LiveActive security incident?Get immediate response
CVE archive

October 2016

Browse CVE records published in October 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 706 matching CVEs · Page 6 of 15.

Unknown · CVSS Not scored

CVE-2016-10729: An issue was discovered in Amanda 3.3.1.

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allowing users to manipulate commands and perform command injection as root.

Published Oct 24, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10730: An issue was discovered in Amanda 3.3.1.

An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. Amstar is an Amanda Application API script. It should not be run by users directly. It uses star to backup and restore data. It runs binaries with root permissions when parsing the command line argument --star-path.

Published Oct 24, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10731: ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter statu...

ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.

Published Oct 28, 2018 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-10699: D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password...

D-Link DSL-2740E 1.00_BG_20150720 devices are prone to persistent XSS attacks in the username and password fields: a remote unauthenticated user may craft logins and passwords with script tags in them. Because there is no sanitization in the input fields, an unaware logged-in administrator may be a victim when checking the router logs.

Published Oct 31, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-9017: Artifex Software, Inc.

Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by using the "opname in crafted JavaScript file" approach, related to an "Out-of-Bounds read" issue affecting the jsC_dumpfunction function in the jsdump.c component.

Published Oct 28, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8878: Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app...

Out-of-Bounds read vulnerability in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to execute arbitrary code via a crafted BMP image embedded in the XFA stream in a PDF document, aka "Data from Faulting Address may be used as a return value starting at FOXITREADER."

Published Oct 31, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8875: The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enable...

The ConvertToPDF plugin in Foxit Reader and PhantomPDF before 8.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image, aka "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at ConvertToPDF_x86!CreateFXPDFConvertor."

Published Oct 31, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8879: The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8....

The thumbnail shell extension plugin (FoxitThumbnailHndlr_x86.dll) in Foxit Reader and PhantomPDF before 8.1 on Windows allows remote attackers to cause a denial of service (out-of-bounds write and application crash) via a crafted JPEG2000 image embedded in a PDF document, aka an "Exploitable - Heap Corruption" issue.

Published Oct 31, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8856: Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from...

Foxit Reader for Mac 2.1.0.0804 and earlier and Foxit Reader for Linux 2.1.0.0805 and earlier suffered from a vulnerability where weak file permissions could be exploited by attackers to execute arbitrary code. After the installation, Foxit Reader's core files were world-writable by default, allowing an attacker to overwrite them with backdoor code, which when executed by privileged user would result in Privilege Escalation, Code Execution, or both.

Published Oct 31, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8658: Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80...

Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a long SSID Information Element in a command to a Netlink socket.

Published Oct 16, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-8666: The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack con...

The IP stack in the Linux kernel before 4.6 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for packets with tunnel stacking, as demonstrated by interleaved IPv4 headers and GRE headers, a related issue to CVE-2016-7039.

Published Oct 16, 2016 · Updated Aug 6, 2024