Latest CVE Feed
-
4.3
MEDIUMCVE-2015-7776
Cybozu Garoon 3.x and 4.x before 4.2.0 does not properly restrict loading of IMG elements, which makes it easier for remote attackers to track users via a crafted HTML e-mail message, a different vulnerability than CVE-2016-1196.... Read more
Affected Products : garoon- EPSS Score: %0.56
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2015-7462
IBM WebSphere MQ 8.0.0.4 on IBM i platforms allows local users to discover cleartext certificate-keystore passwords within MQ trace output by leveraging administrator privileges to execute the mqcertck program.... Read more
Affected Products : websphere_mq- EPSS Score: %0.03
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1226
Cross-site scripting (XSS) vulnerability in Trend Micro Internet Security 8 and 10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : internet_security- EPSS Score: %0.37
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1225
Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : internet_security- EPSS Score: %0.75
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1197
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.x before 4.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7775.... Read more
Affected Products : garoon- EPSS Score: %0.32
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2016-1195
Open redirect vulnerability in Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.... Read more
Affected Products : garoon- EPSS Score: %0.27
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7775
Cross-site scripting (XSS) vulnerability in Cybozu Garoon 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-1197.... Read more
Affected Products : garoon- EPSS Score: %0.22
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-4821
I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified vectors.... Read more
- EPSS Score: %0.50
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-4820
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users.... Read more
- EPSS Score: %0.13
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4819
The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f through 3.16b, and DX Library for Visual C++ 3.13f through 3.16b allows remote attackers to execute arbitrary code via a crafted string.... Read more
Affected Products : dx_library- EPSS Score: %2.68
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4817
lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packe... Read more
- EPSS Score: %7.96
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-4816
BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.... Read more
- EPSS Score: %0.38
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4815
Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : wzr-900dhp_firmware wzr-600dhp2_firmware wzr-600dhp3_firmware wzr-900dhp2_firmware wzr-s600dhp_firmware wzr-s900dhp_firmware wzr-900dhp2 wzr-600dhp3 wzr-s900dhp wzr-s600dhp +2 more products- EPSS Score: %0.39
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4814
Directory traversal vulnerability in kml2jsonp.php in Geospatial Information Authority of Japan (aka GSI) Old_GSI_Maps before January 2015 on Windows allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : old_gsi_maps- EPSS Score: %0.36
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-4813
NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.... Read more
Affected Products : netcommons- EPSS Score: %0.49
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
8.0
HIGHCVE-2016-4371
HPE Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote authenticated users to obtain sensitive information, modify data, and conduct server-side request forgery (SSRF) attacks via unspecified vectors, related to the ... Read more
- EPSS Score: %0.07
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1424
Cisco IOS 15.2(1)T1.11 and 15.2(2)TST allows remote attackers to cause a denial of service (device crash) via a crafted LLDP packet, aka Bug ID CSCun63132.... Read more
Affected Products : ios- EPSS Score: %0.24
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1397
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote authenticated users to cause a denial o... Read more
- EPSS Score: %0.51
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1396
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to i... Read more
- EPSS Score: %0.25
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1395
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted ... Read more
- EPSS Score: %1.21
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025