LiveActive security incident?Get immediate response
CVE archive

November 2016

Browse CVE records published in November 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 409 matching CVEs · Page 5 of 9.

Unknown · CVSS Not scored

CVE-2016-7242: The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code...

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, and CVE-2016-7243.

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7237: Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2...

Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote authenticated users to cause a denial of service (system hang) via a crafted request, aka "Local Security Authority Subsystem Service Denial of Service Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7208: The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code...

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7205: Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012...

Animation Manager in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Animation Manager Memory Corruption Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7221: Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1...

Input Method Editor (IME) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 mishandles DLL loading, which allows local users to gain privileges via unspecified vectors, aka "Windows IME Elevation of Privilege Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7212: Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server...

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow remote attackers to execute arbitrary code via a crafted image file, aka "Windows Remote Code Execution Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7210: atmfd.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W...

atmfd.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted Open Type font on a web site, aka "Open Type Font Information Disclosure Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7223: Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows...

Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 does not properly restrict access to files, which allows local users to gain privileges via a crafted application, aka "VHD Driver Elevation of Privilege Vulnerability."

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7202: The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers...

The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," as demonstrated by the Chakra JavaScript engine, a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7203: The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code...

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7200, CVE-2016-7201, CVE-2016-7202, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7184: The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1...

The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows local users to gain privileges via a crafted application, aka "Windows Common Log File System Driver Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0026, CVE-2016-3332, CVE-2016-3333, CVE-2016-3334, CVE-2016-3335, CVE-2016-3338, CVE-2016-3340, CVE-2016-3342, and CVE-2016-3343.

Published Nov 10, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7165: A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Produ...

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions < V13 SP2), SIMATIC STEP 7 V5.X (All versions < V5.5 SP4 HF11), SIMATIC WinCC (TIA Portal) Basic, Comfort, Advanced (All versions < V14), SIMATIC WinCC (TIA Portal) Professional V13 (All versions < V13 SP2), SIMATIC WinCC (TIA Portal) Professional V14 (All versions < V14 SP1), SIMATIC WinCC Runtime Professional V13 (All versions < V13 SP2), SIMATIC WinCC Runtime Professional V14 (All versions < V14 SP1), SIMATIC WinCC V7.0 SP2 and earlier versions (All versions < V7.0 SP2 Upd 12), SIMATIC WinCC V7.0 SP3 (All versions < V7.0 SP3 Upd 8), SIMATIC WinCC V7.2 (All versions < V7.2 Upd 14), SIMATIC WinCC V7.3 (All versions < V7.3 Upd 11), SIMATIC WinCC V7.4 (All versions < V7.4 SP1), SIMIT V9.0 (All versions < V9.0 SP1), SINEMA Remote Connect Client (All versions < V1.0 SP3), SINEMA Server (All versions < V13 SP2), SOFTNET Security Client V5.0 (All versions), Security Configuration Tool (SCT) (All versions < V4.3 HF1), TeleControl Server Basic (All versions < V3.0 SP2), WinAC RTX 2010 SP2 (All versions), WinAC RTX F 2010 SP2 (All versions). Unquoted service paths could allow local Microsoft Windows operating system users to escalate their privileges if the affected products are not installed under their default path ("C:\Program Files\*" or the localized equivalent).

Published Nov 15, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6754: A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x...

A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-11-05 could enable a remote attacker to execute arbitrary code when the user is navigating to a website. This issue is rated as High due to the possibility of remote code execution in an unprivileged process. Android ID: A-31217937.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6753: An information disclosure vulnerability in kernel components, including the process-grouping subsystem and...

An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30149174.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6743: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 co...

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30937462.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6748: An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM...

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30076504. References: Qualcomm QC-CR#987018.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6742: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 co...

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30799828.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6736: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable...

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30953284. References: NVIDIA N-CVE-2016-6736.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6725: A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enab...

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of remote code execution in the context of the kernel. Android ID: A-30515053. References: Qualcomm QC-CR#1050970.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6728: An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enab...

An elevation of privilege vulnerability in the kernel ION subsystem in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30400942.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6717: An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1...

An elevation of privilege vulnerability in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires exploitation of a separate vulnerability. Android ID: A-31350239.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6724: A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5....

A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could enable a local malicious application to cause the device to continually reboot. This issue is rated as Moderate because it is a temporary denial of service that requires a factory reset to fix. Android ID: A-30568284.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6698: An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM...

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30741851. References: Qualcomm QC-CR#1058826.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6746: An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable...

An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user permission. Android ID: A-30955105. References: NVIDIA N-CVE-2016-6746.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6747: A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to u...

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Android ID: A-31244612. References: NVIDIA N-CVE-2016-6747.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6740: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could en...

An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30143904. References: Qualcomm QC-CR#1056307.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6733: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable...

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30906694. References: NVIDIA N-CVE-2016-6733.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6741: An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could en...

An elevation of privilege vulnerability in the Qualcomm camera driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-30559423. References: Qualcomm QC-CR#1060554.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6701: A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker...

A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as High due to the possibility of remote code execution within the context of the gallery process. Android ID: A-30190637.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6745: An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 co...

An elevation of privilege vulnerability in the Synaptics touchscreen driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Android ID: A-31252388.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6731: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable...

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30906023. References: NVIDIA N-CVE-2016-6731.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6715: An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0...

An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 before 2016-11-01 could allow a local malicious application to record audio without the user's permission. This issue is rated as Moderate because it is a local bypass of user interaction requirements (access to functionality that would normally require either user initiation or user permission.) Android ID: A-29833954.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6730: An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable...

An elevation of privilege vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Android ID: A-30904789. References: NVIDIA N-CVE-2016-6730.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6751: An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM...

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-30902162. References: Qualcomm QC-CR#1062271.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6709: An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0...

An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-the-middle attacker to gain access to sensitive information if a non-standard cipher suite is used by an application. This issue is rated as High because it could be used to access data without permission. Android ID: A-31081987.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6752: An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM...

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver in Android before 2016-11-05 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Android ID: A-31498159. References: Qualcomm QC-CR#987051.

Published Nov 25, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-6721: An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016...

An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Android ID: A-30875060.

Published Nov 25, 2016 · Updated Aug 6, 2024