2016 VULNERABILITY DATABASE
CVE-2016-4534
Summary: The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles.
Published: 5/5/2016 2:59:12 PM
CVSS Severity: v3 - 3.0 LOW v2 - 3.0 LOW
CVE-2016-4351
Summary: SQL injection vulnerability in the authentication functionality in Trend Micro Email Encryption Gateway (TMEEG) 5.5 before build 1107 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Published: 5/5/2016 2:59:11 PM
CVSS Severity: v3 - 9.8 CRITICAL v2 - 7.5 HIGH
CVE-2016-4008
Summary: The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate.
Published: 5/5/2016 2:59:10 PM
CVSS Severity: v3 - 5.9 MEDIUM v2 - 4.3 MEDIUM
CVE-2016-3718
Summary: The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.
Published: 5/5/2016 2:59:08 PM
CVSS Severity: v3 - 6.3 MEDIUM v2 - 4.3 MEDIUM
CVE-2016-3717
Summary: The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.
Published: 5/5/2016 2:59:07 PM
CVSS Severity: v3 - 5.5 MEDIUM v2 - 7.1 HIGH
CVE-2016-3716
Summary: The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image.
Published: 5/5/2016 2:59:06 PM
CVSS Severity: v3 - 3.3 LOW v2 - 4.3 MEDIUM
CVE-2016-3715
Summary: The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.
Published: 5/5/2016 2:59:04 PM
CVSS Severity: v3 - 5.5 MEDIUM v2 - 5.8 MEDIUM
CVE-2016-3714
Summary: The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick."
Published: 5/5/2016 2:59:03 PM
CVSS Severity: v3 - 8.4 HIGH v2 - 10.0 HIGH
CVE-2016-2168
Summary: The req_check_access function in the mod_authz_svn module in the httpd server in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a crafted header in a (1) MOVE or (2) COPY request, involving an authorization check.
Published: 5/5/2016 2:59:01 PM
CVSS Severity: v3 - 6.5 MEDIUM v2 - 4.0 MEDIUM
CVE-2016-2167
Summary: The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication is used, allows remote attackers to authenticate and bypass intended access restrictions via a realm string that is a prefix of an expected repository realm string.
Published: 5/5/2016 2:59:00 PM
CVSS Severity: v3 - 6.8 MEDIUM v2 - 4.9 MEDIUM
CVE-2016-2176
Summary: The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a denial of service (buffer over-read) via crafted EBCDIC ASN.1 data.
Published: 5/4/2016 9:59:06 PM
CVSS Severity: v3 - 8.2 HIGH v2 - 6.4 MEDIUM
CVE-2016-2109
Summary: The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding.
Published: 5/4/2016 9:59:05 PM
CVSS Severity: v3 - 7.5 HIGH v2 - 7.8 HIGH
CVE-2016-2108
Summary: The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.
Published: 5/4/2016 9:59:04 PM
CVSS Severity: v3 - 9.8 CRITICAL v2 - 10.0 HIGH
CVE-2016-2107
Summary: The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session, NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169.
Published: 5/4/2016 9:59:03 PM
CVSS Severity: v3 - 5.9 MEDIUM v2 - 2.6 LOW
CVE-2016-2106
Summary: Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.
Published: 5/4/2016 9:59:02 PM
CVSS Severity: v3 - 7.5 HIGH v2 - 5.0 MEDIUM
CVE-2016-2105
Summary: Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
Published: 5/4/2016 9:59:01 PM
CVSS Severity: v3 - 7.5 HIGH v2 - 5.0 MEDIUM
CVE-2000-1254
Summary: crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms.
Published: 5/4/2016 9:59:00 PM
CVSS Severity: v3 - 7.5 HIGH v2 - 5.0 MEDIUM
CVE-2016-0895
Summary: EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to conduct clickjacking attacks via web-site elements with crafted transparency or opacity.
Published: 5/3/2016 11:59:03 AM
CVSS Severity: v3 - 4.3 MEDIUM v2 - 4.3 MEDIUM
CVE-2016-0894
Summary: EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to bypass intended object access restrictions via a modified parameter.
Published: 5/3/2016 11:59:02 AM
CVSS Severity: v3 - 6.3 MEDIUM v2 - 6.5 MEDIUM
CVE-2016-0893
Summary: EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote authenticated users to obtain sensitive information by reading error messages.
Published: 5/3/2016 11:59:01 AM
CVSS Severity: v3 - 4.3 MEDIUM v2 - 4.0 MEDIUM