Latest CVE Feed
-
9.3
HIGHCVE-2016-3301
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; Office 2007 SP3; Office 2010 SP2; Word Viewer; Skype... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 office lync skype_for_business word_viewer +2 more products- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-3300
The Netlogon service in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 improperly establishes secure communications channels, which allows local users to gain privileges by leveraging access to a domain-joined machine, aka "Net... Read more
- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-3299
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to hijack network traffic or bypass intended Enhanced Protect... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3296
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."... Read more
Affected Products : edge- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3293
Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more
- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3290
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3288.... Read more
Affected Products : internet_explorer- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3289
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code via a crafted web page, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3322.... Read more
- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-3288
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code via a crafted web page, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3290.... Read more
Affected Products : internet_explorer- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-3237
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows man-in-the-middle attackers to bypass authentication via v... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_vista windows_rt- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-4253
The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : experience_manager- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4170
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : experience_manager- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-4169
Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.... Read more
Affected Products : experience_manager- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4168
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager 5.6.1, 6.0, and 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : experience_manager- Published: Aug. 09, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-5878
Open redirect vulnerability in IBM FileNet Workplace 4.0.2 before 4.0.2.14 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : filenet_workplace- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-5331
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.... Read more
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-5330
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 through 6.0, VMware Workstation Pro 12.1.x before 12.1.1, VMware Workstation Player 12.1.x before 12.1.1, and VMware Fusion 8.1.x before... Read more
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
6.2
MEDIUMCVE-2016-3059
IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.4 before 6.4.1.9 and Tivoli Storage FlashCopy Manager for Microsoft SQL Server (aka IBM Spectrum Protect S... Read more
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-3054
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.... Read more
Affected Products : filenet_workplace- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2989
Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : connections_portlets- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-2960
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service vi... Read more
Affected Products : websphere_application_server- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025