Latest CVE Feed
-
6.5
MEDIUMCVE-2016-5548
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111. Easily exploitable vulnerability allows unauthenticate... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5547
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Easily exploitable vulnerability ... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5546
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u131, 7u121 and 8u112; Java SE Embedded: 8u111; JRockit: R28.3.12. Easily exploitable vulnera... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-5545
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to 5.1.14. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
Affected Products : vm_virtualbox- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2016-5541
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.26 and earlier, 7.3.14 and earlier and 7.4.12 and earlier. Difficult to exploit vulnerability allows unauthenticated... Read more
Affected Products : mysql_cluster- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2016-5528
Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network a... Read more
Affected Products : glassfish_server- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-5509
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Difficult to exploit vulnerability allows l... Read more
Affected Products : flexcube_investor_servicing- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-5822
Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted HTTP packets.... Read more
Affected Products : oceanstor_5800_v3- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3996
ClipboardDataMgr in Samsung KNOX 1.0.0 and 2.3.0 does not properly check the caller, which allows local users to read KNOX clipboard data via a crafted application.... Read more
Affected Products : knox- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-1920
Samsung KNOX 1.0.0 uses the shared certificate on Android, which allows local users to conduct man-in-the-middle attacks as demonstrated by installing a certificate and running a VPN service.... Read more
Affected Products : knox- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-1919
Samsung KNOX 1.0 uses a weak eCryptFS Key generation algorithm, which makes it easier for local users to obtain sensitive information by leveraging knowledge of the TIMA key and a brute-force attack.... Read more
Affected Products : knox- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-9453
The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one.... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9448
The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this v... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8411
Buffer overflow vulnerability while processing QMI QOS TLVs. Product: Android. Versions: versions that have qmi_qos_srvc.c. Android ID: 31805216. References: QC CR#912775.... Read more
Affected Products : android- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
3.7
LOWCVE-2016-1551
ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Because reference clocks are treated like other peers and stored in the same s... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10003
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.... Read more
Affected Products : squid- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10002
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests... Read more
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5599
An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the Patient Portal. Inserted payload is rendered within the Patient Portal and t... Read more
Affected Products : patient_portal- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5598
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to... Read more
Affected Products : patient_portal- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9054
An exploitable stack-based buffer overflow vulnerability exists in the querying functionality of Aerospike Database Server 3.10.0.3. A specially crafted packet can cause a stack-based buffer overflow in the function as_sindex__simatch_list_by_set_binid re... Read more
Affected Products : database_server- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025