Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2016-6412

    The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-middle attackers to trigger arbitrary downloads via crafted HTTP headers, aka Bug ID CSCuz84773.... Read more

    Affected Products : ios
    • EPSS Score: %0.15
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6411

    Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.... Read more

    Affected Products : firesight_system_software
    • EPSS Score: %0.21
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2016-6410

    The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuy19856.... Read more

    Affected Products : ios
    • EPSS Score: %0.31
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6409

    The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.... Read more

    Affected Products : ios
    • EPSS Score: %0.69
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6408

    Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.... Read more

    Affected Products : prime_home
    • EPSS Score: %0.43
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6414

    iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.... Read more

    Affected Products : ios
    • EPSS Score: %0.22
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6406

    Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA) devices, when Enrollment Client before 1.0.2-065 is installed, allows remote attackers to obtain root acc... Read more

    Affected Products : email_security_appliance_firmware
    • EPSS Score: %2.88
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-6374

    Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, aka Bug ID CSCuz89093.... Read more

    Affected Products : cloud_services_platform_2100
    • EPSS Score: %5.62
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2016-6373

    The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.... Read more

    Affected Products : cloud_services_platform_2100
    • EPSS Score: %0.78
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 7.4

    HIGH
    CVE-2016-5284

    Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 s... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %0.46
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5283

    Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.... Read more

    Affected Products : firefox
    • EPSS Score: %0.10
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-5282

    Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.... Read more

    Affected Products : firefox
    • EPSS Score: %0.46
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5281

    Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.74
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5280

    Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectiona... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.71
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-5279

    Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.... Read more

    Affected Products : firefox
    • EPSS Score: %0.40
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5278

    Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled durin... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.37
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5277

    Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.36
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5276

    Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of ... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.16
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5275

    Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.... Read more

    Affected Products : firefox
    • EPSS Score: %3.19
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5274

    Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction betwee... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.52
    • Published: Sep. 22, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291712 Results