Latest CVE Feed
-
7.5
HIGHCVE-2016-9282
SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_string parameter.... Read more
Affected Products : exponent_cms- Published: Nov. 11, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-9277
Integer overflow in SystemUI in KK(4.4) and L(5.0/5.1) on Samsung Note devices allows attackers to cause a denial of service (UI restart) via vectors involving APIs and an activity that computes an out-of-bounds array index, aka SVE-2016-6906.... Read more
Affected Products : samsung_mobile- Published: Nov. 11, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-9274
Untrusted search path vulnerability in Git 1.x for Windows allows local users to gain privileges via a Trojan horse git.exe file in the current working directory. NOTE: 2.x is unaffected.... Read more
Affected Products : git_for_windows- Published: Nov. 11, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-9272
A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.... Read more
Affected Products : exponent_cms- Published: Nov. 11, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-5195
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October... Read more
Affected Products : linux_kernel ubuntu_linux enterprise_linux fedora debian_linux ontap_select_deploy_administration_utility cloud_backup solidfire enterprise_linux_eus oncommand_balance +8 more products- Actively Exploited
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-9268
Unrestricted file upload vulnerability in the Blog appearance in the "Install or upgrade manually" module in Dotclear through 2.10.4 allows remote authenticated super-administrators to execute arbitrary code by uploading a theme file with an zip extension... Read more
Affected Products : dotclear- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-7148
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=AttachFile (via page name) component.... Read more
Affected Products : moinmoin- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-7146
MoinMoin 1.9.8 allows remote attackers to conduct "JavaScript injection" attacks by using the "page creation or crafted URL" approach, related to a "Cross Site Scripting (XSS)" issue affecting the action=fckdialog&dialog=attachment (via page name) compone... Read more
Affected Products : moinmoin- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-7490
The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.... Read more
Affected Products : studio_express- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7489
Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to elevated code execution.... Read more
Affected Products : virtual_machine- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-7488
Teradata Virtual Machine Community Edition v15.10 has insecure file permissions on /etc/luminex/pkgmgr. These could allow a local user to modify its contents and execute commands as root.... Read more
Affected Products : virtual_machine- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4095
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-7256
atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows remote a... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista windows_10_1607 windows_10_1507 +1 more products- Actively Exploited
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow local users to gain pri... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016 windows_vista windows_10_1607 windows_10_1507 +1 more products- Actively Exploited
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-7254
Microsoft SQL Server 2012 SP2 and 2012 SP3 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-7253
The agent in Microsoft SQL Server 2012 SP2, 2012 SP3, 2014 SP1, 2014 SP2, and 2016 does not properly check the atxcore.dll ACL, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Server Agent Elevation of Privileg... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-7252
Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQL Analysis Services Information Disclosure Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-7251
Cross-site scripting (XSS) vulnerability in the MDS API in Microsoft SQL Server 2016 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka "MDS API XSS Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-7250
Microsoft SQL Server 2014 SP1, 2014 SP2, and 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-7249
Microsoft SQL Server 2016 does not properly perform a cast of an unspecified pointer, which allows remote authenticated users to gain privileges via unknown vectors, aka "SQL RDBMS Engine Elevation of Privilege Vulnerability."... Read more
- Published: Nov. 10, 2016
- Modified: Apr. 12, 2025