Latest CVE Feed
-
9.8
CRITICALCVE-2016-7405
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.... Read more
- EPSS Score: %3.10
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-7401
The cookie parsing code in Django before 1.8.15 and 1.9.x before 1.9.10, when used on a site with Google Analytics, allows remote attackers to bypass an intended CSRF protection mechanism by setting arbitrary cookies.... Read more
- EPSS Score: %6.63
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-7031
The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.... Read more
- EPSS Score: %0.51
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6494
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.... Read more
- EPSS Score: %0.08
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6352
The OneLine32 function in io-ico.c in gdk-pixbuf before 2.35.3 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via crafted dimensions in an ICO file.... Read more
- EPSS Score: %1.78
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-5432
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.... Read more
- EPSS Score: %0.13
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5398
Cross-site scripting (XSS) vulnerability in Business Process Editor in Red Hat JBoss BPM Suite before 6.3.3 allows remote authenticated users to inject arbitrary web script or HTML by levering permission to create business processes.... Read more
Affected Products : jboss_bpm_suite- EPSS Score: %0.19
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5019
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.... Read more
- EPSS Score: %6.02
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1372
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.... Read more
- EPSS Score: %3.31
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1371
ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executable.... Read more
- EPSS Score: %0.58
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1244
The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.... Read more
- EPSS Score: %9.94
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1243
Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname.... Read more
- EPSS Score: %27.59
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-7445
convert.c in OpenJPEG before 2.1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors involving the variable s.... Read more
- EPSS Score: %2.04
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2016-7442
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the proxy user settings in "system settings / scan settings / anti spam" configurat... Read more
Affected Products : unified_threat_management_software- EPSS Score: %0.03
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2016-7397
The Frontend component in Sophos UTM with firmware 9.405-5 and earlier allows local administrators to obtain sensitive password information by reading the "value" field of the SMTP user settings in the notifications configuration tab.... Read more
Affected Products : unified_threat_management_software- EPSS Score: %0.03
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5700
Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 before HF4, and 12.1.0 before HF2, when configured with the HTTP Explicit Proxy functionality or SOCKS profile... Read more
- EPSS Score: %5.61
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3658
The TIFFWriteDirectoryTagLongLong8Array function in tif_dirwrite.c in the tiffset tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving the ma variable.... Read more
Affected Products : libtiff- EPSS Score: %0.95
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3634
The tagCompare function in tif_dirinfo.c in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to field_tag matching.... Read more
Affected Products : libtiff- EPSS Score: %0.69
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3633
The setrow function in the thumbnail tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the src variable.... Read more
Affected Products : libtiff- EPSS Score: %0.45
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3631
The (1) cpStrips and (2) cpTiles functions in the thumbnail tool in LibTIFF 4.0.6 and earlier allow remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the bytecounts[] array variable.... Read more
Affected Products : libtiff- EPSS Score: %0.79
- Published: Oct. 03, 2016
- Modified: Apr. 12, 2025