Latest CVE Feed
-
3.3
LOWCVE-2016-4670
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "Security" component. It allows local users to discover lengths of arbitrary passwords by reading a log.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Kernel" component. It allows local users to execute a... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4667
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ATS" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a ... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4666
An issue was discovered in certain Apple products. iOS before 10.1 is affected. Safari before 10.0.1 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a de... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4665
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read audio-recording metadata vi... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4664
An issue was discovered in certain Apple products. iOS before 10.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "Sandbox Profiles" component, which allows attackers to read photo-directory metadata vi... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4663
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "NVIDIA Graphics Drivers" component. It allows attackers to cause a denial of service (memory corruption) via a crafted app.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-4662
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "AppleGraphicsControl" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrup... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-4661
An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk images and allows attackers to cause a denial of service via a crafted app.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-4660
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. watchOS before 3.1 is affected. The issue involves the "FontParser" component. It allows remote attackers to ... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4617
An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process spawning in the "libxpc" component.... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4613
An issue was discovered in certain Apple products. Safari before 10.0.1 is affected. iCloud before 6.0.1 is affected. iTunes before 12.5.2 is affected. tvOS before 10.0.1 is affected. The issue involves the "WebKit" component. It allows remote attackers t... Read more
- Published: Feb. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6074
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free... Read more
- Published: Feb. 18, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-6001
Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vul... Read more
Affected Products : linux_kernel- Published: Feb. 18, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5986
Race condition in the sctp_wait_for_sndbuf function in net/sctp/socket.c in the Linux kernel before 4.9.11 allows local users to cause a denial of service (assertion failure and panic) via a multithreaded application that peels off an association in a cer... Read more
Affected Products : linux_kernel- Published: Feb. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6065
SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.... Read more
Affected Products : genixcms- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6055
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrary files or possibly have unspecified other impact via a crafted edoc file.... Read more
Affected Products : eparakstitajs_3- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-7511
Integer overflow in the dwarf_die_deliv.c in libdwarf 20160613 allows remote attackers to cause a denial of service (crash) via a crafted file.... Read more
Affected Products : libdwarf- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7510
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.... Read more
Affected Products : libdwarf- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-7111
MantisBT before 1.3.1 and 2.x before 2.0.0-beta.2 uses a weak Content Security Policy when using the Gravatar plugin, which allows remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.... Read more
Affected Products : mantisbt- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025