Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.3

    HIGH
    CVE-2016-6474

    A vulnerability in the implementation of X.509 Version 3 for SSH authentication functionality in Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to bypass authentication on an affected system. More Information: CSCuv89417. Kn... Read more

    Affected Products : ios
    • EPSS Score: %0.32
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-6473

    A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2 network storm. More Information: CSCuu69332, CSCux07028. Known Affected Releases: 15.2(3)E. Known Fixed R... Read more

    Affected Products : ios
    • EPSS Score: %0.22
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-6471

    A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authenticated, remote attacker to view the Remote Storage Password. More Information: CSCvb19366. Known Affected Re... Read more

    • EPSS Score: %0.42
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6470

    A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to the root level. More Information: CSCvb81344. Known Affected Releases: 1.0.... Read more

    Affected Products : hybrid_media_service
    • EPSS Score: %0.06
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6469

    A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) vulnerability due to the proxy process unexpectedly restarting. More Information... Read more

    Affected Products : web_security_appliance
    • EPSS Score: %0.99
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-6468

    A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information:... Read more

    Affected Products : emergency_responder
    • EPSS Score: %0.33
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6467

    A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Switch could allow an unauthenticated, remote attacker to cause an unexpected reload of the Network Processing Unit (NPU) process. More In... Read more

    Affected Products : asr_5000_series_software asr_5000
    • EPSS Score: %1.79
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-6465

    A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances and Cisco Web Security Appliances could allow an unauthenticated, remote attacker to bypass user filters that are configured for an affect... Read more

    Affected Products : email_security_appliance
    • EPSS Score: %0.19
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6464

    A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, remote attacker to view information on web pages that should be restricted. More Information: CSCva49629. K... Read more

    • EPSS Score: %1.36
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6449

    A vulnerability in the system management of certain FireAMP system processes in Cisco FireAMP Connector Endpoint software could allow an authenticated, local attacker to stop certain protected FireAMP processes without requiring a password. Stopping certa... Read more

    • EPSS Score: %0.05
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2016-1411

    A vulnerability in the update functionality of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Content Management Security Appliance (SMA) could allow an unauthenticated, remote attacker to im... Read more

    • EPSS Score: %0.22
    • Published: Dec. 14, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-5060

    Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save.... Read more

    Affected Products : ngrinder
    • EPSS Score: %0.51
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-2334

    Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.... Read more

    Affected Products : fedora solaris 7-zip
    • EPSS Score: %16.30
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.0

    HIGH
    CVE-2016-6664

    mysqld_safe in Oracle MySQL through 5.5.51, 5.6.x through 5.6.32, and 5.7.x through 5.7.14; MariaDB; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x before 5.7.14-8; and Percona XtraDB Cluster before 5.5.41-37.0, 5.6.x before 5.6.32... Read more

    • EPSS Score: %44.47
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.0

    HIGH
    CVE-2016-6663

    Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB before 5.5.52, 10.0.x before 10.0.28, and 10.1.x before 10.1.18; Percona Server before 5.5.51-38.2, 5.6.x before 5.6.32-78-1, and 5.7.x b... Read more

    • EPSS Score: %2.10
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-7953

    Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.... Read more

    Affected Products : fedora libxvmc
    • EPSS Score: %1.00
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-7952

    X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.... Read more

    Affected Products : fedora libxtst
    • EPSS Score: %0.86
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-7951

    Multiple integer overflows in X.org libXtst before 1.2.3 allow remote X servers to trigger out-of-bounds memory access operations by leveraging the lack of range checks.... Read more

    Affected Products : fedora libxtst
    • EPSS Score: %0.71
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-7950

    The XRenderQueryFilters function in X.org libXrender before 0.9.10 allows remote X servers to trigger out-of-bounds write operations via vectors involving filter name lengths.... Read more

    Affected Products : fedora libxrender
    • EPSS Score: %0.75
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-7949

    Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.... Read more

    Affected Products : fedora libxrender
    • EPSS Score: %4.76
    • Published: Dec. 13, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292495 Results