LiveActive security incident?Get immediate response
CVE archive

June 2016

Browse CVE records published in June 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 828 matching CVEs · Page 5 of 17.

Unknown · CVSS Not scored

CVE-2016-9973: IBM Jazz Foundation is vulnerable to cross-site scripting.

IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.

Published Jun 13, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9901: HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code ex...

HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9902: The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify...

The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9904: An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another co...

An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9893: Memory safety bugs were reported in Thunderbird 45.5.

Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9747: IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting.

IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Published Jun 22, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9834: An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installa...

An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.

Published Jun 7, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9698: IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity In...

IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.

Published Jun 8, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9490: ManageEngine Applications Manager versions 12 and 13 suffer from a Reflected Cross-Site Scripting vulnerability

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without authentication.

Published Jun 5, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9488: ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities

ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.

Published Jun 5, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9358: A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with...

A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. The end user does not have the ability to change system passwords.

Published Jun 30, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9078: Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL...

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9080: Memory safety bugs were reported in Firefox 50.0.2.

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9064: Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on b...

Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9065: The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its...

The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024