Latest CVE Feed
-
7.5
HIGHCVE-2016-5285
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.... Read more
- EPSS Score: %0.65
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2016-5236
Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when creating a new user, account or signature.... Read more
Affected Products : websafe_alert_server- EPSS Score: %0.25
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-5235
A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert.... Read more
Affected Products : websafe_alert_server- EPSS Score: %0.67
- Published: Jul. 01, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2016-5202
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access d... Read more
- EPSS Score: %0.14
- Published: Oct. 25, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-5194
Unspecified vulnerabilities in Google Chrome before 54.0.2840.59.... Read more
Affected Products : chrome- EPSS Score: %0.25
- Published: Nov. 20, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2016-5179
Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.... Read more
Affected Products : chrome_os- EPSS Score: %3.35
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-4991
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve comma... Read more
Affected Products : nodepdf- EPSS Score: %1.24
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2016-4983
A postinstall script in the dovecot rpm allows local users to read the contents of newly created SSL/TLS key files.... Read more
- EPSS Score: %0.14
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
2.5
LOW- EPSS Score: %0.13
- Published: Nov. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-4975
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fi... Read more
Affected Products : http_server- EPSS Score: %86.60
- Published: Aug. 14, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-4761
WebKitGTK+ before 2.14.0: A use-after-free vulnerability can allow remote attackers to cause a DoS... Read more
- EPSS Score: %0.54
- Published: Jan. 22, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-4676
A Cross-origin vulnerability exists in WebKit in Apple Safari before 10.0.1 when processing location attributes, which could let a remote malicious user obtain sensitive information.... Read more
- EPSS Score: %1.78
- Published: Feb. 03, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-4644
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a downgrade issue existed with HTTP authentication credentials saved in Keychain. This issue was addressed by storing the authentication types with t... Read more
- EPSS Score: %0.45
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-4643
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, a validation issue existed in the parsing of 407 responses. This issue was addressed through improved response validation.... Read more
- EPSS Score: %0.37
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-4642
In iOS before 9.3.3, tvOS before 9.2.2, and OS X El Capitan before v10.11.6 and Security Update 2016-004, proxy authentication incorrectly reported HTTP proxies received credentials securely. This issue was addressed through improved warnings.... Read more
- EPSS Score: %0.36
- Published: Jan. 11, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-4606
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions.... Read more
- EPSS Score: %0.22
- Published: Feb. 21, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-4572
In Cloudera CDH before 5.7.1, Impala REVOKE ALL ON SERVER commands do not revoke all privileges.... Read more
Affected Products : cdh- EPSS Score: %0.34
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-4427
In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.... Read more
Affected Products : zulip- EPSS Score: %0.26
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2016-4426
In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.... Read more
Affected Products : zulip- EPSS Score: %0.15
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2016-4406
A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.... Read more
Affected Products : integrated_lights-out_4_firmware integrated_lights-out_3_firmware integrated_lights-out- EPSS Score: %0.54
- Published: Aug. 06, 2018
- Modified: Nov. 21, 2024