Latest CVE Feed
-
5.5
MEDIUMCVE-2016-9756
arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.... Read more
Affected Products : linux_kernel- EPSS Score: %0.03
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-9755
The netfilter subsystem in the Linux kernel before 4.9 mishandles IPv6 reassembly, which allows local users to cause a denial of service (integer overflow, out-of-bounds write, and GPF) or possibly have unspecified other impact via a crafted application t... Read more
Affected Products : linux_kernel- EPSS Score: %0.05
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-9685
Multiple memory leaks in error paths in fs/xfs/xfs_attr_list.c in the Linux kernel before 4.5.1 allow local users to cause a denial of service (memory consumption) via crafted XFS filesystem operations.... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-9588
arch/x86/kvm/vmx.c in the Linux kernel through 4.9 mismanages the #BP and #OF exceptions, which allows guest OS users to cause a denial of service (guest OS crash) by declining to handle an exception thrown by an L2 guest.... Read more
Affected Products : linux_kernel- EPSS Score: %0.07
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-9576
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 4.8.14 does not properly restrict the type of iterator, which allows local users to read or write to arbitrary kernel memory locations or cause a denial of service (use-after-f... Read more
Affected Products : linux_kernel- EPSS Score: %0.07
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-6787
kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 31095224.... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-6786
kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users to gain privileges via a crafted application, aka Android internal bug 30955111.... Read more
Affected Products : linux_kernel- EPSS Score: %0.09
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2016-6213
fs/namespace.c in the Linux kernel before 4.9 does not restrict how many mounts may exist in a mount namespace, which allows local users to cause a denial of service (memory consumption and deadlock) via MS_BIND mount system calls, as demonstrated by a lo... Read more
Affected Products : linux_kernel- EPSS Score: %0.04
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2012-6704
The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5 mishandles negative values of sk_sndbuf and sk_rcvbuf, which allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified o... Read more
Affected Products : linux_kernel- EPSS Score: %0.13
- Published: Dec. 28, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10072
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. To properly e... Read more
Affected Products : wampserver- EPSS Score: %0.17
- Published: Dec. 27, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10031
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privil... Read more
Affected Products : wampserver- EPSS Score: %0.24
- Published: Dec. 27, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-9224
A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Information: CSCvc31635. Known Affected Releases: 10.6(9). Known Fixed Releases: 11.0(0).... Read more
Affected Products : jabber_guest- EPSS Score: %0.30
- Published: Dec. 26, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-9223
A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote attacker to install Docker containers with high privileges on the affected system. Affected Products: This vu... Read more
Affected Products : cloudcenter_orchestrator- EPSS Score: %1.75
- Published: Dec. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-9217
A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. More Information: CSCus99394. Known Affected Releases: 7.3... Read more
Affected Products : intercloud_fabric- EPSS Score: %0.58
- Published: Dec. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-9681
Multiple cross-site scripting (XSS) vulnerabilities in Serendipity before 2.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a category or directory name.... Read more
Affected Products : serendipity- EPSS Score: %0.24
- Published: Dec. 25, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10041
An issue was discovered in Sprecher Automation SPRECON-E Service Program before 3.43 SP0. Under certain preconditions, it is possible to execute telegram simulation as a non-admin user. As prerequisites, a user must have created an online-connection, vali... Read more
Affected Products : sprecon-e_service_program- EPSS Score: %0.56
- Published: Dec. 25, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-10006
In OWASP AntiSamy before 1.5.5, by submitting a specially crafted input (a tag that supports style with active content), you could bypass the library protections and supply executable code. The impact is XSS.... Read more
Affected Products : antisamy- EPSS Score: %0.99
- Published: Dec. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10039
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.... Read more
Affected Products : modx_revolution- EPSS Score: %0.79
- Published: Dec. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10038
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.... Read more
Affected Products : modx_revolution- EPSS Score: %0.79
- Published: Dec. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-10037
Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.... Read more
Affected Products : modx_revolution- EPSS Score: %0.79
- Published: Dec. 24, 2016
- Modified: Apr. 12, 2025