSS.

Revive Adserver before 3.2.3 suffers from persistent XSS. Usernames are not properly escaped when displayed in the audit trail widget of the dashboard upon login, allowing persistent XSS attacks. An authenticated user with enough privileges to create other users could exploit the vulnerability to access the administrator account.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9125: Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be...

Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have been an opportunity for an attacker to steal an authenticated session.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9121: go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm.

go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static private key of the receiver, thus making it vulnerable to an invalid curve attack.

Published Mar 28, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9006: IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting.

IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: C1000264.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8935: IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting.

IBM Kenexa LMS on Cloud 13.1, 13.2, 13.2.2, 13.2.3, 13.2.4 and 14.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999483.

Published Mar 31, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8940: IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient author...

IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or use by administrators. The access of these product specific database tables may allow access to passwords or other sensitive information for the product. IBM Reference #: 1998946.

Published Mar 7, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8782: Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak...

Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices repeatedly. Due to improper validation of some specific fields of the packet, the LDP processing module does not release the memory, resulting in memory leak.

Published Mar 9, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8863: Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka...

Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.

Published Mar 7, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8785: Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V20...

Huawei S12700 V200R007C00, V200R008C00, S5700 V200R007C00, S7700 V200R002C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R007C00 have an input validation vulnerability. Due to the lack of input validation, an attacker may craft a malformed packet and send it to the device using VRP, causing the device to display additional memory data and possibly leading to sensitive information leakage.

Published Mar 9, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8784: Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak...

Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacker may send specific Label Distribution Protocol (LDP) packets to the devices. When the values of some parameters in the packet are abnormal, the LDP processing module does not release the memory to handle the packet, resulting in memory leak.

Published Mar 9, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8786: Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V200R008C...

Huawei S12700 V200R005C00, V200R006C00, V200R007C00, V200R008C00, S5700 V200R006C00, V200R007C00, V200R008C00, S6700 V200R008C00, S7700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00, S9700 V200R001C00, V200R002C00, V200R003C00, V200R005C00, V200R006C00, V200R007C00, V200R008C00 have a denial of service (DoS) vulnerability. Due to the lack of input validation, a remote attacker may craft a malformed Resource Reservation Protocol (RSVP) packet and send it to the device, causing a few buffer overflows and occasional device restart.

Published Mar 9, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8783: Touchscreen drive in Huawei H60 (Honor 6) Versions earlier than H60-L02_6.12.16 and P9 Plus Versions earlie...

Touchscreen drive in Huawei H60 (Honor 6) Versions earlier than H60-L02_6.12.16 and P9 Plus Versions earlier than VIE-AL10BC00B356 has a stack overflow vulnerabilities. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to touchscreen drive to crash the system or escalate privilege.

Published Mar 9, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8417: An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious applic...

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process and is mitigated by current platform configurations. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32342399. References: QC-CR#1088824.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8483: An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious applica...

An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Product: Android. Versions: Kernel-3.10. Android ID: A-33745862. References: QC-CR#1035099.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8479: An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious applicati...

An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-31824853. References: QC-CR#1093687.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8477: An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious applic...

An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32720522. References: QC-CR#1090007.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8478: An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious applica...

An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32511270. References: QC-CR#1088206.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8416: An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious applica...

An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-32510746. References: QC-CR#1088206.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8413: An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious applic...

An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32709702. References: QC-CR#518731.

Published Mar 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8232: Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM...

Document Object Model-(DOM) based cross-site scripting vulnerability in the Advanced Management Module (AMM) versions earlier than 66Z of Lenovo IBM BladeCenter HS22, HS22V, HS23, HS23E, HX5 allows an unauthenticated attacker with access to the AMM's IP address to send a crafted URL that could inject a malicious script to access a user's AMM data such as cookies or other session information.

Published Mar 1, 2017 · Updated Aug 6, 2024