LiveActive security incident?Get immediate response
CVE archive

June 2016

Browse CVE records published in June 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 828 matching CVEs · Page 6 of 17.

Unknown · CVSS Not scored

CVE-2016-9062: Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "bro...

Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9061: A previously installed malicious Android application which defines a specific signature-level permissions u...

A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8218: An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-releas...

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

Published Jun 13, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7811: Corega CG-WLR300NX firmware Ver.

Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary operations via unspecified vectors.

Published Jun 9, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7818: Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver.

Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program Ver. 5.00 and earlier, Device data encryption program Ver. 1.00 and earlier, and TODOKESHO creation program Ver. 15.00 and earlier available prior to October 17, 2016 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Published Jun 9, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7830: Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior...

Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices with firmware version prior to Ver.1.22 allow an attacker on the same network segment to bypass authentication to perform administrative operations via unspecified vectors.

Published Jun 9, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7469: A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in B...

A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2, 11.4.0 - 11.6.1, and 11.2.1 allows an authenticated user to inject arbitrary web script or HTML. Exploitation requires Resource Administrator or Administrator privileges, and it could cause the Configuration utility client to become unstable.

Published Jun 9, 2017 · Updated Aug 6, 2024