Latest CVE Feed
-
6.8
MEDIUMCVE-2016-7585
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves mishandling of DMA in the "EFI" component. It allows physically proximate attackers to discover the FileVault 2 encryption password via a crafted Thund... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7603
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "CoreStorage" component. It allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7610
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to exe... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-7613
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows attackers to execute arb... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7645
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to exe... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7649
An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to exe... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7658
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. The issue involves the "Audio" component. It allows remote attackers to execute arbitrary code or cause a d... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7798
The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-7837
Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utilities.... Read more
Affected Products : bluez- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7929
The Juniper PPPoE ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-juniper.c:juniper_parse_header().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7935
The RTP parser in tcpdump before 4.9.0 has a buffer overflow in print-udp.c:rtp_print().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7958
In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/CMakeLists.txt by registering this dissector.... Read more
Affected Products : wireshark- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7992
The Classical IP over ATM parser in tcpdump before 4.9.0 has a buffer overflow in print-cip.c:cip_if_print().... Read more
Affected Products : tcpdump- Published: Jan. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8330
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protoco... Read more
Affected Products : solaris- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-8350
An issue was discovered in Moxa ioLogik E1210, firmware Version V2.4 and prior, ioLogik E1211, firmware Version V2.3 and prior, ioLogik E1212, firmware Version V2.4 and prior, ioLogik E1213, firmware Version V2.5 and prior, ioLogik E1214, firmware Version... Read more
Affected Products : iologik_e1200_series_firmware iologik_e2200_series_firmware iologik_e1210 iologik_e1211 iologik_e1212 iologik_e1213 iologik_e1214 iologik_e1240 iologik_e1241 iologik_e1242 +9 more products- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-8652
The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborting authentication without setting a username.... Read more
Affected Products : dovecot- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-8681
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.... Read more
Affected Products : libdwarf- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-8706
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.... Read more
Affected Products : memcached- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-5740
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.... Read more
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3405
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote att... Read more
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025