Latest CVE Feed
-
7.5
HIGHCVE-2016-1438
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.... Read more
- EPSS Score: %0.38
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1437
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.... Read more
Affected Products : prime_collaboration_deployment- EPSS Score: %0.22
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1436
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1... Read more
- EPSS Score: %0.72
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-1435
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.... Read more
- EPSS Score: %0.18
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1434
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.... Read more
- EPSS Score: %0.16
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1428
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.... Read more
- EPSS Score: %0.45
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0914
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated us... Read more
Affected Products : documentum_administrator documentum_webtop documentum_taskspace documentum_capital_projects- EPSS Score: %0.16
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6289
Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.... Read more
- EPSS Score: %11.66
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2364
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms ... Read more
- EPSS Score: %0.15
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-2363
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local users to obtain root access for unspecified command execution by leveraging access to the nobody account.... Read more
Affected Products : fonality- EPSS Score: %0.04
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2362
Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.... Read more
Affected Products : fonality- EPSS Score: %0.89
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2178
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack.... Read more
- EPSS Score: %0.38
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2177
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging un... Read more
- EPSS Score: %47.95
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8289
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote attackers to discover the cleartext administrator password by reading the cgi-bin/passrec.asp HTML source code... Read more
- EPSS Score: %0.75
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-8288
NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier use the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by ... Read more
- EPSS Score: %0.75
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025
-
5.6
MEDIUMCVE-2016-4811
The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-middle attackers to obtain API access via unspecified vectors.... Read more
Affected Products : japan_connected-free_wi-fi- EPSS Score: %0.44
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-4530
OSIsoft PI SQL Data Access Server (aka OLE DB) 2016 1.5 allows remote authenticated users to cause a denial of service (service outage and data loss) via a message.... Read more
Affected Products : pi_sql_data_access_server_2016- EPSS Score: %0.56
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-4518
OSIsoft PI AF Server before 2016 2.8.0 allows remote authenticated users to cause a denial of service (service outage) via a message.... Read more
Affected Products : pi_af_server_2016- EPSS Score: %0.41
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
7.7
HIGHCVE-2016-4514
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local proxy.... Read more
- EPSS Score: %0.26
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2016-1864
The XSS auditor in WebKit, as used in Apple iOS before 9.3 and Safari before 9.1, does not properly handle redirects in block mode, which allows remote attackers to obtain sensitive information via a crafted URL.... Read more
- EPSS Score: %0.55
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025