Latest CVE Feed
-
6.9
MEDIUMCVE-2017-3749
On Lenovo VIBE mobile phones, the Idea Friend Android application allows private data to be backed up and restored via Android Debug Bridge, which allows tampering leading to privilege escalation in conjunction with CVE-2017-3748 and CVE-2017-3750.... Read more
Affected Products : android vibe_a1600 vibe_a2560 vibe_a2800 vibe_a2860 vibe_a2880 vibe_a3000 vibe_a3500 vibe_a3600-d vibe_a3600u +11 more products- EPSS Score: %0.01
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6768
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote co... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4964
Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."... Read more
Affected Products : bosh_azure_cpi- EPSS Score: %0.16
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4961
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on t... Read more
Affected Products : bosh- EPSS Score: %0.20
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-6122
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 discloses answers to security questions in a response to authenticated users.... Read more
Affected Products : kenexa_lms_on_cloud- EPSS Score: %0.18
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-4897
VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. ... Read more
Affected Products : horizon_daas- EPSS Score: %0.11
- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10392
In all Qualcomm products with Android releases from CAF using the Linux kernel, a driver can potentially leak kernel memory.... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10386
In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10334
In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.... Read more
Affected Products : android- EPSS Score: %0.08
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-0121
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.... Read more
- EPSS Score: %1.53
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-0115
Directory traversal vulnerability in the log viewer in Apache Storm 0.9.0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to log.... Read more
Affected Products : storm- EPSS Score: %0.66
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-0073
The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers,... Read more
- EPSS Score: %11.44
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10297
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2014-0043
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is ... Read more
Affected Products : wicket- EPSS Score: %0.79
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2013-7430
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.... Read more
Affected Products : googlemaps- EPSS Score: %0.26
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10181
An issue was discovered on the D-Link DWR-932B router. qmiweb provides sensitive information for CfgType=get_homeCfg requests.... Read more
- EPSS Score: %12.07
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6601
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to read arbitrary files via a .. (dot dot) in the fileName parameter to servlets/FetchFile.... Read more
Affected Products : webnms_framework- EPSS Score: %92.78
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-6560
illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.... Read more
Affected Products : illumos- EPSS Score: %0.48
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-3812
A vulnerability in the implementation of Common Industrial Protocol (CIP) functionality in Cisco Industrial Ethernet 2000 Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition due to a system memory l... Read more
Affected Products : industrial_ethernet_2000_series_firmware industrial_ethernet_2000_series_firmware industrial_ethernet_2000_16ptc-g-e_switch industrial_ethernet_2000_16ptc-g-l_switch industrial_ethernet_2000_16ptc-g-nx_switch industrial_ethernet_2000_16t67-b_switch industrial_ethernet_2000_16t67p-g-e_switch industrial_ethernet_2000_16tc-g-e_switch industrial_ethernet_2000_16tc-g-l_switch industrial_ethernet_2000_16tc-g-n_switch +21 more products- EPSS Score: %0.69
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2013-6648
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).... Read more
Affected Products : skia- EPSS Score: %0.38
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025