Latest CVE Feed
-
9.8
CRITICALCVE-2016-2054
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.... Read more
- EPSS Score: %4.09
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2004
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014... Read more
Affected Products : data_protector- EPSS Score: %92.31
- Published: Apr. 21, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-20017
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.... Read more
- Actively Exploited
- EPSS Score: %88.20
- Published: Oct. 19, 2022
- Modified: Mar. 14, 2025
-
9.8
CRITICALCVE-2016-1578
Use-after-free vulnerability in Oxide allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via unspecified vectors, related to responding synchronously to permission requests.... Read more
- EPSS Score: %2.21
- Published: May. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1387
The XML API in TelePresence Codec (TC) 7.2.0, 7.2.1, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, and 7.3.5 and Collaboration Endpoint (CE) 8.0.0, 8.0.1, and 8.1.0 in Cisco TelePresence Software mishandles authentication, which allows remote attackers to execute co... Read more
Affected Products : telepresence_tc_software- EPSS Score: %1.44
- Published: May. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1352
Cisco Unified Computing System (UCS) Central Software 1.3(1b) and earlier allows remote attackers to execute arbitrary OS commands via a crafted HTTP request, aka Bug ID CSCuv33856.... Read more
Affected Products : unified_computing_system_central_software- EPSS Score: %0.39
- Published: Apr. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1114
Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.... Read more
Affected Products : coldfusion- EPSS Score: %2.34
- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-10727
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it eas... Read more
- EPSS Score: %0.93
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-10192
Heap-based buffer overflow in ffserver.c in FFmpeg before 2.8.10, 3.0.x before 3.0.5, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 allows remote attackers to execute arbitrary code by leveraging failure to check chunk size.... Read more
Affected Products : ffmpeg- EPSS Score: %12.51
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execut... Read more
- EPSS Score: %67.86
- Published: Dec. 30, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0791
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.... Read more
- EPSS Score: %0.49
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8972
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated when in UCI mode.... Read more
Affected Products : chess- EPSS Score: %3.21
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8768
click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to install an alternate security policy and gain privileges via a crafted package, as demonstrated by the test.mmro... Read more
- EPSS Score: %1.59
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8626
The User::randomPassword function in MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates passwords smaller than $wgMinimalPasswordLength, which makes it easier for remote attackers to obtain access via ... Read more
Affected Products : mediawiki- EPSS Score: %0.85
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8521
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8520, and CVE-2015-8522.... Read more
Affected Products : tivoli_storage_manager_fastback- EPSS Score: %8.91
- Published: Apr. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8520
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8519, CVE-2015-8521, and CVE-2015-8522.... Read more
Affected Products : tivoli_storage_manager_fastback- EPSS Score: %8.91
- Published: Apr. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8519
Buffer overflow in the server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to execute arbitrary code via a crafted command, a different vulnerability than CVE-2015-8520, CVE-2015-8521, and CVE-2015-8522.... Read more
Affected Products : tivoli_storage_manager_fastback- EPSS Score: %8.91
- Published: Apr. 05, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8212
CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted arguments, which are handled by a non-CGI aware program.... Read more
Affected Products : netbsd- EPSS Score: %2.30
- Published: Jan. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8103
The Jenkins CLI subsystem in Jenkins before 1.638 and LTS before 1.625.2 allows remote attackers to execute arbitrary code via a crafted serialized Java object, related to a problematic webapps/ROOT/WEB-INF/lib/commons-collections-*.jar file and the "Groo... Read more
- EPSS Score: %90.56
- Published: Nov. 25, 2015
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-7510
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.... Read more
Affected Products : systemd- EPSS Score: %0.45
- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025