Latest CVE Feed
-
5.3
MEDIUMCVE-2017-5653
JAX-RS XML Security streaming clients in Apache CXF before 3.1.11 and 3.0.13 do not validate that the service response was signed or encrypted, which allows remote attackers to spoof servers.... Read more
Affected Products : cxf- EPSS Score: %3.17
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2016-3037
IBM Cognos TM1 10.1 and 10.2 provides a service to return the victim's password with a valid session key. An authenticated attacker with user interaction could obtain this sensitive information. IBM X-Force ID: 114613.... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.27
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3036
IBM Cognos TM1 10.1 and 10.2 is vulnerable to a denial of service, caused by a stack-based buffer overflow when parsing packets. A remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 114612.... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %1.18
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-5396
Apache Traffic Server 6.0.0 to 6.2.0 are affected by an HPACK Bomb Attack.... Read more
Affected Products : traffic_server- EPSS Score: %1.81
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6727
The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.... Read more
Affected Products : android- EPSS Score: %5.74
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6726
Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8256
Multiple cross-site scripting (XSS) vulnerabilities in Axis network cameras.... Read more
Affected Products : network_camera_firmware cannon_network_camera explosion-protected_camera fixed_box_camera fixed_bullet_camera fixed_dome_camera modular_camera onboard_camera panoramic_camera ptz_camera +1 more products- EPSS Score: %6.91
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-4874
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to conduct a "reflected file download" attack.... Read more
Affected Products : office- EPSS Score: %0.23
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4867
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restriction to view unauthorized project information via the Project function.... Read more
Affected Products : office- EPSS Score: %0.22
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10331
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.... Read more
Affected Products : photo_station- EPSS Score: %0.39
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8930
Multiple cross-site request forgery (CSRF) vulnerabilities in Simple Invoices 2013.1.beta.8 allow remote attackers to hijack the authentication of admins for requests that can (1) create new administrator user accounts and take over the entire application... Read more
Affected Products : simple_invoices- EPSS Score: %0.12
- Published: May. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0593
An elevation of privilege vulnerability in the Framework APIs could enable a local malicious application to obtain access to custom permissions. This issue is rated as High because it is a general bypass for operating system protections that isolate appli... Read more
Affected Products : android- EPSS Score: %0.02
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5655
In Ambari 2.2.2 through 2.4.2 and Ambari 2.5.0, sensitive data may be stored on disk in temporary files on the Ambari Server host. The temporary files are readable by any user authenticated on the host.... Read more
Affected Products : ambari- EPSS Score: %0.15
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9573
The North Adams State Bank (Ursa) nasb-mobile-banking/id980573797 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : nasb_mobile_bank- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9572
The athens-state-bank-mobile-banking/id719748589 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : athens_state_bank_mobile- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9568
The financial-plus-mobile-banking/id731070564 app 3.0.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : financial_plus_mobile_banking- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9624
Multiple cross-site scripting (XSS) vulnerabilities in Telaxus/EPESI 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via crafted currency decimal-sign data.... Read more
Affected Products : epesi- EPSS Score: %0.22
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-4986
EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : secure_remote_services- EPSS Score: %0.42
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9464
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect... Read more
Affected Products : piwigo- EPSS Score: %0.19
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9463
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data fro... Read more
Affected Products : piwigo- EPSS Score: %0.22
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025