Latest CVE Feed
-
9.8
CRITICALCVE-2016-4926
Insufficient authentication vulnerability in Junos Space before 15.2R2 allows remote network based users with access to Junos Space web interface to perform certain administrative tasks without authentication.... Read more
- EPSS Score: %3.64
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9072
In all Qualcomm products with Android releases from CAF using the Linux kernel, an untrusted pointer dereference can occur in a TrustZone syscall.... Read more
Affected Products : android- EPSS Score: %0.13
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2819
An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902. A specially crafted document stream can cause an integer underflow resulting in a buffer overflow which... Read more
- EPSS Score: %0.64
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-2785
An exploitable buffer overflow exists in the psnotifyd application of the Pharos PopUp printer client version 9.0. A specially crafted packet can be sent to the victim's computer and can lead to a heap based buffer overflow resulting in remote code execut... Read more
Affected Products : popup- EPSS Score: %16.09
- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9067
In all Qualcomm products with Android releases from CAF using the Linux kernel, a potential compiler optimization of memset() is addressed.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9061
In all Qualcomm products with Android releases from CAF using the Linux kernel, playReady DRM failed to check a length potentially leading to unauthorized access to secure memory.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2709
HiGame with software earlier than 7.3.0 versions, SkyTone with software earlier than 8.1.1 versions have a DoS Vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, the attacker can send malformed packets to ... Read more
- EPSS Score: %0.08
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4547
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.... Read more
Affected Products : samsung_mobile- EPSS Score: %0.56
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2213
Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : semidynaexe- EPSS Score: %0.14
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2325
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.... Read more
Affected Products : northstar_controller- EPSS Score: %0.49
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2253
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : toolbar- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12907
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-2141
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.... Read more
- EPSS Score: %0.48
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2126
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors.... Read more
- EPSS Score: %13.46
- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2090
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %3.37
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-3403
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove account... Read more
Affected Products : zimbra_collaboration_suite- EPSS Score: %2.57
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12783
The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.... Read more
- EPSS Score: %0.62
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3091
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.... Read more
Affected Products : diego- EPSS Score: %0.56
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2016-3021
IBM Security Access Manager for Web could allow an authenticated attacker to obtain sensitive information from error message using a specially crafted HTTP request.... Read more
- EPSS Score: %0.07
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9631
A Null Pointer Dereference issue was discovered in Schneider Electric Wonderware ArchestrA Logger, versions 2017.426.2307.1 and prior. The null pointer dereference vulnerability could allow an attacker to crash the logger process, causing a denial of serv... Read more
Affected Products : wonderware_archestra_logger- EPSS Score: %0.87
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025