Latest CVE Feed
-
6.5
MEDIUMCVE-2016-1188
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.21
- Published: Jun. 25, 2016
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2016-4528
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file.... Read more
- EPSS Score: %0.14
- Published: Jun. 25, 2016
- Modified: Apr. 12, 2025
-
6.6
MEDIUMCVE-2016-4525
Unspecified ActiveX controls in Advantech WebAccess before 8.1_20160519 allow remote authenticated users to obtain sensitive information or modify data via unknown vectors, related to the INTERFACESAFE_FOR_UNTRUSTED_CALLER (aka safe for scripting) flag.... Read more
- EPSS Score: %0.14
- Published: Jun. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4519
Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a ZIP archive in a vlp file.... Read more
Affected Products : visilogic_oplc_ide- EPSS Score: %6.41
- Published: Jun. 25, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-5723
Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors.... Read more
Affected Products : fusioninsight_hd- EPSS Score: %0.02
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5722
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP header, which allows remote attackers to conduct replay attacks and obtain sensitive information by sniff... Read more
- EPSS Score: %0.21
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2016-5709
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.... Read more
Affected Products : virtualization_manager- EPSS Score: %0.10
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-5435
Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 before V500R001C20SPC100, when in hot standby networking where two devices are not directly connected, allows r... Read more
- EPSS Score: %0.15
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
4.9
MEDIUMCVE-2016-5021
The iControl REST service in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before 12.0.0 HF3; BIG-IP GTM 11.5.x before 11.5.4 and 11.6.x befor... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +6 more products- EPSS Score: %0.16
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-4802
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll... Read more
Affected Products : curl- EPSS Score: %0.45
- Published: Jun. 24, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1439
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.... Read more
- EPSS Score: %0.25
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1438
Cisco AsyncOS 9.7.0-125 on Email Security Appliance (ESA) devices allows remote attackers to bypass intended spam filtering via crafted executable content in a ZIP archive, aka Bug ID CSCuy39210.... Read more
- EPSS Score: %0.38
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1437
SQL injection vulnerability in the SQL database in Cisco Prime Collaboration Deployment before 11.5.1 allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuy92549.... Read more
Affected Products : prime_collaboration_deployment- EPSS Score: %0.22
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1436
The General Packet Radio Switching Tunneling Protocol 1 (aka GTPv1) implementation on Cisco ASR 5000 Packet Data Network Gateway devices before 19.4 allows remote attackers to cause a denial of service (Session Manager process restart) via a crafted GTPv1... Read more
- EPSS Score: %0.72
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.0
HIGHCVE-2016-1435
Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files by leveraging shell access, aka Bug ID CSCuz03014.... Read more
- EPSS Score: %0.18
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1434
The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010.... Read more
- EPSS Score: %0.16
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1428
Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via a sequence of crafted SNMP read requests, aka Bug ID CSCux13174.... Read more
- EPSS Score: %0.45
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0914
EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.9 before Patch 23 and 1.10 before Patch 10, and Documentum TaskSpace 6.7 SP3 allow remote authenticated us... Read more
Affected Products : documentum_administrator documentum_webtop documentum_taskspace documentum_capital_projects- EPSS Score: %0.16
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6289
Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consumption) via crafted TCP packets on the SSH port, aka Bug ID CSCuu13476.... Read more
- EPSS Score: %11.66
- Published: Jun. 23, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2364
The Chrome HUDweb plugin before 2016-05-05 for Fonality (previously trixbox Pro) 12.6 through 14.1i uses the same hardcoded private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms ... Read more
- EPSS Score: %0.15
- Published: Jun. 20, 2016
- Modified: Apr. 12, 2025