Latest CVE Feed
-
8.8
HIGHCVE-2016-3324
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %17.01
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3306
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- EPSS Score: %0.50
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3305
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack ... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- EPSS Score: %0.54
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2016-3302
Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code... Read more
- EPSS Score: %0.83
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-3297
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more
- EPSS Score: %46.44
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3295
Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more
- EPSS Score: %52.99
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3294
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3330.... Read more
Affected Products : edge- EPSS Score: %23.50
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2016-3292
Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."... Read more
Affected Products : internet_explorer- EPSS Score: %4.45
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2016-3291
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."... Read more
- EPSS Score: %5.16
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3247
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more
- EPSS Score: %66.98
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0141
The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Info... Read more
Affected Products : office- EPSS Score: %7.71
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0138
Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Out... Read more
Affected Products : exchange_server- EPSS Score: %15.24
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0137
The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."... Read more
Affected Products : office- EPSS Score: %6.54
- Published: Sep. 14, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6399
Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb1631... Read more
Affected Products : ace_application_control_engine_module_a1 ace_application_control_engine_module_a3 ace_application_control_engine_module_a4 ace_application_control_engine_module_a5 ace_4700_series_application_control_engine_appliance ace_4700_series_application_control_engine_appliance_a1 ace_4700_series_application_control_engine_appliance_a3 ace_4700_series_application_control_engine_appliance_a4 ace_4700_series_application_control_engine_appliance_a5- EPSS Score: %0.74
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6398
The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274.... Read more
Affected Products : ios- EPSS Score: %0.27
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-6396
Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.43
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-6395
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted ... Read more
Affected Products : firesight_system_software- EPSS Score: %0.34
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-6394
Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.... Read more
Affected Products : firesight_system_software- EPSS Score: %0.30
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6371
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSCuz64717.... Read more
Affected Products : hosted_collaboration_mediation_fulfillment- EPSS Score: %7.29
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-6370
Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in an HTTP request, aka Bug ID CSCuz272... Read more
Affected Products : hosted_collaboration_mediation_fulfillment- EPSS Score: %0.54
- Published: Sep. 12, 2016
- Modified: Apr. 12, 2025