Latest CVE Feed
-
4.3
MEDIUMCVE-2015-2246
The MeWidget module on Huawei P7 smartphones with software P7-L10 V100R001C00B136 and earlier versions could lead to the disclosure of contact information.... Read more
- EPSS Score: %0.09
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-8011
Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.... Read more
Affected Products : endpoint_security_web_control- EPSS Score: %0.30
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-7835
Use-after-free vulnerability in H2O allows remote attackers to cause a denial-of-service (DoS) or obtain server certificate private keys and possibly other information.... Read more
- EPSS Score: %3.16
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7614
An issue was discovered in certain Apple products. iCloud before 6.1 is affected. The issue involves the "Windows Security" component. It allows local users to obtain sensitive information from iCloud desktop-client process memory via unspecified vectors.... Read more
Affected Products : icloud- EPSS Score: %0.13
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7400
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, o... Read more
Affected Products : exponent_cms- EPSS Score: %18.22
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-7144
The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.... Read more
Affected Products : unrealircd- EPSS Score: %2.39
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2016-7060
The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display.... Read more
Affected Products : quickstart_cloud_installer- EPSS Score: %0.08
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6916
Integer overflow in nvhost_job.c in the NVIDIA video driver for Android, Shield TV before OTA 3.3, Shield Table before OTA 4.4, and Shield Table TK1 before OTA 1.5 allows local users to cause a denial of service (system crash) via unspecified vectors, whi... Read more
- EPSS Score: %0.05
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6887
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via a CRT attack.... Read more
Affected Products : matrixssl- EPSS Score: %0.30
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6879
The X509_Certificate::allowed_usage function in botan 1.11.x before 1.11.31 might allow attackers to have unspecified impact by leveraging a call with more than one Key_Usage set in the enum value.... Read more
Affected Products : botan- EPSS Score: %0.18
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6103
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.15
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6095
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.39
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6800
The default configuration of the Apache OFBiz framework offers a blog functionality. Different users are able to operate blogs which are related to specific parties. In the form field for the creation of new blog articles the user input of the summary fie... Read more
Affected Products : ofbiz- EPSS Score: %2.35
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6772
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process. ... Read more
Affected Products : android- EPSS Score: %1.44
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6522
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.... Read more
- EPSS Score: %0.08
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2015-0238
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.... Read more
- EPSS Score: %0.04
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-6269
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt... Read more
Affected Products : smart_protection_server- EPSS Score: %1.85
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6244
The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negative "ts.tv_sec" value.... Read more
- EPSS Score: %1.05
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6062
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
Affected Products : resilient- EPSS Score: %0.24
- Published: Feb. 16, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2016-6040
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.19
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025