Latest CVE Feed
-
7.1
HIGHCVE-2016-9993
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Referen... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.16
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0404
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- EPSS Score: %0.33
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0391
A denial of service vulnerability in decoder/ihevcd_decode.c in libhevc in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of ... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0385
An elevation of privilege vulnerability in Audioserver could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated c... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-4697
Cross-site request forgery (CSRF) vulnerability in Google Analyticator Wordpress Plugin before 6.4.9.3 rev @1183563.... Read more
Affected Products : google_analyticator- EPSS Score: %0.21
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0337
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.25
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0335
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.25
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0329
An elevation of privilege vulnerability in the NVIDIA boot and power management processor driver could enable a local malicious application to execute arbitrary code within the context of the boot and power management processor. This issue is rated as Hig... Read more
- EPSS Score: %0.18
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0152
A remote code execution vulnerability exists in the way affected Microsoft scripting engine render when handling objects in memory in Microsoft browsers. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in... Read more
Affected Products : edge- EPSS Score: %14.55
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9985
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.05
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9984
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.... Read more
- EPSS Score: %2.59
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9825
libswscale/utils.c in libav 11.8 allows remote attackers to cause a denial of service (crash) via vectors involving left shift of a negative value.... Read more
Affected Products : libav- EPSS Score: %0.21
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-9683
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/cgi-bin/extensionsettings) component... Read more
Affected Products : sonicwall_secure_remote_access_server- EPSS Score: %21.97
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-4046
The asset discovery scanner in AlienVault OSSIM before 5.0.1 allows remote authenticated users to execute arbitrary commands via the assets array parameter to netscan/do_scan.php.... Read more
Affected Products : open_source_security_information_management- EPSS Score: %6.20
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9720
IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Reference #: 1999533.... Read more
- EPSS Score: %0.21
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9704
IBM Security Identity Manager Virtual Appliance is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure ... Read more
Affected Products : security_identity_manager_virtual_appliance- EPSS Score: %0.25
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9347
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell)... Read more
- EPSS Score: %0.12
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-9463
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticatin... Read more
- EPSS Score: %3.86
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-4979
EMC Isilon OneFS 8.0.1.0, OneFS 8.0.0.0 - 8.0.0.2, OneFS 7.2.1.0 - 7.2.1.3, and OneFS 7.2.0.x is affected by an NFS export vulnerability. Under certain conditions, after upgrading a cluster from OneFS 7.1.1.x or earlier, users may have unexpected levels o... Read more
- EPSS Score: %0.35
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4980
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system. Affected versions are 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3, and 8.0.0 - 8.0.0.1.... Read more
- EPSS Score: %2.68
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025