Latest CVE Feed
-
7.1
HIGHCVE-2016-3108
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.... Read more
Affected Products : pulp- EPSS Score: %0.04
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-2800
The user authentication module in Huawei Campus switches S5700, S5300, S6300, and S6700 with software before V200R001SPH012 and S7700, S9300, and S9700 with software before V200R001SPH015 allows remote attackers to cause a denial of service (device restar... Read more
Affected Products : s5300_firmware s5700_firmware s6300_firmware s6700_firmware s7700_firmware s9300_firmware s9700_firmware campus_s5300 campus_s5700 campus_s6300 +4 more products- EPSS Score: %2.80
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2015-2253
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.... Read more
- EPSS Score: %0.08
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-2252
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.... Read more
- EPSS Score: %0.47
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-2251
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.... Read more
- EPSS Score: %0.14
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICAL- EPSS Score: %4.15
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9983
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.... Read more
Affected Products : rar- EPSS Score: %0.26
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7966
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.... Read more
Affected Products : somachine- EPSS Score: %0.98
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1125
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.... Read more
- EPSS Score: %0.05
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5960
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.... Read more
Affected Products : security_privileged_identity_manager- EPSS Score: %0.06
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5959
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For... Read more
Affected Products : security_privileged_identity_manager- EPSS Score: %0.22
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-3019
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.... Read more
- EPSS Score: %0.13
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-7723
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.... Read more
Affected Products : fglrx-driver- EPSS Score: %0.03
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7312
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).... Read more
Affected Products : personify360- EPSS Score: %8.33
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-0768
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.... Read more
Affected Products : postgresql- EPSS Score: %0.24
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-0767
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.... Read more
Affected Products : pl\/java- EPSS Score: %0.12
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9420
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.... Read more
Affected Products : spiffy_calendar- EPSS Score: %0.41
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-3830
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8083
CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges... Read more
- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9005
In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025