Total
9585 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2016-4042 | 1 Plone | 1 Plone | 2025-04-20 | N/A |
Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors. | ||||
CVE-2016-4341 | 1 Netapp | 1 Clustered Data Ontap | 2025-04-20 | N/A |
NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors. | ||||
CVE-2016-4842 | 1 Cybozu | 1 Mailwise | 2025-04-20 | N/A |
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read. | ||||
CVE-2016-4843 | 1 Cybozu | 1 Mailwise | 2025-04-20 | N/A |
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information. | ||||
CVE-2016-4844 | 1 Cybozu | 1 Mailwise | 2025-04-20 | N/A |
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks. | ||||
CVE-2016-4664 | 1 Apple | 3 Iphone Os, Tvos, Watchos | 2025-04-20 | N/A |
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata via a crafted app. | ||||
CVE-2016-4665 | 1 Apple | 3 Iphone Os, Tvos, Watchos | 2025-04-20 | N/A |
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata via a crafted app. | ||||
CVE-2016-4680 | 1 Apple | 3 Iphone Os, Tvos, Watchos | 2025-04-20 | N/A |
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to obtain sensitive information from kernel memory via a crafted app. | ||||
CVE-2016-4806 | 1 Web2py | 1 Web2py | 2025-04-20 | N/A |
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server sensitive files. | ||||
CVE-2016-4867 | 1 Cybozu | 1 Office | 2025-04-20 | N/A |
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function. | ||||
CVE-2016-4869 | 1 Cybozu | 1 Office | 2025-04-20 | N/A |
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed. | ||||
CVE-2016-4872 | 1 Cybozu | 1 Office | 2025-04-20 | N/A |
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail. | ||||
CVE-2016-4947 | 1 Cloudera | 1 Hue | 2025-04-20 | N/A |
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete. | ||||
CVE-2016-4976 | 1 Apache | 1 Ambari | 2025-04-20 | N/A |
Apache Ambari 2.x before 2.4.0 includes KDC administrator passwords on the kadmin command line, which allows local users to obtain sensitive information via a process listing. | ||||
CVE-2016-5006 | 1 Pivotal Software | 2 Cloud Foundry, Cloud Foundry Elastic Runtime | 2025-04-20 | N/A |
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors. | ||||
CVE-2016-5012 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 3.x, glossary search displays entries without checking user permissions to view them. | ||||
CVE-2016-5014 | 1 Moodle | 1 Moodle | 2025-04-20 | N/A |
In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. | ||||
CVE-2016-5045 | 1 Netapp | 1 Oncommand System Manager | 2025-04-20 | N/A |
NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. | ||||
CVE-2016-5051 | 1 Osram | 1 Lightify Home | 2025-04-20 | N/A |
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application. | ||||
CVE-2016-5220 | 2 Google, Redhat | 2 Chrome, Rhel Extras | 2025-04-20 | N/A |
PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, which allowed a remote attacker to read local files via a crafted PDF file. |