Latest CVE Feed
-
6.8
MEDIUMCVE-2016-1397
Buffer overflow in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote authenticated users to cause a denial o... Read more
- EPSS Score: %0.51
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1396
Cross-site scripting (XSS) vulnerability in the web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to i... Read more
- EPSS Score: %0.25
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1395
The web-based management interface on Cisco RV110W devices with firmware before 1.2.1.7, RV130W devices with firmware before 1.0.3.16, and RV215W devices with firmware before 1.3.0.8 allows remote attackers to execute arbitrary code as root via a crafted ... Read more
- EPSS Score: %1.21
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1224
CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.... Read more
- EPSS Score: %0.48
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1223
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %1.68
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1183
NTT Data TERASOLUNA Server Framework for Java(WEB) 2.0.0.1 through 2.0.6.1, as used in Fujitsu Interstage Business Application Server and other products, allows remote attackers to bypass a file-extension protection mechanism, and consequently read arbitr... Read more
Affected Products : terasoluna_server_framework_for_java_web- EPSS Score: %0.16
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1432
Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated users to cause a denial of service (NULL pointer dereference and card restart) via a crafted SNMP request, aka Bug ID CSCuu68862.... Read more
- EPSS Score: %0.45
- Published: Jun. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1431
Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCur25516.... Read more
- EPSS Score: %0.25
- Published: Jun. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1427
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remote attackers to obtain sensitive information via crafted SCP messages, aka Bug ID CSCuv35694.... Read more
Affected Products : prime_network_registrar- EPSS Score: %0.30
- Published: Jun. 18, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5433
Citrix iOS Receiver before 7.0 allows attackers to cause TLS certificates to be incorrectly validated via unspecified vectors.... Read more
Affected Products : ios_receiver- EPSS Score: %0.10
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
8.2
HIGHCVE-2016-5363
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended MAC-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via (1) a crafted DHCP ... Read more
- EPSS Score: %4.75
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
8.2
HIGHCVE-2016-5362
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended DHCP-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a crafted DHCP dis... Read more
- EPSS Score: %6.31
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3643
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."... Read more
Affected Products : virtualization_manager- Actively Exploited
- EPSS Score: %4.46
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-3642
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.... Read more
Affected Products : virtualization_manager- EPSS Score: %22.38
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2015-8914
The IPTables firewall in OpenStack Neutron before 7.0.4 and 8.0.0 through 8.1.0 allows remote attackers to bypass an intended ICMPv6-spoofing protection mechanism and consequently cause a denial of service or intercept network traffic via a link-local sou... Read more
- EPSS Score: %6.66
- Published: Jun. 17, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-5300
The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted identifiers in an XML document. NOTE: this vulnerability exists because o... Read more
- EPSS Score: %1.94
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-3687
Open redirect vulnerability in F5 BIG-IP APM 11.2.1, 11.4.x, 11.5.x, and 11.6.x before 11.6.0 HF6 and Edge Gateway 11.2.1, when using multi-domain single sign-on (SSO), allows remote attackers to redirect users to arbitrary web sites and conduct phishing ... Read more
- EPSS Score: %0.37
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-3062
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.... Read more
- EPSS Score: %2.45
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2016-2841
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP reg... Read more
- EPSS Score: %0.07
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2538
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS contr... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025