Latest CVE Feed
-
7.8
HIGHCVE-2016-1712
Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local users to gain privileges by leveraging improper sanitization of the root_reboot local invocation.... Read more
Affected Products : pan-os- EPSS Score: %0.05
- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6257
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM600 and Ultraslim Wireless mice, does not enforce incrementing AES counters, which allows remote attackers to inject ... Read more
Affected Products : firmware km714_firmware km632_firmware unifying_firmware ultraslim_firmware usb_dongle wireless_keyboard km714_dongle km714_wireless_keyboard km632_dongle +4 more products- EPSS Score: %1.03
- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6185
The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.... Read more
- EPSS Score: %0.45
- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-3737
The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.... Read more
Affected Products : jboss_operations_network- EPSS Score: %0.45
- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1238
(1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Enc... Read more
- EPSS Score: %0.38
- Published: Aug. 02, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-5672
Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without promp... Read more
Affected Products : crosswalk- EPSS Score: %0.39
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-5138
Integer overflow in the kbasep_vinstr_attach_client function in midgard/mali_kbase_vinstr.c in Google Chrome before 52.0.2743.85 allows remote attackers to cause a denial of service (heap-based buffer overflow and use-after-free) by leveraging an unrestri... Read more
Affected Products : chrome- EPSS Score: %1.07
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4837
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : discount_coupon- EPSS Score: %2.61
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-4834
modules/Users/actions/Save.php in Vtiger CRM 6.4.0 and earlier does not properly restrict user-save actions, which allows remote authenticated users to create or modify user accounts via unspecified vectors.... Read more
Affected Products : vtiger_crm- EPSS Score: %0.61
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4373
The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.... Read more
Affected Products : operations_manager- EPSS Score: %1.84
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-3120
The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.3, when restrict_anonymous_to_tgt is enabled, uses an incorrect client data structure, which allows remote... Read more
- EPSS Score: %1.89
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2180
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) v... Read more
- EPSS Score: %4.38
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1611
Novell Filr 1.2 before Hot Patch 6 and 2.0 before Hot Patch 2 uses world-writable permissions for /etc/profile.d/vainit.sh, which allows local users to gain privileges by replacing this file's content with arbitrary shell commands.... Read more
Affected Products : filr- EPSS Score: %0.05
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1610
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote attackers to bypass intended access restrictions and write to arbitrary files via a .. (dot dot) in ... Read more
Affected Products : filr- EPSS Score: %23.33
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-1609
Multiple cross-site scripting (XSS) vulnerabilities in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allow remote authenticated users to inject arbitrary web script or HTML via crafted input, as demonstrated by a crafted attrib... Read more
Affected Products : filr- EPSS Score: %1.36
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-1608
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ntpServer parameter.... Read more
Affected Products : filr- EPSS Score: %10.81
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-1607
Multiple cross-site request forgery (CSRF) vulnerabilities in the administrative interface in Novell Filr before 2.0 Security Update 2 allow remote attackers to hijack the authentication of administrators, as demonstrated by reconfiguring time settings vi... Read more
Affected Products : filr- EPSS Score: %0.97
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1605
Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field.... Read more
Affected Products : sentinel- EPSS Score: %0.81
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1461
Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachment in an e-mail message, aka Bug ID CSCuz14932.... Read more
- EPSS Score: %0.98
- Published: Aug. 01, 2016
- Modified: Apr. 12, 2025
-
4.8
MEDIUMCVE-2016-5005
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.3.9 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via the connector.sourceRepoId parameter to admin/addProxyConnector_commit.action.... Read more
Affected Products : archiva- EPSS Score: %0.74
- Published: Jul. 28, 2016
- Modified: Apr. 12, 2025