Latest CVE Feed
-
4.0
MEDIUMCVE-2016-6097
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.... Read more
- EPSS Score: %0.06
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-5137
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.... Read more
Affected Products : entera_sms_gateway_firmware avera_sms_gateway_firmware entera_sms_gateway avera_sms_gateway- EPSS Score: %0.32
- Published: Feb. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7147
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, a... Read more
Affected Products : plone- EPSS Score: %0.30
- Published: Feb. 04, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-3809
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Release... Read more
- EPSS Score: %0.59
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2766
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exp... Read more
Affected Products : documentum_eroom- EPSS Score: %0.79
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8211
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be explo... Read more
Affected Products : emc_data_protection_advisor- EPSS Score: %0.78
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2016-6648
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administ... Read more
- EPSS Score: %0.12
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6116
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive informati... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.22
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6237
The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file.... Read more
Affected Products : lepton- EPSS Score: %0.21
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8963
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.... Read more
- EPSS Score: %0.05
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8930
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- EPSS Score: %0.35
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8929
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- EPSS Score: %0.28
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8928
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
- EPSS Score: %0.35
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-6115
IBM General Parallel File System is vulnerable to a buffer overflow. A remote authenticated attacker could overflow a buffer and execute arbitrary code on the system with root privileges or cause the server to crash.... Read more
- EPSS Score: %3.14
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-6001
IBM Forms Experience Builder could be susceptible to a server-side request forgery (SSRF) from the application design interface allowing for some information disclosure of internal resources.... Read more
Affected Products : forms_experience_builder- EPSS Score: %0.14
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-2942
IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processes to run on a remote UCD agent machine.... Read more
Affected Products : urbancode_deploy- EPSS Score: %0.24
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6117
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 can be deployed with active debugging code that can disclose sensitive information.... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.22
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2016-6105
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 do not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas.... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.26
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-0371
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application tracing is enabled.... Read more
- EPSS Score: %0.12
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8921
IBM FileNet WorkPlace XT could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.... Read more
Affected Products : filenet_workplace_xt- EPSS Score: %2.86
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025