Latest CVE Feed
-
7.6
HIGHCVE-2017-0444
An elevation of privilege vulnerability in the Realtek sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proc... Read more
- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0438
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0437
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0433
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromis... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0424
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it is a general bypass for a user level defense ... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0420
An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate application data from other applications. This issue is rated as High because it could be used to gain acce... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0417
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated c... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8414
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires comprom... Read more
- EPSS Score: %0.16
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6495
NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access.... Read more
Affected Products : data_ontap- EPSS Score: %0.35
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8981
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.... Read more
- EPSS Score: %0.06
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-8544
NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : snapdrive- EPSS Score: %0.48
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-7599
Integer overflow in the _authenticate function in svc_auth.c in Wind River VxWorks 5.5 through 6.9.4.1, when the Remote Procedure Call (RPC) protocol is enabled, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co... Read more
Affected Products : vxworks- EPSS Score: %5.29
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2016-6097
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 allows web pages to be stored locally which can be read by another user on the system.... Read more
- EPSS Score: %0.06
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-5137
An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective.... Read more
Affected Products : entera_sms_gateway_firmware avera_sms_gateway_firmware entera_sms_gateway avera_sms_gateway- EPSS Score: %0.32
- Published: Feb. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7147
Cross-site scripting (XSS) vulnerability in the manage_findResult component in the search feature in Zope ZMI in Plone before 4.3.12 and 5.x before 5.0.7 allows remote attackers to inject arbitrary web script or HTML via vectors involving double quotes, a... Read more
Affected Products : plone- EPSS Score: %0.30
- Published: Feb. 04, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-3809
A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to prevent deployment of a complete and accurate rule base. More Information: CSCvb95281. Known Affected Release... Read more
- EPSS Score: %0.59
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2766
EMC Documentum eRoom version 7.4.4, EMC Documentum eRoom version 7.4.4 SP1, EMC Documentum eRoom version prior to 7.4.5 P04, EMC Documentum eRoom version prior to 7.5.0 P01 includes an unverified password change vulnerability that could potentially be exp... Read more
Affected Products : documentum_eroom- EPSS Score: %0.79
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8211
EMC Data Protection Advisor 6.1.x, EMC Data Protection Advisor 6.2, EMC Data Protection Advisor 6.2.1, EMC Data Protection Advisor 6.2.2, EMC Data Protection Advisor 6.2.3 prior to patch 446 has a path traversal vulnerability that may potentially be explo... Read more
Affected Products : emc_data_protection_advisor- EPSS Score: %0.78
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2016-6648
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by sensitive information disclosure vulnerability as a result of incorrect permissions set on a sensitive system file. A malicious administ... Read more
- EPSS Score: %0.12
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6116
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive informati... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.22
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025