Latest CVE Feed
-
4.3
MEDIUMCVE-2016-8301
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnera... Read more
Affected Products : flexcube_universal_banking- EPSS Score: %0.64
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-8282
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.51
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-8226
The BIOS in Lenovo System X M5, M6, and X6 systems allows administrators to cause a denial of service via updating a UEFI data structure.... Read more
- EPSS Score: %0.30
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-5509
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows l... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.25
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-1920
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.... Read more
Affected Products : knox- EPSS Score: %0.12
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8710
An exploitable heap write out of bounds vulnerability exists in the decoding of BPG images in Libbpg library. A crafted BPG image decoded by libbpg can cause an integer underflow vulnerability causing an out of bounds heap write leading to remote code exe... Read more
Affected Products : libbpg- EPSS Score: %3.06
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8225
Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code with elevated privileges.... Read more
- EPSS Score: %0.06
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3803
A vulnerability in the Cisco IOS Software forwarding queue of Cisco 2960X and 3750X switches could allow an unauthenticated, adjacent attacker to cause a memory leak in the software forwarding queue that would eventually lead to a partial denial of servic... Read more
Affected Products : ios- EPSS Score: %0.17
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3802
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected ... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.29
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9307
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed 3DS format files.... Read more
Affected Products : fbx_software_development_kit- EPSS Score: %2.68
- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9305
Improper handling in the Autodesk FBX-SDK before 2017.1 of type mismatches and previously deleted objects related to reading and converting malformed FBX format files can allow attackers to gain access to uninitialized pointers.... Read more
Affected Products : fbx_software_development_kit- EPSS Score: %0.58
- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5594
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the registered user's password, when the debug toolbar is enabled. The password is successfully recovered using this exploit. The SecureLayer7... Read more
Affected Products : pagekit- EPSS Score: %9.42
- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2016-7102
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.... Read more
Affected Products : owncloud_desktop_client- EPSS Score: %0.17
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6920
Heap-based buffer overflow in the decode_block function in libavcodec/exr.c in FFmpeg before 3.1.3 allows remote attackers to cause a denial of service (application crash) via vectors involving tile positions.... Read more
Affected Products : ffmpeg- EPSS Score: %3.62
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6668
The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat plugin 6.26.0 before 7.8.17; and HipChat for JIRA plugin 6.26.0 before 7.8.17 allows remote attackers to o... Read more
- EPSS Score: %1.32
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-1281
Untrusted search path vulnerability in the installer for TrueCrypt 7.2 and 7.1a, VeraCrypt before 1.17-BETA, and possibly other products allows local users to execute arbitrary code with administrator privileges and conduct DLL hijacking attacks via a Tro... Read more
- EPSS Score: %0.23
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6521
Cross-site request forgery (CSRF) vulnerability in Grails console (aka Grails Debug Console and Grails Web Console) 2.0.7, 1.5.10, and earlier allows remote attackers to hijack the authentication of users for requests that execute arbitrary Groovy code vi... Read more
Affected Products : grails- EPSS Score: %0.29
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6484
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the contentType parameter in a login action to config/userAdmin/login.... Read more
Affected Products : netmri- EPSS Score: %0.44
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-8362
Vivint Sky Control Panel 1.1.1.9926 allows remote attackers to enable and disable the alarm system and modify other security settings via the Web-enabled interface.... Read more
- EPSS Score: %2.67
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5182
Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all... Read more
- EPSS Score: %0.99
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025