Latest CVE Feed
-
6.1
MEDIUMCVE-2016-8215
EMC RSA Security Analytics 10.5.3 and 10.6.2 contains fixes for a Reflected Cross-Site Scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : rsa_security_analytics- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-8005
File extension filtering vulnerability in Intel Security McAfee Email Gateway (MEG) before 7.6.404h1128596 allows attackers to fail to identify the file name properly via scanning an email with a forged attached filename that uses a null byte within the f... Read more
Affected Products : email_gateway- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-6028
IBM Jazz technology based products might allow an attacker to view work item titles that they do not have privilege to view.... Read more
Affected Products : rational_collaborative_lifecycle_management- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7834
SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM550, SNC-ZM551, SNC-EP550, SNC-EP580, SNC-ER550, SNC-ER550C, SNC-ER580, SNC-E... Read more
Affected Products : snc_series_firmware snc-cx600 snc-cx600w snc-eb600 snc-eb600b snc-eb602r snc-eb630 snc-eb630b snc-eb632r snc-em600 +71 more products- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7789
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7791
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which le... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7790
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-7150
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.... Read more
Affected Products : b2evolution- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2016-6769
An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-6884
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.... Read more
Affected Products : matrixssl- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6874
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.... Read more
Affected Products : hhvm- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6777
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6594
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6125
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : kenexa_lms_on_cloud- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume a... Read more
Affected Products : infosphere_information_server infosphere_information_server_on_cloud infosphere_datastage- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6045
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6022
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5896
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2016-5894
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.... Read more
Affected Products : websphere_commerce- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-5862
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a dev... Read more
Affected Products : android- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025