Latest CVE Feed
-
5.5
MEDIUMCVE-2017-0555
An information disclosure vulnerability in libavc in Mediaserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access data without permission. Produc... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0538
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- EPSS Score: %0.26
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0525
An elevation of privilege vulnerability in the Qualcomm IPA driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proce... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0488
A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. Versions... Read more
Affected Products : android- EPSS Score: %0.28
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0481
An elevation of privilege vulnerability in NFC could enable a proximate attacker to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to elevated capabilities, whic... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0453
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0408
A remote code execution vulnerability in libgdx could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote code execution in an ... Read more
Affected Products : android- EPSS Score: %0.98
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0406
A remote code execution vulnerability in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code execution ... Read more
Affected Products : android- EPSS Score: %1.38
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0392
A denial of service vulnerability in VBRISeeker.cpp in libstagefright in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of se... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0390
A denial of service vulnerability in Tremolo/dpen.s in Mediaserver could enable a remote attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High due to the possibility of remote denial of service. Product: An... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0382
A remote code execution vulnerability in the Framesequence library could enable an attacker using a specially crafted file to execute arbitrary code in the context of an unprivileged process. This issue is rated as High due to the possibility of remote co... Read more
Affected Products : android- EPSS Score: %0.28
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-4673
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via (1) the collection_description parameter to upload/manage_collections.php in an add_new action or the (2)... Read more
Affected Products : clipbucket- EPSS Score: %0.19
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0325
An elevation of privilege vulnerability in the NVIDIA I2C HID driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.18
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9977
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's sessi... Read more
Affected Products : maximo_application_suite maximo_asset_management maximo_asset_management_essentials- EPSS Score: %1.05
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9869
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. Incorrect permissions on the SCINI driver may allow a low-privileged local attacker to modify the configuration and render the ScaleIO Data Client (SDC) server unavailable.... Read more
Affected Products : scaleio- EPSS Score: %0.04
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9871
EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected sys... Read more
- EPSS Score: %0.50
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-9750
IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.34
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9737
IBM TRIRIGA 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9730
IBM QRadar Incident Forensics 7.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 1999549.... Read more
- EPSS Score: %0.11
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9731
IBM Business Process Manager is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted se... Read more
Affected Products : business_process_manager- EPSS Score: %0.23
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025