Latest CVE Feed
-
9.8
CRITICALCVE-2016-3067
Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.... Read more
Affected Products : cygwin- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1561
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image.... Read more
Affected Products : ex3000_firmware ex5000_firmware ex7000_firmware ex10000e_firmware ex13000e_firmware ex21000e_firmware ex32000e_firmware ex40000e_firmware ex3000 ex5000 +6 more products- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1519
The com.softphone.common package in the Grandstream Wave app 1.0.1.26 and earlier for Android does not properly validate SSL certificates, which allows man-in-the-middle attackers to spoof the Grandstream provisioning server via a crafted certificate.... Read more
Affected Products : wave- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1221
Jetstar App for iOS before 3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : jetstar- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-1187
Cybozu KUNAI for iPhone 2.0.3 through 3.1.5 and for Android 2.1.2 through 3.0.4 does not verify SSL certificates.... Read more
Affected Products : kunai- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-1558
Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, a... Read more
Affected Products : dap-3662_firmware dap-2310_firmware dap-2330_firmware dap-2360_firmware dap-2553_firmware dap-2660_firmware dap-2690_firmware dap-2695_firmware dap-3320_firmware dap-2230_firmware +10 more products- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1556
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.... Read more
Affected Products : wnap320_firmware wnd930_firmware wn604_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wnap320 wndap350 wndap360 wndap210v2 +2 more products- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-6615
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when ... Read more
Affected Products : ios_xe- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9978
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.... Read more
Affected Products : curam_social_program_management- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4862
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.... Read more
Affected Products : cs-cart- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-4850
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.... Read more
Affected Products : line- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1216
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5762
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.... Read more
Affected Products : groupwise- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5409
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.... Read more
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7978
Samsung Android devices with L(5.0/5.1), M(6.0), and N(7.x) software allow attackers to obtain sensitive information by reading a world-readable log file after an unexpected reboot. The Samsung ID is SVE-2017-8290.... Read more
Affected Products : samsung_mobile- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6727
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.... Read more
Affected Products : android- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8256
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.... Read more
Affected Products : network_camera_firmware cannon_network_camera explosion-protected_camera fixed_box_camera fixed_bullet_camera fixed_dome_camera modular_camera onboard_camera panoramic_camera ptz_camera +1 more products- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0593
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate appli... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.... Read more
Affected Products : ambari- Published: May. 15, 2017
- Modified: Apr. 20, 2025