Latest CVE Feed
-
5.4
MEDIUMCVE-2016-9694
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust... Read more
Affected Products : rational_rhapsody_design_manager- EPSS Score: %0.23
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-9682
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component respons... Read more
Affected Products : sonicwall_secure_remote_access_server- EPSS Score: %21.42
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
3.1
LOWCVE-2016-9471
Revive Adserver before 3.2.5 and 4.0.0 suffers from Special Element Injection. Usernames weren't properly sanitised when creating users on a Revive Adserver instance. Especially, control characters were not filtered, allowing apparently identical username... Read more
Affected Products : revive_adserver- EPSS Score: %0.27
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9356
An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue.... Read more
Affected Products : dacenter- EPSS Score: %0.08
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9333
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. The SoftCMS Application does not properly sanitize input that may allow a remote attacker access to SoftCMS with administrator's privilege through specially crafted input (SQL INJECTIO... Read more
Affected Products : softcms- EPSS Score: %0.66
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9278
The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) via a crafted ioctl command. The Samsung ID is SVE-2016-6736.... Read more
Affected Products : exynos_fimg2d_driver- EPSS Score: %0.06
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-9225
A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an unauthenticated, remote attacker to cause the CX module to be unable to process further traffic, resulting... Read more
Affected Products : asa_cx_context-aware_security_software- EPSS Score: %1.38
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9218
A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0.... Read more
Affected Products : hybrid_meeting_server- EPSS Score: %0.19
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9006
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : urbancode_deploy- EPSS Score: %0.26
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8951
IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. I... Read more
Affected Products : emptoris_strategic_supply_management- EPSS Score: %0.67
- Published: Jul. 13, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-8925
IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.... Read more
Affected Products : tivoli_application_dependency_discovery_manager- EPSS Score: %0.21
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8917
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.... Read more
Affected Products : sterling_selling_and_fulfillment_foundation- EPSS Score: %0.15
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2016-8762
The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier versions and P8 Lite with software ALE-L02C636B150 and earlier versions has an input validation vulnerabilit... Read more
- EPSS Score: %0.03
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8761
Video driver in Huawei P9 phones with software versions before EVA-AL10C00B192 and Huawei Honor 6 phones with software versions before H60-L02_6.10.1 has a stack overflow vulnerability, which allows attackers to crash the system or escalate user privilege... Read more
- EPSS Score: %0.06
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2016-8659
Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated by sending commands to a PrivSep socket.... Read more
Affected Products : bubblewrap- EPSS Score: %0.06
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8477
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. ... Read more
- EPSS Score: %0.28
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-8315
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure Code). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerabi... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.39
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8474
An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged proces... Read more
- EPSS Score: %0.23
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8469
An information disclosure vulnerability in the camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: ... Read more
- EPSS Score: %0.23
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8468
An elevation of privilege vulnerability in Binder could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as Moderate because it first requires compromising a privileged process ... Read more
- EPSS Score: %0.24
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025