Latest CVE Feed
-
7.3
HIGHCVE-2016-6474
A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on an affected system. More Information: CSCuv89417. Kn... Read more
Affected Products : ios- EPSS Score: %0.32
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6473
A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2 network storm. More Information: CSCuu69332, CSCux07028. Known Affected Releases: 15.2(3)E. Known Fixed R... Read more
Affected Products : ios- EPSS Score: %0.22
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6471
A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view the Remote Storage Password. More Information: CSCvb19366. Known Affected Re... Read more
Affected Products : firepower_management_center firesight_system_software secure_firewall_management_center- EPSS Score: %0.42
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6470
A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb81344. Known Affected Releases: 1.0.... Read more
Affected Products : hybrid_media_service- EPSS Score: %0.06
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6469
A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting. More Information... Read more
Affected Products : web_security_appliance- EPSS Score: %0.99
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-6468
A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information:... Read more
Affected Products : emergency_responder- EPSS Score: %0.33
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6467
A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Switch could allow an unauthenticated, remote attacker to cause an unexpected reload of the Network Processing Unit (NPU) process. More In... Read more
- EPSS Score: %1.79
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-6465
A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affect... Read more
Affected Products : email_security_appliance- EPSS Score: %0.19
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6464
A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. More Information: CSCva49629. K... Read more
Affected Products : unified_communications_manager_im_and_presence_service unified_communications_manager- EPSS Score: %1.36
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6449
A vulnerability in the system management of certain FireAMP system processes in Cisco FireAMP Connector Endpoint software could allow an authenticated, local attacker to stop certain protected FireAMP processes without requiring a password. Stopping certa... Read more
Affected Products : fireamp_connector_endpoint_software- EPSS Score: %0.05
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-1411
A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to im... Read more
Affected Products : web_security_appliance email_security_appliance content_security_management_appliance- EPSS Score: %0.22
- Published: Dec. 14, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5060
Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save.... Read more
Affected Products : ngrinder- EPSS Score: %0.51
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-2334
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.... Read more
- EPSS Score: %16.30
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-6664
mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32... Read more
- EPSS Score: %44.47
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-6663
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x b... Read more
- EPSS Score: %2.10
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7953
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.... Read more
- EPSS Score: %1.00
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-7952
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.... Read more
- EPSS Score: %0.86
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7951
Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.... Read more
- EPSS Score: %0.71
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7950
The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.... Read more
- EPSS Score: %0.75
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-7949
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.... Read more
- EPSS Score: %4.76
- Published: Dec. 13, 2016
- Modified: Apr. 12, 2025