Latest CVE Feed
-
7.8
HIGHCVE-2017-0382
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote co... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0325
An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9977
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's sessi... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9871
EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected sys... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-9750
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.... Read more
Affected Products : qradar_security_information_and_event_manager- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9737
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
Affected Products : tririga_application_platform- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9730
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.... Read more
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9731
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : business_process_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9694
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : rational_rhapsody_design_manager- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9356
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.... Read more
Affected Products : dacenter- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9333
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTIO... Read more
Affected Products : softcms- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9278
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.... Read more
Affected Products : exynos_fimg2d_driver- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-9225
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting... Read more
Affected Products : asa_cx_context-aware_security_software- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9218
A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0.... Read more
Affected Products : hybrid_meeting_server- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9006
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : urbancode_deploy- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-8925
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.... Read more
Affected Products : tivoli_application_dependency_discovery_manager- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8917
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.... Read more
Affected Products : sterling_selling_and_fulfillment_foundation- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2016-8762
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerabilit... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8761
Video driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a stack overflow vulnerability, which allows attackers to crash the system or escalate user privilege... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2016-8659
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.... Read more
Affected Products : bubblewrap- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025