Latest CVE Feed
-
7.6
HIGHCVE-2016-8451
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privile... Read more
- EPSS Score: %0.24
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8445
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it fi... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8424
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
Affected Products : linux_kernel- EPSS Score: %0.26
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-8375
An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7, and 8000 PC unit. An unauthorized user with physical access to an affected Alaris PC unit may be able to ob... Read more
Affected Products : alaris_8015_pc_unit- EPSS Score: %0.45
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2016-8355
An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database, which would allow an authenticated... Read more
Affected Products : cadd-solis_medication_safety_software- EPSS Score: %0.39
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2016-8354
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulat... Read more
Affected Products : unity_pro- EPSS Score: %0.16
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2016-8312
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.76
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8218
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to ... Read more
- EPSS Score: %0.58
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7840
Cross-site scripting vulnerability in WEB SCHEDULE allows remote attackers to inject arbitrary web script or HTML via the month parameter.... Read more
Affected Products : olive_blog- EPSS Score: %0.20
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7808
Cross-site scripting vulnerability in Corega CG-WLBARGMH and CG-WLBARGNL allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.32
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-7062
rhscon-ceph in Red Hat Storage Console 2 x86_64 and Red Hat Storage Console Node 2 x86_64 allows local users to obtain the password as cleartext.... Read more
- EPSS Score: %0.07
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6875
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.... Read more
Affected Products : hhvm- EPSS Score: %0.46
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6789
An elevation of privilege vulnerability in the NVIDIA libomx library (libnvomx) could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain l... Read more
- EPSS Score: %0.16
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6784
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. ... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-6755
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- EPSS Score: %0.20
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-6236
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.... Read more
Affected Products : lepton- EPSS Score: %0.21
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6099
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.... Read more
Affected Products : security_key_lifecycle_manager- EPSS Score: %0.19
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2016-5979
IBM Distributed Marketing 8.6, 9.0, and 10.0 could allow a privileged authenticated user to create an instance that gets created with security profile not valid for the templates, that results in the new instance not accessible for the intended user. IBM ... Read more
Affected Products : distributed_marketing- EPSS Score: %0.24
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-5948
IBM Kenexa LCMS Premier on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.23
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2016-5941
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.... Read more
- EPSS Score: %0.47
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025