Latest CVE Feed
-
9.8
CRITICALCVE-2016-10243
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.... Read more
- EPSS Score: %9.88
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1585
In all versions of AppArmor mount rules are accidentally widened when compiled.... Read more
- EPSS Score: %0.08
- Published: Apr. 22, 2019
- Modified: May. 02, 2025
-
9.8
CRITICALCVE-2016-4000
Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.... Read more
- EPSS Score: %15.58
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4160
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +3 more products- EPSS Score: %2.36
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5022
F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +12 more products- EPSS Score: %1.30
- Published: Sep. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5239
The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspecified vectors.... Read more
Affected Products : imagemagick- EPSS Score: %0.92
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5343
drivers/soc/qcom/qdsp6v2/voice_svc.c in the QDSP6v2 Voice Service driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (memory... Read more
Affected Products : linux_kernel- EPSS Score: %0.83
- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5535
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, 12.2.1.0, and 12.2.1.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : weblogic_server- EPSS Score: %3.55
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5771
spl_array.c in the SPL extension in PHP before 5.5.37 and 5.6.x before 5.6.23 improperly interacts with the unserialize implementation and garbage collection, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-... Read more
- EPSS Score: %8.19
- Published: Aug. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6354
Heap-based buffer overflow in the yy_get_next_buffer function in Flex before 2.6.1 might allow context-dependent attackers to cause a denial of service or possibly execute arbitrary code via vectors involving num_to_read.... Read more
- EPSS Score: %36.85
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7417
ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via... Read more
Affected Products : php- EPSS Score: %1.14
- Published: Sep. 17, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-8735
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this... Read more
Affected Products : ubuntu_linux debian_linux agile_engineering_data_management oncommand_insight oncommand_shift mysql_enterprise_monitor tomcat hospitality_guest_access jboss_enterprise_web_server agile_plm +9 more products- Actively Exploited
- EPSS Score: %94.00
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0903
RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possible remote code execution vulnerability. YAML deserialization of gem specifications can bypass class white lists. Specially crafted serialized objects can possibly be used to escalate to ... Read more
- EPSS Score: %4.90
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10913
The grant-table feature in Xen through 4.8.x provides false mapping information in certain cases of concurrent unmap calls, which allows backend attackers to obtain sensitive information or gain privileges, aka XSA-218 bug 1.... Read more
Affected Products : xen- EPSS Score: %1.20
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11362
In PHP 7.x before 7.0.21 and 7.1.x before 7.1.7, ext/intl/msgformat/msgformat_parse.c does not restrict the locale length, which allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unsp... Read more
Affected Products : php- EPSS Score: %1.72
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11721
Buffer overflow in ioquake3 before 2017-08-02 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted packet.... Read more
Affected Products : ioquake3- EPSS Score: %3.23
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1196
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) 1.9.70 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123671.... Read more
Affected Products : bigfix_security_compliance_analytics- EPSS Score: %0.31
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8011
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV b... Read more
- EPSS Score: %4.15
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12562
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- EPSS Score: %2.71
- Published: Aug. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12858
Double free vulnerability in the _zip_dirent_read function in zip_dirent.c in libzip allows attackers to have unspecified impact via unknown vectors.... Read more
Affected Products : libzip- EPSS Score: %1.00
- Published: Aug. 23, 2017
- Modified: Apr. 20, 2025