CVE Database

Comprehensive vulnerability intelligence with advanced analytics

7.8

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2, Word Automation Services on SharePoint Server 2013 SP1, Office Web Apps 2010…

Published: Oct 14, 2016
Modified: Oct 22, 2025
Product: microsoft word
EPSS: 71.20%
View Details
7.8

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows remote attackers to execute arbitrary code via a crafted…

Published: Oct 14, 2016
Modified: Oct 22, 2025
Product: microsoft windows_10_1607
EPSS: 32.42%
View Details
6.5

CVE-2016-3298

Medium KEV

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allow remote attackers to determine the existence of arbitrary files via a crafted web site, aka "Internet Explorer Information Disclosure Vulnerability."

Published: Oct 14, 2016
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 27.73%
View Details
6.5

CVE-2016-3351

Medium KEV

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."

Published: Sep 14, 2016
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 40.29%
View Details
7.8

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

Published: Aug 25, 2016
Modified: Oct 22, 2025
Product: apple iphone_os
EPSS: 73.33%
View Details
5.5

CVE-2016-4655

Medium KEV

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

Published: Aug 25, 2016
Modified: Oct 22, 2025
Product: apple iphone_os
EPSS: 82.29%
View Details
9.8

CVE-2016-4171

Critical KEV

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.

Published: Jun 16, 2016
Modified: Nov 17, 2025
Product: redhat enterprise_linux_server
EPSS: 50.54%
View Details
7.8

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which allows local users to gain privileges via a crafted application, aka "Microsoft Office OLE DLL Side Loading Vulnerability."

Published: Jun 16, 2016
Modified: Oct 22, 2025
Product: microsoft visio_viewer
EPSS: 81.16%
View Details
7.5

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.

Published: Jun 09, 2016
Modified: Oct 22, 2025
Product: trihedral vtscada
EPSS: 66.95%
View Details
10.0

CVE-2010-5326

Critical KEV

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote attackers to execute arbitrary code via an HTTP or HTTPS request, as exploited in the wild in 2013 through 2016, aka a "Detour" attack.

Published: May 13, 2016
Modified: Oct 22, 2025
EPSS: 16.90%
View Details
7.5

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a…

Published: May 11, 2016
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 91.50%
View Details
7.8

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Center link (aka .mcl) file, aka "Windows Media Center Remote Code Execution Vulnerability."

Published: May 11, 2016
Modified: Oct 22, 2025
Product: microsoft windows_8.1
EPSS: 82.75%
View Details
5.5

CVE-2016-3718

Medium KEV

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image.

Published: May 05, 2016
Modified: Oct 22, 2025
Product: opensuse opensuse
EPSS: 79.25%
View Details
5.5

CVE-2016-3715

Medium KEV

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

Published: May 05, 2016
Modified: Oct 22, 2025
Product: opensuse opensuse
EPSS: 79.80%
View Details
9.8

CVE-2016-3427

Critical KEV

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

Published: Apr 21, 2016
Modified: Oct 22, 2025
Product: netapp oncommand_report
EPSS: 93.62%
View Details
7.8

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege…

Published: Apr 12, 2016
Modified: Oct 22, 2025
Product: microsoft windows_rt_8.1
EPSS: 7.02%
View Details
4.3

CVE-2016-0162

Medium KEV

Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."

Published: Apr 12, 2016
Modified: Oct 22, 2025
Product: microsoft internet_explorer
EPSS: 37.99%
View Details
7.8

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

Published: Apr 12, 2016
Modified: Oct 22, 2025
Product: microsoft windows_rt_8.1
EPSS: 44.07%
View Details
9.8

CVE-2016-1019

Critical KEV

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, as exploited in the wild in April 2016.

Published: Apr 07, 2016
Modified: Nov 17, 2025
Product: adobe flash_player_desktop_runtime
EPSS: 74.46%
View Details
8.8

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider element data types, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted JavaScript code.

Published: Mar 29, 2016
Modified: Oct 22, 2025
Product: canonical ubuntu_linux
EPSS: 68.65%
View Details
8.8

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux, Adobe AIR before 21.0.0.176, Adobe AIR SDK before 21.0.0.176, and Adobe AIR SDK & Compiler before 21.0.0.176 allows attackers to execute arbitrary code via unspecified vectors,…

Published: Mar 12, 2016
Modified: Oct 22, 2025
Product: adobe flash_player_desktop_runtime
EPSS: 15.63%
View Details
7.8

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 does not properly process request handles, which allows local users to gain privileges via…

Published: Mar 09, 2016
Modified: Oct 22, 2025
Product: microsoft windows_server_2012
EPSS: 92.00%
View Details
8.8

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."

Published: Jan 13, 2016
Modified: Oct 22, 2025
EPSS: 47.07%
View Details
8.8

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified vectors.

Published: Dec 28, 2015
Modified: Oct 22, 2025
Product: hp version_control_repository_manager
EPSS: 90.48%
View Details