Latest CVE Feed
-
7.8
HIGHCVE-2016-5857
The Qualcomm SPCom driver in Android before 7.0 allows local users to execute arbitrary code within the context of the kernel via a crafted application, aka Android internal bug 34386529 and Qualcomm internal bug CR#1094140.... Read more
Affected Products : android- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-5876
ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct request.... Read more
Affected Products : owncloud- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9946
In Core Kernel in all Android releases from CAF using the Linux kernel, a Use After Free vulnerability could potentially exist.... Read more
Affected Products : android- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5752
The SAML2 implementation in Identity Server in NetIQ Access Manager 4.1 before 4.1.2 HF1 and 4.2 before 4.2.2 was handling unsigned SAML requests incorrectly, leaking results to a potentially malicious "Assertion Consumer Service URL" instead of the origi... Read more
Affected Products : access_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4987
Directory traversal vulnerability in the Image Gallery plugin before 1.4 in Jenkins allows remote attackers to list arbitrary directories and read arbitrary files via unspecified form fields.... Read more
Affected Products : image_gallery- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-9137
Huawei USG9500 with software V200R001C01SPC800 and earlier versions, V300R001C00; USG2100 with software V300R001C00SPC900 and earlier versions; USG2200 with software V300R001C00SPC900; USG5100 with software V300R001C00SPC900 could allow an unauthenticated... Read more
Affected Products : usg9500_firmware fusionmanager usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware usg2100 usg2200 usg5100 usg5500 +1 more products- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4948
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera Manager 5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Template Name field when renaming a template; (2) KDC Server host, (3) Kerberos Security Real... Read more
Affected Products : manager- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4859
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0... Read more
Affected Products : splunk- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4884
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Blog version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : basercms- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-4870
Cross-site scripting vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to inject arbitrary web script or HTML via the Schedule function.... Read more
Affected Products : office- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4868
Email header injection vulnerability in Cybozu Office 9.0.0 to 10.4.0 allows remote attackers to inject arbitrary email headers to send unintended emails via specially crafted requests.... Read more
Affected Products : office- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4841
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.... Read more
Affected Products : mailwise- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4844
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.... Read more
Affected Products : mailwise- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4305
A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially crafted native api call can cause a access violation in KLIF kernel driver resulting in local denial of service. An att... Read more
Affected Products : internet_security- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3996
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.... Read more
Affected Products : knox- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3038
IBM Cognos TM1 10.1 and 10.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : cognos_business_intelligence- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1217
Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10316
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the return-url parameter to... Read more
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10275
An elevation of privilege vulnerability in the Qualcomm bootloader could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
Affected Products : android- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-10103
Information Disclosure can occur in encryptionProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for GPG Encryption profiles. Verified in all 10.x versions up... Read more
Affected Products : automize- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025