Latest CVE Feed
-
7.8
HIGHCVE-2017-8062
drivers/media/usb/dvb-usb/dw2102.c in the Linux kernel 4.9.x and 4.10.x before 4.10.4 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspe... Read more
Affected Products : linux_kernel- EPSS Score: %0.12
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8061
drivers/media/usb/dvb-usb/dvb-usb-firmware.c in the Linux kernel 4.9.x and 4.10.x before 4.10.7 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly ... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-3067
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.... Read more
Affected Products : cygwin- EPSS Score: %0.59
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.... Read more
Affected Products : ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware ex3000 ex5000 +6 more products- EPSS Score: %84.40
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1519
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.... Read more
Affected Products : wave- EPSS Score: %0.23
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1518
The auto-provisioning mechanism in the Grandstream Wave app 1.0.1.26 and earlier for Android and Grandstream Video IP phones allows man-in-the-middle attackers to spoof provisioning data and consequently modify device functionality, obtain sensitive infor... Read more
Affected Products : wave- EPSS Score: %0.85
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1221
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jetstar- EPSS Score: %0.26
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1210
The 105 BANK app 1.0 and 1.1 for Android and 1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : 105_bank- EPSS Score: %0.26
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1198
Photopt for Android before 2.0.1 does not verify SSL certificates.... Read more
Affected Products : photopt- EPSS Score: %0.41
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-1187
Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.... Read more
Affected Products : kunai- EPSS Score: %0.38
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1186
Kintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.... Read more
Affected Products : kintone- EPSS Score: %0.56
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-1558
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, a... Read more
Affected Products : dap-3662_firmware dap-2310_firmware dap-2330_firmware dap-2360_firmware dap-2553_firmware dap-2660_firmware dap-2690_firmware dap-2695_firmware dap-3320_firmware dap-2230_firmware +10 more products- EPSS Score: %14.87
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1556
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.... Read more
Affected Products : wnap320_firmware wnd930_firmware wn604_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wnap320 wndap350 wndap360 wndap210v2 +2 more products- EPSS Score: %0.96
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- EPSS Score: %0.82
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.... Read more
Affected Products : tokyo_star_bank- EPSS Score: %0.23
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.... Read more
Affected Products : akerun- EPSS Score: %0.46
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exis... Read more
Affected Products : documentum_content_server- EPSS Score: %0.67
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-6615
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when ... Read more
Affected Products : ios_xe- EPSS Score: %0.45
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-4969
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks.... Read more
Affected Products : cf-release- EPSS Score: %0.38
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-1122
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.... Read more
Affected Products : security_guardium- EPSS Score: %0.05
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025