LiveActive security incident?Get immediate response
CVE archive

May 2016

Browse CVE records published in May 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 764 matching CVEs · Page 4 of 16.

Unknown · CVSS Not scored

CVE-2016-10292: A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a...

A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-34514463. References: QC-CR#1065466.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10277: An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious applicati...

An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33840490.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10282: An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious appli...

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-33939045. References: M-ALPS03149189.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10276: An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious applicati...

An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: N/A. Android ID: A-32952839. References: QC-CR#1094105.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10281: An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious appli...

An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175647. References: M-ALPS02696475.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10289: An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious applic...

An elevation of privilege vulnerability in the Qualcomm crypto driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33899710. References: QC-CR#1116295.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10296: An information disclosure vulnerability in the Qualcomm shared memory driver could enable a local malicious...

An information disclosure vulnerability in the Qualcomm shared memory driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-33845464. References: QC-CR#1109782.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10295: An information disclosure vulnerability in the Qualcomm LED driver could enable a local malicious applicati...

An information disclosure vulnerability in the Qualcomm LED driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.18. Android ID: A-33781694. References: QC-CR#1109326.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10284: An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious applica...

An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10, Kernel-3.18. Android ID: A-32402303. References: QC-CR#2000664.

Published May 12, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10036: Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote...

Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to (1) deploy an arbitrary servlet application and execute arbitrary code by uploading a war file or (2) possibly write to arbitrary files and cause a denial of service by uploading an HTML file.

Published May 1, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9692: IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, ca...

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By submitting suitable payloads, an attacker can cause the application server to attack other systems that it can interact with. IBM X-Force ID: 119516.

Published May 5, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9691: IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML E...

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID: 119515.

Published May 5, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9256: In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions...

In F5 BIG-IP 12.1.0 through 12.1.2, permissions enforced by iControl can lag behind the actual permissions assigned to a user if the role_map is not reloaded between the time the permissions are changed and the time of the user's next request. This is a race condition that occurs rarely in normal usage; the typical period in which this is possible is limited to at most a few seconds after the permission change.

Published May 9, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9257: In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a req...

In F5 BIG-IP APM 12.0.0 through 12.1.2, non-authenticated users may be able to inject JavaScript into a request that will then be rendered and executed in the context of the Administrative user when the Administrative user is viewing the Access System Logs, allowing the non-authenticated user to carry out a Cross Site Scripting (XSS) attack against the Administrative user.

Published May 9, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8741: The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to han...

The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these AuthenticationProviders in Apache Qpid Broker for Java 6.0.x before 6.0.6 and 6.1.x before 6.1.1 prematurely terminate the SCRAM SASL negotiation if the provided user name does not exist thus allowing remote attacker to determine the existence of user accounts. The Vulnerability does not apply to AuthenticationProviders other than SCRAM-SHA-1 and SCRAM-SHA-256.

Published May 15, 2017 · Updated Aug 6, 2024

Medium · CVSS 4.3

CVE-2016-8627: admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log f...

admin-cli before versions 3.0.0.alpha25, 2.2.1.cr2 is vulnerable to an EAP feature to download server log files that allows logs to be available via GET requests making them vulnerable to cross-origin attacks. An attacker could trigger the user's browser to request the log files consuming enough resources that normal server functioning could be impaired.

Published May 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8202: A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS)...

A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected versions, non-root users can gain root access with a combination of shell commands and parameters.

Published May 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7476: The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, P...

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, 11.5.0 before 11.5.3 HF2, and 11.3.0 before 11.4.1 HF10 may suffer from a memory leak while handling certain types of TCP traffic. Remote attackers may cause a denial of service (DoS) by way of a crafted TCP packet.

Published May 11, 2017 · Updated Aug 6, 2024

Medium · CVSS 6.4

CVE-2016-7076: sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run vi...

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly use this flaw to execute arbitrary commands with elevated privileges.

Published May 29, 2018 · Updated Aug 6, 2024