Latest CVE Feed
-
8.2
HIGHCVE-2016-0271
The agents in IBM UrbanCode Deploy 6.x before 6.0.1.14, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 do not verify a server's identity in a JMS session or an HTTP session, which allows local users to obtain root access to arbitrary agents via unspecifie... Read more
Affected Products : urbancode_deploy- EPSS Score: %0.04
- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
5.1
MEDIUMCVE-2016-0252
IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via unspecified vectors.... Read more
- EPSS Score: %0.05
- Published: Jul. 08, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2119
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1) SMB2_SESSION_FL... Read more
Affected Products : samba- EPSS Score: %1.16
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2923
IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cookie header for an unspecified JAX-RS API cookie, which makes it easier for remote attackers to obtain potent... Read more
Affected Products : websphere_application_server- EPSS Score: %0.28
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1444
The Mobile and Remote Access (MRA) component in Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7 and Expressway X8.1 through X8.6 mishandles certificates, which allows remote attackers to bypass authentication via an arbitrary trusted... Read more
- EPSS Score: %0.17
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1443
The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malwa... Read more
Affected Products : amp_threat_grid_appliance- EPSS Score: %0.36
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-1442
The administrative web interface in Cisco Prime Infrastructure (PI) before 3.1.1 allows remote authenticated users to execute arbitrary commands via crafted field values, aka Bug ID CSCuy96280.... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.69
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-0389
Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.23
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-0230
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via... Read more
- EPSS Score: %0.08
- Published: Jul. 07, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-6170
ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service ... Read more
- EPSS Score: %2.61
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4979
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" directive for HTTP/2 request authorization, which allows remote attackers to bypass intended access restriction... Read more
Affected Products : http_server- EPSS Score: %32.93
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4508
Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : bladecontrol-webvis- EPSS Score: %0.58
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2016-4507
SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : bladecontrol-webvis- EPSS Score: %0.26
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-1546
The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does not limit the number of simultaneous stream workers for a single HTTP/2 connection, which allows remote attackers to cause a denial of service (stream-processing outage) via modifie... Read more
Affected Products : http_server- EPSS Score: %22.78
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-0906
The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remote authenticated users to read or delete directories via a Linux backup-restore operation.... Read more
Affected Products : avamar- EPSS Score: %0.40
- Published: Jul. 06, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5099
Cross-site scripting (XSS) vulnerability in phpMyAdmin 4.4.x before 4.4.15.6 and 4.6.x before 4.6.2 allows remote attackers to inject arbitrary web script or HTML via special characters that are mishandled during double URL decoding.... Read more
- EPSS Score: %0.48
- Published: Jul. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-5098
Directory traversal vulnerability in libraries/error_report.lib.php in phpMyAdmin before 4.6.2-prerelease allows remote attackers to determine the existence of arbitrary files by triggering an error.... Read more
- EPSS Score: %0.39
- Published: Jul. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-5097
phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote attackers to obtain sensitive information by reading (1) HTTP requests or (2) server logs.... Read more
- EPSS Score: %0.54
- Published: Jul. 05, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4957
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.... Read more
Affected Products : leap opensuse solaris linux_enterprise_server linux_enterprise_desktop ntp openstack_cloud manager_proxy suse_manager- EPSS Score: %57.88
- Published: Jul. 05, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-4956
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.... Read more
Affected Products : leap opensuse solaris linux_enterprise_server linux_enterprise_desktop ntp openstack_cloud simatic_net_cp_443-1_opc_ua_firmware simatic_cp_443-1_opc_ua_firmware manager_proxy +2 more products- EPSS Score: %2.28
- Published: Jul. 05, 2016
- Modified: Apr. 12, 2025