Latest CVE Feed
-
9.3
HIGHCVE-2015-2252
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.... Read more
- EPSS Score: %0.47
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-2251
The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information via a crafted UDS patch with JavaScript.... Read more
- EPSS Score: %0.14
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICAL- EPSS Score: %4.15
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9983
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.... Read more
Affected Products : rar- EPSS Score: %0.26
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7966
A DLL Hijacking vulnerability in the programming software in Schneider Electric's SoMachine HVAC v2.1.0 allows a remote attacker to execute arbitrary code on the targeted system. The vulnerability exists due to the improper loading of a DLL.... Read more
Affected Products : somachine- EPSS Score: %0.98
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1125
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340.... Read more
- EPSS Score: %0.05
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-5960
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171.... Read more
Affected Products : security_privileged_identity_manager- EPSS Score: %0.06
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5959
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-For... Read more
Affected Products : security_privileged_identity_manager- EPSS Score: %0.22
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-3019
IBM Security Access Manager for Web 9.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 114462.... Read more
- EPSS Score: %0.13
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-7723
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.... Read more
Affected Products : fglrx-driver- EPSS Score: %0.03
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7312
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read existing vendor account data (including usernames and passwords).... Read more
Affected Products : personify360- EPSS Score: %8.33
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-0768
PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.... Read more
Affected Products : postgresql- EPSS Score: %0.24
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-0767
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.... Read more
Affected Products : pl\/java- EPSS Score: %0.12
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9420
Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter.... Read more
Affected Products : spiffy_calendar- EPSS Score: %0.41
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-3830
The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a victim by displaying a malicious page for legitimate domain names.... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8083
CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges... Read more
- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9005
In TrustZone in all Android releases from CAF using the Linux kernel, an Integer Overflow to Buffer Overflow vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9952
In the Secure File System in all Android releases from CAF using the Linux kernel, a capture-replay vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-9951
In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9948
In TrustZone in all Android releases from CAF using the Linux kernel, an Improper Validation of Array Index vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025