LiveActive security incident?Get immediate response
CVE archive

December 2016

Browse CVE records published in December 2016, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 530 matching CVEs · Page 6 of 11.

Unknown · CVSS Not scored

CVE-2016-7966: Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's pla...

Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.

Published Dec 23, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2016-7460: The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automati...

The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published Dec 29, 2016 · Updated Aug 6, 2024