Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-0667 1 Oracle 1 Mysql 2016-12-03 2.8 LOW 4.4 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Locking.
CVE-2016-0669 1 Oracle 1 Solaris 2016-12-03 5.2 MEDIUM 6.0 MEDIUM
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Fwflash.
CVE-2016-0671 1 Oracle 1 Http Server 2016-12-03 2.6 LOW 3.7 LOW
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to OSSL Module.
CVE-2016-0672 1 Oracle 1 Flexcube Direct Banking 2016-12-03 5.0 MEDIUM 6.1 MEDIUM
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to Pre-Login.
CVE-2016-0673 1 Oracle 1 Siebel Ui Framework 2016-12-03 4.9 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to UIF Open UI.
CVE-2016-0674 1 Oracle 1 Siebel Core-common Components 2016-12-03 3.2 LOW 4.4 MEDIUM
Unspecified vulnerability in the Siebel Core - Common Components component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows local users to affect confidentiality and integrity via vectors related to Email.
CVE-2016-0676 1 Oracle 1 Solaris 2016-12-03 4.0 MEDIUM 4.7 MEDIUM
Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect availability via vectors related to the kernel.
CVE-2016-0677 1 Oracle 1 Database 2016-12-03 5.0 MEDIUM 5.9 MEDIUM
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.
CVE-2016-0678 1 Oracle 1 Vm Virtualbox 2016-12-03 4.1 MEDIUM 6.7 MEDIUM
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox before 5.0.18 allows local users to affect confidentiality, integrity, and availability via vectors related to Core.
CVE-2016-0679 1 Oracle 1 Peoplesoft Enterprise Peopletools 2016-12-03 5.5 MEDIUM 8.7 HIGH
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect integrity and availability via vectors related to PIA Grids.
CVE-2016-0680 1 Oracle 1 Peoplesoft Supply Chain Management Eprocurement 2016-12-03 5.5 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Services Procurement.
CVE-2016-0681 1 Oracle 1 Olap 2016-12-03 6.5 MEDIUM 7.8 HIGH
Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unspecified vectors.
CVE-2016-0683 1 Oracle 1 Peoplesoft Enterprise Peopletools 2016-12-03 4.0 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Search Framework.
CVE-2016-0684 1 Oracle 1 Micros Arspos 2016-12-03 6.8 MEDIUM 6.5 MEDIUM
Unspecified vulnerability in the Oracle Retail MICROS ARS POS component in Oracle Retail Applications 1.5 allows remote authenticated users to affect confidentiality via vectors related to POS.
CVE-2016-0685 1 Oracle 1 Peoplesoft Enterprise Peopletools 2016-12-03 5.5 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to File Processing.
CVE-2016-0690 1 Oracle 1 Database 2016-12-03 4.0 MEDIUM 3.3 LOW
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691.
CVE-2016-0691 1 Oracle 1 Database 2016-12-03 4.0 MEDIUM 3.3 LOW
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690.
CVE-2016-0693 1 Oracle 1 Solaris 2016-12-03 10.0 HIGH 9.8 CRITICAL
Unspecified vulnerability in Oracle Sun Solaris 10 and 11.3 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to the PAM LDAP module.
CVE-2016-0697 1 Oracle 1 Application Object Library 2016-12-03 3.6 LOW 6.0 MEDIUM
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users to affect confidentiality and integrity via unknown vectors.
CVE-2016-0698 1 Oracle 1 Peoplesoft Enterprise Peopletools 2016-12-03 4.3 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53, 8.54, and 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to Rich Text Editor, a different vulnerability than CVE-2016-3423.
CVE-2016-0699 1 Oracle 1 Flexcube Direct Banking 2016-12-03 9.4 HIGH 9.1 CRITICAL
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.2 and 12.0.3 allows remote attackers to affect confidentiality and integrity via vectors related to the Login sub-component.
CVE-2016-0737 1 Openstack 1 Swift 2016-12-03 5.0 MEDIUM 7.5 HIGH
OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL.
CVE-2016-0211 1 Ibm 2 Db2, Db2 Connect 2016-12-03 4.0 MEDIUM 4.3 MEDIUM
IBM DB2 9.7 through FP11, 9.8, 10.1 through FP5, and 10.5 through FP7 on Linux, UNIX, and Windows allows remote authenticated users to cause a denial of service (daemon crash) via a crafted DRDA message.
CVE-2016-0226 2 Ibm, Microsoft 2 Informix Dynamic Server, Windows 2016-12-03 6.9 MEDIUM 7.8 HIGH
The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
CVE-2016-0227 1 Ibm 1 Business Process Manager 2016-12-03 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in the document-list control implementation in IBM Business Process Manager (BPM) 8.0 through 8.0.1.3, 8.5.0 through 8.5.0.2, and 8.5.5 and 8.5.6 through 8.5.6.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-0283 1 Ibm 1 Websphere Application Server 2016-12-03 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the OpenID Connect (OIDC) client web application in IBM WebSphere Application Server (WAS) Liberty Profile 8.5.5 before 8.5.5.9 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
CVE-2016-0407 1 Oracle 1 Peoplesoft Enterprise Human Capital Management Human Resources 2016-12-03 4.0 MEDIUM 6.5 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 and 9.2 allows remote authenticated users to affect confidentiality via vectors related to Fusion HR Talent Integration.
CVE-2016-0408 1 Oracle 1 Peoplesoft Enterprise Peopletools 2016-12-03 4.3 MEDIUM 5.4 MEDIUM
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 through 8.55 allows remote authenticated users to affect confidentiality and integrity via vectors related to the Activity Guide sub-component.
CVE-2016-0468 1 Oracle 1 Business Intelligence 2016-12-03 3.5 LOW 5.4 MEDIUM
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to Analytics Web General.
CVE-2016-0469 1 Oracle 1 Micros C2 2016-12-03 4.6 MEDIUM 5.5 MEDIUM
Unspecified vulnerability in the Oracle Retail MICROS C2 component in Oracle Retail Applications 9.89.0.0 allows local users to affect confidentiality via vectors related to POS.
CVE-2016-0479 1 Oracle 1 Business Intelligence 2016-12-03 5.8 MEDIUM 6.1 MEDIUM
Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote attackers to affect confidentiality and integrity via vectors related to Analytics Scorecard.
CVE-2016-0623 1 Oracle 1 Solaris 2016-12-03 4.3 MEDIUM 4.7 MEDIUM
Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect integrity via vectors related to the Automated Installer sub-component.
CVE-2016-0652 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to DML.
CVE-2016-0653 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to FTS.
CVE-2016-0654 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0656.
CVE-2016-0656 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to InnoDB, a different vulnerability than CVE-2016-0654.
CVE-2016-0657 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect confidentiality via vectors related to JSON.
CVE-2016-0658 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Optimizer.
CVE-2016-0659 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Optimizer.
CVE-2016-0662 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 5.5 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.11 and earlier allows local users to affect availability via vectors related to Partition.
CVE-2016-0663 1 Oracle 1 Mysql 2016-12-03 3.5 LOW 4.7 MEDIUM
Unspecified vulnerability in Oracle MySQL 5.7.10 and earlier allows local users to affect availability via vectors related to Performance Schema.
CVE-2015-8791 1 Matroska 1 Libebml 2016-12-03 4.3 MEDIUM 4.3 MEDIUM
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access.
CVE-2015-8816 2 Linux, Novell 9 Linux Kernel, Suse Linux Enterprise Debuginfo, Suse Linux Enterprise Desktop and 6 more 2016-12-03 7.2 HIGH 6.8 MEDIUM
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB hub device.
CVE-2015-7560 1 Samba 1 Samba 2016-12-03 4.0 MEDIUM 6.5 MEDIUM
The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote authenticated users to modify arbitrary ACLs by using a UNIX SMB1 call to create a symlink, and then using a non-UNIX SMB1 call to write to the ACL content.
CVE-2015-7840 1 Solarwinds 1 Log And Event Manager 2016-12-03 7.5 HIGH N/A
The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code via unspecified vectors involving the ping feature.
CVE-2015-7914 1 Sauter 1 Moduweb Vision 2016-12-03 9.3 HIGH 8.1 HIGH
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 allows remote attackers to bypass authentication by leveraging knowledge of a password hash without knowledge of the associated password.
CVE-2015-7915 1 Sauter 1 Moduweb Vision 2016-12-03 10.0 HIGH 9.8 CRITICAL
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2015-8152 1 Symantec 1 Endpoint Protection Manager 2016-12-03 8.5 HIGH 8.0 HIGH
Cross-site request forgery (CSRF) vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to hijack the authentication of administrators for requests that execute arbitrary code by adding lines to a logging script.
CVE-2015-8153 1 Symantec 1 Endpoint Protection Manager 2016-12-03 8.3 HIGH 8.8 HIGH
SQL injection vulnerability in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6-MP4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
CVE-2015-8154 1 Symantec 1 Endpoint Protection Manager 2016-12-03 9.3 HIGH 8.8 HIGH
The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4 allows remote attackers to execute arbitrary code via a crafted HTML document, related to "RWX Permissions."