Latest CVE Feed
-
9.8
CRITICALCVE-2016-6814
When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an... Read more
- EPSS Score: %4.12
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-6293
The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ does not ensure that there is a '\0' character at the end of a certain temporary array, which allows remote attackers to cause... Read more
Affected Products : international_components_for_unicode- EPSS Score: %1.07
- Published: Jul. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6291
The exif_process_IFD_in_MAKERNOTE function in ext/exif/exif.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds array access and memory corruption), obtain sensitive informa... Read more
Affected Products : php- EPSS Score: %4.80
- Published: Jul. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5769
Multiple integer overflows in mcrypt.c in the mcrypt extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allow remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecif... Read more
Affected Products : php- EPSS Score: %5.90
- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5734
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code via a crafted s... Read more
Affected Products : phpmyadmin- EPSS Score: %72.92
- Published: Jul. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5254
Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) ... Read more
- EPSS Score: %0.89
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5003
The Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to execute arbitrary code via a crafted serialized Java object in an <ex:serializable> element.... Read more
Affected Products : ws-xmlrpc- EPSS Score: %40.15
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4564
The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and appli... Read more
Affected Products : imagemagick- EPSS Score: %0.99
- Published: Jun. 04, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3132
Double free vulnerability in the SplDoublyLinkedList::offsetSet function in ext/spl/spl_dllist.c in PHP 7.x before 7.0.6 allows remote attackers to execute arbitrary code via a crafted index.... Read more
Affected Products : php- EPSS Score: %16.48
- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2177
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging un... Read more
- EPSS Score: %47.95
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2008
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : data_protector- EPSS Score: %20.72
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1908
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding priv... Read more
- EPSS Score: %4.36
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1901
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.... Read more
- EPSS Score: %4.36
- Published: Jan. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-10134
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.... Read more
Affected Products : zabbix- EPSS Score: %88.00
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8778
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers... Read more
- EPSS Score: %6.77
- Published: Apr. 19, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-5740
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.... Read more
- EPSS Score: %6.04
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-4643
Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflo... Read more
- EPSS Score: %6.68
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-3253
The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object.... Read more
- EPSS Score: %52.46
- Published: Aug. 13, 2015
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2022-23305
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipu... Read more
Affected Products : business_intelligence weblogic_server identity_manager_connector snapmanager mysql_enterprise_monitor hyperion_data_relationship_management tuxedo business_process_management_suite communications_instant_messaging_server communications_offline_mediation_controller +18 more products- EPSS Score: %14.14
- Published: Jan. 18, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2014-9843
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.... Read more
- EPSS Score: %1.09
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025