Latest CVE Feed
-
8.8
HIGHCVE-2016-3062
The mov_read_dref function in libavformat/mov.c in Libav before 11.7 and FFmpeg before 0.11 allows remote attackers to cause a denial of service (memory corruption) or execute arbitrary code via the entries value in a dref box in an MP4 file.... Read more
- EPSS Score: %1.40
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2016-2841
The ne2000_receive function in the NE2000 NIC emulation support (hw/net/ne2000.c) in QEMU before 2.5.1 allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) via crafted values for the PSTART and PSTOP reg... Read more
- EPSS Score: %0.07
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2538
Multiple integer overflows in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 allow local guest OS administrators to cause a denial of service (QEMU process crash) or obtain sensitive host memory information via a remote NDIS contr... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2392
The is_rndis function in the USB Net device emulator (hw/usb/dev-network.c) in QEMU before 2.5.1 does not properly validate USB configuration descriptor objects, which allows local guest OS administrators to cause a denial of service (NULL pointer derefer... Read more
- EPSS Score: %0.09
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2016-2391
The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via vectors related to multiple eof_timers.... Read more
- EPSS Score: %0.06
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2012-6702
Expat, when used in a parser that has not called XML_SetHashSalt or passed it a seed of 0, makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via vectors involving use of the srand function.... Read more
- EPSS Score: %0.46
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-5361
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet. NOTE: the original behavior complies with the IKEv1 proto... Read more
Affected Products : libreswan- EPSS Score: %0.95
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4171
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in June 2016.... Read more
Affected Products : windows_10 windows_8.1 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation macos flash_player mac_os_x opensuse +5 more products- Actively Exploited
- EPSS Score: %23.58
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4167
Adobe DNG Software Development Kit (SDK) before 1.4 2016 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
Affected Products : dng_software_development_kit- EPSS Score: %6.48
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4166
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs list... Read more
Affected Products : windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x chrome_os windows- EPSS Score: %2.19
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4165
The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input.... Read more
Affected Products : brackets- EPSS Score: %6.15
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4164
Cross-site scripting (XSS) vulnerability in Adobe Brackets before 1.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : brackets- EPSS Score: %0.64
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4163
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +3 more products- EPSS Score: %2.36
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4162
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +3 more products- EPSS Score: %2.35
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4161
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +3 more products- EPSS Score: %2.36
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-4160
Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
Affected Products : android windows_10 windows_8.1 linux_kernel flash_player_desktop_runtime flash_player mac_os_x iphone_os chrome_os windows +3 more products- EPSS Score: %2.36
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-4159
Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 10 before Update 20, 11 before Update 9, and 2016 before Update 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : coldfusion- EPSS Score: %0.70
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
7.3
HIGHCVE-2016-4158
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.... Read more
- EPSS Score: %1.96
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
7.3
HIGHCVE-2016-4157
Untrusted search path vulnerability in the installer in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse resource in an unspecified directory.... Read more
Affected Products : creative_cloud- EPSS Score: %0.16
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-4156
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs list... Read more
Affected Products : windows_10 windows_8.1 windows_rt_8.1 windows_server_2012 linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation macos flash_player_desktop_runtime +6 more products- EPSS Score: %3.70
- Published: Jun. 16, 2016
- Modified: Apr. 12, 2025