Latest CVE Feed
-
3.3
LOWCVE-2015-0238
selinux-policy as packaged in Red Hat OpenShift 2 allows attackers to obtain process listing information via a privilege escalation attack.... Read more
- EPSS Score: %0.04
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-6269
Multiple directory traversal vulnerabilities in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allow remote attackers to read and delete arbitrary files via the tmpfname parameter to (1) log_mgt... Read more
Affected Products : smart_protection_server- EPSS Score: %1.85
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6244
The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negative "ts.tv_sec" value.... Read more
- EPSS Score: %1.05
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6062
IBM Resilient v26.0, v26.1, and v26.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
Affected Products : resilient- EPSS Score: %0.24
- Published: Feb. 16, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2016-6040
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.19
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6031
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure ... Read more
- EPSS Score: %0.23
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6033
IBM Tivoli Storage Manager for Virtual Environments 7.1 (VMware) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1995... Read more
- EPSS Score: %0.15
- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6000
IBM TRIRIGA Application Platform is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.24
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-5854
In a driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, kernel heap memory can be exposed to userspace.... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-5857
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-5876
ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct request.... Read more
Affected Products : owncloud- EPSS Score: %0.30
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-5822
Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted HTTP packets.... Read more
Affected Products : oceanstor_5800_v3- EPSS Score: %0.37
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9946
In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5752
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the origi... Read more
Affected Products : access_manager- EPSS Score: %0.30
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4987
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.... Read more
Affected Products : image_gallery- EPSS Score: %0.43
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-9137
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated... Read more
Affected Products : usg9500_firmware fusionmanager usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware usg2100 usg2200 usg5100 usg5500 +1 more products- EPSS Score: %0.09
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4948
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a template; (2) KDC Server host, (3) Kerberos Security Real... Read more
Affected Products : manager- EPSS Score: %0.10
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4859
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0... Read more
Affected Products : splunk- EPSS Score: %0.23
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4884
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.12
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4896
SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.... Read more
Affected Products : setucocms- EPSS Score: %0.27
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025