Latest CVE Feed
-
9.1
CRITICALCVE-2016-9121
go-jose before 1.0.4 suffers from an invalid curve attack for the ECDH-ES algorithm. When deriving a shared key using ECDH-ES for an encrypted message, go-jose neglected to check that the received public key on a message is on the same curve as the static... Read more
Affected Products : go-jose- EPSS Score: %0.22
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5623
An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fastboot oem boot_mode {rf/wlan/ftm/normal} command' in contradiction to the threat model of Android where the... Read more
- EPSS Score: %0.05
- Published: Mar. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9036
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows local users to gain privileges by leveraging an unrestricted quarantine directory.... Read more
Affected Products : serverprotect- EPSS Score: %0.10
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0505
An elevation of privilege vulnerability in MediaTek components, including the M4U driver, sound driver, touchscreen driver, GPU driver, and Command Queue driver, could enable a local malicious application to execute arbitrary code within the context of th... Read more
Affected Products : android- EPSS Score: %3.78
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0306
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6653
A vulnerability in the TCP throttling process for the GUI of the Cisco Identity Services Engine (ISE) 2.1(0.474) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device where the ISE GUI may fail ... Read more
Affected Products : identity_services_engine- EPSS Score: %0.75
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6647
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Temporary File information on an affected system. The vulnerability exists because the affected softwar... Read more
Affected Products : remote_expert_manager- EPSS Score: %0.37
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6642
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not suff... Read more
Affected Products : remote_expert_manager- EPSS Score: %0.37
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8483
An information disclosure vulnerability in the Qualcomm power driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit... Read more
- EPSS Score: %0.28
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5173
An Improper Neutralization of Special Elements (in an OS command) issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An improper neutralization of special elements vulnerability has been identified. If special elements are not ... Read more
- EPSS Score: %80.50
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5915
The Emirates NBD Bank P.J.S.C Emirates NBD KSA app 3.10.0 through 3.10.4 (UAE) and 2.0.1 through 2.1.0 (KSA) for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive inform... Read more
- EPSS Score: %0.12
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2116
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to delete "customapp" templates via unspecified vectors.... Read more
Affected Products : office- EPSS Score: %0.20
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2115
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.... Read more
Affected Products : office- EPSS Score: %0.12
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7221
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by leveraging the availability of the dm_bp_transition docbase me... Read more
Affected Products : documentum_content_server- EPSS Score: %1.72
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-8769
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service query paths. An attacker may put an executable file in the search path of the affected service and obtain el... Read more
Affected Products : utps_firmware- EPSS Score: %0.42
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8757
ION memory management module in Huawei P9 phones with software EVA-AL10C00B192 and earlier versions, EVA-DL10C00B192 and earlier versions, EVA-TL10C00B192 and earlier versions, EVA-CL10C00B192 and earlier versions allows attackers to obtain sensitive info... Read more
- EPSS Score: %0.08
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-9136
Huawei FusionManager with software V100R002C03 and V100R003C00 could allow an unauthenticated, remote attacker to conduct a CSRF attack against the user of the web interface.... Read more
Affected Products : usg9500_firmware fusionmanager usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware usg2100 usg2200 usg5100 usg5500 +1 more products- EPSS Score: %0.09
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9733
IBM Team Concert (RTC) 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a... Read more
- EPSS Score: %0.27
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9701
IBM Team Concert 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
- EPSS Score: %0.27
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10804
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database lay... Read more
Affected Products : odoo- EPSS Score: %0.88
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025