Latest CVE Feed
-
8.8
HIGHCVE-2016-5273
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.... Read more
Affected Products : firefox- EPSS Score: %0.58
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5272
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arb... Read more
- EPSS Score: %0.51
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-5271
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets... Read more
Affected Products : firefox- EPSS Score: %0.65
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5270
Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds writ... Read more
- EPSS Score: %2.65
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5257
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4 and Thunderbird < 45.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execut... Read more
- EPSS Score: %0.82
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5256
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 49.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more
Affected Products : firefox- EPSS Score: %1.02
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2827
The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.... Read more
Affected Products : firefox- EPSS Score: %0.65
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-2146
The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via ... Read more
- EPSS Score: %0.23
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-6824
Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial of service (device restart) via crafted CAPWAP packets.... Read more
Affected Products : ac6005_firmware ac6605_firmware acu2_firmware ac6003_firmware ac6003 ac6005 ac6605 acu2- EPSS Score: %0.20
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6669
Buffer overflow in the Authentication, Authorization and Accounting (AAA) module in Huawei USG2100, USG2200, USG5100, and USG5500 unified security gateways with software before V300R001C10SPC600 allows remote authenticated RADIUS servers to execute arbitr... Read more
Affected Products : usg2100_firmware usg2200_firmware usg5100_firmware usg5500_firmware usg2100 usg2200 usg5100 usg5500- EPSS Score: %2.85
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6525
Heap-based buffer overflow in the pdf_load_mesh_params function in pdf/pdf-shade.c in MuPDF allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a large decode array.... Read more
- EPSS Score: %5.36
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-6340
The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack.... Read more
- EPSS Score: %0.12
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-6322
Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file.... Read more
- EPSS Score: %0.04
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-6265
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.... Read more
- EPSS Score: %0.50
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-5247
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might ... Read more
Affected Products : bios thinkcentre_e93 thinkcentre_m6500t\/s thinkcentre_m6600 thinkcentre_m6600q thinkcentre_m6600t\/s thinkcentre_m73p thinkcentre_m800 thinkcentre_m83 thinkcentre_m8500t\/s +13 more products- EPSS Score: %0.03
- Published: Sep. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4464
The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured audience URIs, which might allow remote attackers to have bypass intended restrictions and have unspecifi... Read more
Affected Products : cxf_fediz- EPSS Score: %2.06
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3991
Heap-based buffer overflow in the loadImage function in the tiffcrop tool in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image with zero tiles.... Read more
- EPSS Score: %0.38
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3990
Heap-based buffer overflow in the horizontalDifference8 function in tif_pixarlog.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted TIFF image to tiffcp.... Read more
- EPSS Score: %0.44
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3945
Multiple integer overflows in the (1) cvt_by_strip and (2) cvt_by_tile functions in the tiff2rgba tool in LibTIFF 4.0.6 and earlier, when -b mode is enabled, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a craft... Read more
- EPSS Score: %0.12
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3632
The _TIFFVGetField function in tif_dirinfo.c in LibTIFF 4.0.6 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary code via a crafted TIFF image.... Read more
- EPSS Score: %0.18
- Published: Sep. 21, 2016
- Modified: Apr. 12, 2025