Latest CVE Feed
-
10.0
HIGHCVE-2016-4658
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or... Read more
- EPSS Score: %19.34
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4618
Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."... Read more
- EPSS Score: %0.50
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4611
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE... Read more
- EPSS Score: %0.92
- Published: Sep. 25, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6532
DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.... Read more
Affected Products : imaging_suite- EPSS Score: %0.73
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6531
Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ...... Read more
Affected Products : opendental- EPSS Score: %3.27
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5793
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.... Read more
Affected Products : active_opc_server- EPSS Score: %0.05
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4845
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the au... Read more
Affected Products : hvl-a2.0_firmware hvl-a3.0_firmware hvl-a4.0_firmware hvl-at1.0s_firmware hvl-at2.0_firmware hvl-at2.0a_firmware hvl-at3.0_firmware hvl-at3.0a_firmware hvl-at4.0_firmware hvl-at4.0a_firmware +3 more products- EPSS Score: %5.58
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0918
EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.... Read more
- EPSS Score: %0.17
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6413
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.... Read more
Affected Products : application_policy_infrastructure_controller- EPSS Score: %0.08
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6412
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.... Read more
Affected Products : ios- EPSS Score: %0.15
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6411
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.21
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-6410
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.... Read more
Affected Products : ios- EPSS Score: %0.31
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6409
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.... Read more
Affected Products : ios- EPSS Score: %0.69
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6408
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.... Read more
Affected Products : prime_home- EPSS Score: %0.43
- Published: Sep. 24, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6414
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.... Read more
Affected Products : ios- EPSS Score: %0.22
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-6406
Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root acc... Read more
Affected Products : email_security_appliance_firmware- EPSS Score: %2.88
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6374
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.... Read more
Affected Products : cloud_services_platform_2100- EPSS Score: %5.62
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-6373
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.... Read more
Affected Products : cloud_services_platform_2100- EPSS Score: %0.78
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2016-5284
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 s... Read more
- EPSS Score: %0.46
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5283
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.... Read more
Affected Products : firefox- EPSS Score: %0.10
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025