LiveActive security incident?Get immediate response
CVE archive

June 2016

Browse CVE records published in June 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 830 matching CVEs · Page 8 of 17.

Unknown · CVSS Not scored

CVE-2016-5294: The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting...

The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5289: Memory safety bugs were reported in Firefox 49.

Memory safety bugs were reported in Firefox 49. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5293: When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, d...

When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5290: Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4.

Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5295: This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by havin...

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. This vulnerability requires local system access and is a variant of MFSA2013-44. Note: this issue only affects Windows operating systems. This vulnerability affects Firefox < 50.

Published Jun 11, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5234: Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V...

Buffer overflow in Huawei VP9660, VP9650, and VP9630 multipoint control unit devices with software before V500R002C00SPC200 and RSE6500 videoconference devices with software before V500R002C00SPC100, when an unspecified service is enabled, allows remote attackers to execute arbitrary code via a crafted packet, aka HWPSIRT-2016-05054.

Published Jun 13, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5233: Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, N...

Huawei Mate 8 smartphones with software NXT-AL10 before NXT-AL10C00B182, NXT-CL00 before NXT-CL00C92B182, NXT-DL00 before NXT-DL00C17B182, and NXT-TL00 before NXT-TL00C01B182 allow remote base stations to obtain sensitive subscriber signal strength information via vectors involving improper security status verification, aka HWPSIRT-2015-12007.

Published Jun 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-5021: The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x...

The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x before 11.6.1; BIG-IQ Cloud and Security 4.0.0 through 4.5.0; BIG-IQ Device 4.2.0 through 4.5.0; BIG-IQ ADC 4.5.0; BIG-IQ Centralized Management 4.6.0; and BIG-IQ Cloud and Orchestration 1.0.0 allows remote authenticated administrators to obtain sensitive information via unspecified vectors.

Published Jun 24, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-4902: Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's so...

Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)" Ver3.0.1 and earlier and The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.

Published Jun 9, 2017 · Updated Aug 6, 2024