Latest CVE Feed
-
4.3
MEDIUMCVE-2016-4910
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4909
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4908
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4907
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4906
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-4902
Untrusted search path vulnerability in The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.0.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vist... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-7469
A stored cross-site scripting (XSS) vulnerability in the Configuration utility device name change page in BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, PSM, WebAccelerator, WOM and WebSafe version 12.0.0 - 12.1.2... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +6 more products- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9523
The Sophos Web Appliance before 4.3.2 has XSS in the FTP redirect page, aka NSWA-1342.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1319
IBM Tivoli Federated Identity Manager 6.2 is affected by a vulnerability due to a missing secure attribute in encrypted session (SSL) cookie. IBM X-Force ID: 125731.... Read more
Affected Products : tivoli_federated_identity_manager- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-1179
IBM BigFix Compliance Analytics 1.9.79 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 123431.... Read more
Affected Products : bigfix_security_compliance_analytics- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1140
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : business_process_manager- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-9991
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9736
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.... Read more
Affected Products : websphere_application_server- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-9698
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume a... Read more
Affected Products : rational_rhapsody_design_manager- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8987
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-6098
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6093
IBM Tivoli Key Lifecycle Manager does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3913
The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request message.... Read more
Affected Products : s3300_firmware s12700_firmware s2300_firmware s2700_firmware s7700_firmware s9300_firmware s9700_firmware s3700_firmware s2350ei_firmware s5300ei_firmware +34 more products- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3634
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.... Read more
Affected Products : slideshow- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2015-2692
AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.... Read more
Affected Products : adblock- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025