LiveActive security incident?Get immediate response
CVE archive

June 2016

Browse CVE records published in June 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 828 matching CVEs · Page 4 of 17.

Unknown · CVSS Not scored

CVE-2016-1000340: In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the impl...

In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so there was the possibility of rare (in general usage) spurious calculations for elliptic curve scalar multiplications. Such errors would have been detected with high probability by the output validation for our scalar multipliers.

Published Jun 4, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-1000338: In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of si...

In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a signed structure.

Published Jun 1, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-1000343: In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak priv...

In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases this can be dealt with by explicitly passing parameters to the key pair generator.

Published Jun 4, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-1000341: In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing...

In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately the private value as well.

Published Jun 4, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-1000339: In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFas...

In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key being used. There was also a leak in AESEngine although it was substantially less. AESEngine has been modified to remove any signs of leakage (testing carried out on Intel X86-64) and is now the primary AES class for the BC JCE provider from 1.56. Use of AESFastEngine is now only recommended where otherwise deemed appropriate.

Published Jun 4, 2018 · Updated Aug 6, 2024

Medium · CVSS 4

CVE-2016-15032: mback2k mh_httpbl Extension class.tx_mhhttpbl.php stopOutput cross site scripting

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in mback2k mh_httpbl Extension up to 1.1.7 on TYPO3. This affects the function stopOutput of the file class.tx_mhhttpbl.php. The manipulation of the argument $_SERVER['REMOTE_ADDR'] leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.1.8 is able to address this issue. The patch is named a754bf306a433a8c18b55e25595593e8f19b9463. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-230391. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Published Jun 1, 2023 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10723: An issue was discovered in the Linux kernel through 4.17.2.

An issue was discovered in the Linux kernel through 4.17.2. Since the page allocator does not yield CPU resources to the owner of the oom_lock mutex, a local unprivileged user can trivially lock up the system forever by wasting CPU resources from the page allocator (e.g., via concurrent page fault events) when the global OOM killer is invoked. NOTE: the software maintainer has not accepted certain proposed patches, in part because of a viewpoint that "the underlying problem is non-trivial to handle.

Published Jun 21, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10692: haxeshim haxe shim to deal with coexisting versions.

haxeshim haxe shim to deal with coexisting versions. haxeshim downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.

Published Jun 4, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10583: closure-utils is Utilities for Closure Library based projects.

closure-utils is Utilities for Closure Library based projects. closure-utils downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.

Published Jun 1, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10395: In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on W...

In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges.

Published Jun 15, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10363: Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious...

Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted inputs are not handled by the codec and can cause the Logstash process to exit.

Published Jun 16, 2017 · Updated Aug 6, 2024