Latest CVE Feed
-
8.8
HIGHCVE-2015-0104
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, ... Read more
Affected Products : maximo_asset_management maximo_for_life_sciences maximo_for_nuclear_power maximo_for_oil_and_gas maximo_for_transportation maximo_for_utilities change_and_configuration_management_database maximo_asset_management_essentials maximo_for_government tivoli_asset_management_for_it +1 more products- EPSS Score: %2.04
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-2564
Invision Power Services (IPS) Community Suite before 4.1.9 makes session hijack easier by relying on the PHP uniqid function without the more_entropy flag. Attackers can guess an Invision Power Board session cookie if they can predict the exact time of co... Read more
Affected Products : invision_power_board- EPSS Score: %0.29
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8065
crypto/ccm.c in the Linux kernel 4.9.x and 4.10.x through 4.10.12 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact ... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8062
drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspe... Read more
Affected Products : linux_kernel- EPSS Score: %0.12
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8061
drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly ... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-3067
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.... Read more
Affected Products : cygwin- EPSS Score: %0.59
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.... Read more
Affected Products : ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware ex3000 ex5000 +6 more products- EPSS Score: %84.40
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1519
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.... Read more
Affected Products : wave- EPSS Score: %0.23
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1518
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive infor... Read more
Affected Products : wave- EPSS Score: %0.85
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1221
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jetstar- EPSS Score: %0.26
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1210
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : 105_bank- EPSS Score: %0.26
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1198
Photopt for Android before 2.0.1 does not verify SSL certificates.... Read more
Affected Products : photopt- EPSS Score: %0.41
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-1187
Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.... Read more
Affected Products : kunai- EPSS Score: %0.38
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1186
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.... Read more
Affected Products : kintone- EPSS Score: %0.56
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-1558
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, a... Read more
Affected Products : dap-3662_firmware dap-2310_firmware dap-2330_firmware dap-2360_firmware dap-2553_firmware dap-2660_firmware dap-2690_firmware dap-2695_firmware dap-3320_firmware dap-2230_firmware +10 more products- EPSS Score: %14.87
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1556
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.... Read more
Affected Products : wnap320_firmware wnd930_firmware wn604_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wnap320 wndap350 wndap360 wndap210v2 +2 more products- EPSS Score: %0.96
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- EPSS Score: %0.82
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.... Read more
Affected Products : tokyo_star_bank- EPSS Score: %0.23
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.... Read more
Affected Products : akerun- EPSS Score: %0.46
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exis... Read more
Affected Products : documentum_content_server- EPSS Score: %0.67
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025