Latest CVE Feed
-
9.3
HIGHCVE-2016-5814
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS... Read more
- EPSS Score: %0.29
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4860
Yokogawa STARDOM FCN/FCJ controller R1.01 through R4.01 does not require authentication for Logic Designer connections, which allows remote attackers to reconfigure the device or cause a denial of service via a (1) stop application program, (2) change val... Read more
- EPSS Score: %0.92
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4526
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.... Read more
Affected Products : tracer_sc- EPSS Score: %0.06
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1483
Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation component of an unspecified service, aka Bug ID CSCuy92704.... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.51
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-0870
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.... Read more
- EPSS Score: %0.42
- Published: Sep. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-6405
Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368.... Read more
Affected Products : fog_director- EPSS Score: %0.18
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6404
Cross-site scripting (XSS) vulnerability in the web framework in Cisco IOx Local Manager in IOS 15.5(2)T and IOS XE allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuy19854.... Read more
Affected Products : ios- EPSS Score: %0.30
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-6403
The Data in Motion (DMo) application in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service via a crafted packet, aka Bug IDs CSCuy82904, CSCuy82909, and CSCuy82912.... Read more
Affected Products : ios- EPSS Score: %0.56
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6402
UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via crafted CLI input, aka Bug ID CSCuz91263.... Read more
- EPSS Score: %0.08
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-4749
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file.... Read more
Affected Products : iphone_os- EPSS Score: %0.06
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-4747
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors.... Read more
Affected Products : iphone_os- EPSS Score: %0.17
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-4746
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction.... Read more
Affected Products : iphone_os- EPSS Score: %0.46
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-4741
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates.... Read more
Affected Products : iphone_os- EPSS Score: %0.67
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
2.9
LOWCVE-2016-4740
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : iphone_os- EPSS Score: %0.07
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-4719
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application.... Read more
- EPSS Score: %0.23
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4705
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704.... Read more
Affected Products : xcode- EPSS Score: %0.15
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4704
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705.... Read more
Affected Products : xcode- EPSS Score: %0.05
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-4620
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app.... Read more
Affected Products : iphone_os- EPSS Score: %0.26
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1433
Cisco IOS XR 6.0 and 6.0.1 on NCS 6000 devices allows remote attackers to cause a denial of service (OSPFv3 process reload) via crafted OSPFv3 packets, aka Bug ID CSCuz66289.... Read more
Affected Products : ios_xr- EPSS Score: %0.55
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-6643
Cross-site scripting (XSS) vulnerability in EMC ViPR SRM before 3.7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : vipr_srm- EPSS Score: %0.22
- Published: Sep. 18, 2016
- Modified: Apr. 12, 2025