Latest CVE Feed
-
6.1
MEDIUMCVE-2016-6840
Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName parameter to cgi-bin/doLogin_CgiEntry and possibly other... Read more
Affected Products : oceanstor_ism- EPSS Score: %0.15
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6276
Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.... Read more
Affected Products : linux_virtual_delivery_agent- EPSS Score: %0.05
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5406
The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.... Read more
- EPSS Score: %1.50
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.8
MEDIUMCVE-2016-5395
Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.... Read more
Affected Products : ranger- EPSS Score: %0.13
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4993
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attack... Read more
Affected Products : enterprise_linux jboss_enterprise_application_platform jboss_wildfly_application_server- EPSS Score: %0.60
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4303
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer... Read more
Affected Products : debian_linux leap opensuse iperf3 suse_package_hub_for_suse_linux_enterprise iperf3- EPSS Score: %5.76
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3110
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.... Read more
Affected Products : enterprise_linux fedora jboss_enterprise_application_platform jboss_enterprise_web_server- EPSS Score: %3.22
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5997
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not ... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.11
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5996
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 does not ... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.25
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5978
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.17
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5977
Open redirect vulnerability in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before ... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.11
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2016-5976
The web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224_9.0.2A FP3 allows re... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.26
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5975
Cross-site scripting (XSS) vulnerability in the Web UI in the web portal in IBM Tealeaf Customer Experience before 8.7.1.8847 FP10, 8.8 before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108_9.0.1A FP5, 9.0.2 before 9.0.2.1... Read more
Affected Products : tealeaf_customer_experience- EPSS Score: %0.17
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-5974
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to inject arbitrary web script or HTML via an embedded string.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %0.17
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5972
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %0.12
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-5971
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) via an XML document containing an external entity declarati... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %0.41
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5970
Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URL.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %0.39
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5963
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authenticated users to execute arbitrary code via unspecified vectors.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %1.77
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5957
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote attackers to defeat cryptographic protection mechanisms and obtain sensitive information by leveraging a weak algorithm.... Read more
Affected Products : security_privileged_identity_manager_virtual_appliance- EPSS Score: %0.27
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-5947
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking attacks via a crafted web site.... Read more
- EPSS Score: %0.16
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025