Latest CVE Feed
-
7.4
HIGHCVE-2016-2221
Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorre... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1564
Multiple cross-site scripting (XSS) vulnerabilities in wp-includes/class-wp-theme.php in WordPress before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a (1) stylesheet name or (2) template name to wp-admin/customize.php.... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8880
Double free vulnerability in the format printer in PHP 7.x before 7.0.1 allows remote attackers to have an unspecified impact by triggering an error.... Read more
Affected Products : php- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8879
The odbc_bindcols function in ext/odbc/php_odbc.c in PHP before 5.6.12 mishandles driver behavior for SQL_WVARCHAR columns, which allows remote attackers to cause a denial of service (application crash) in opportunistic circumstances by leveraging use of ... Read more
Affected Products : php- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8878
main/php_open_temporary_file.c in PHP before 5.5.28 and 5.6.x before 5.6.12 does not ensure thread safety, which allows remote attackers to cause a denial of service (race condition and heap memory corruption) by leveraging an application that performs ma... Read more
Affected Products : php- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8877
The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses inconsistent allocate and free approaches, which allows remote attackers to cause a denial of service (memory co... Read more
- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8876
Zend/zend_exceptions.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 does not validate certain Exception objects, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or trigger u... Read more
Affected Products : php- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8867
The openssl_random_pseudo_bytes function in ext/openssl/openssl.c in PHP before 5.4.44, 5.5.x before 5.5.28, and 5.6.x before 5.6.12 incorrectly relies on the deprecated RAND_pseudo_bytes function, which makes it easier for remote attackers to defeat cryp... Read more
- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
9.6
CRITICALCVE-2015-8866
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Enti... Read more
- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-8834
Cross-site scripting (XSS) vulnerability in wp-includes/wp-db.php in WordPress before 4.2.2 allows remote attackers to inject arbitrary web script or HTML via a long comment that is improperly stored because of limitations on the MySQL TEXT data type. NO... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7989
Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714.... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-5715
The mw_editPost function in wp-includes/class-wp-xmlrpc-server.php in the XMLRPC subsystem in WordPress before 4.3.1 allows remote authenticated users to bypass intended access restrictions, and arrange for a private post to be published and sticky, via u... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-5714
Cross-site scripting (XSS) vulnerability in WordPress before 4.3.1 allows remote attackers to inject arbitrary web script or HTML by leveraging the mishandling of unclosed HTML elements during processing of shortcode tags.... Read more
Affected Products : wordpress- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9767
Directory traversal vulnerability in the ZipArchive::extractTo function in ext/zip/php_zip.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13 and ext/zip/ext_zip.cpp in HHVM before 3.12.1 allows remote attackers to create arbitrary empty... Read more
- Published: May. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1402
The Active Directory (AD) integration component in Cisco Identity Service Engine (ISE) before 1.2.0.899 patch 7, when AD group-membership authorization is enabled, allows remote attackers to cause a denial of service (authentication outage) via a crafted ... Read more
- Published: May. 21, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1401
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Computing System (UCS) Central Software 1.4(1a) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCuy91250.... Read more
Affected Products : unified_computing_system_central_software- Published: May. 21, 2016
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2016-4441
The get_cmd function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check DMA length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) via unsp... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
6.7
MEDIUMCVE-2016-4439
The esp_reg_write function in hw/scsi/esp.c in the 53C9X Fast SCSI Controller (FSC) support in QEMU does not properly check command buffer length, which allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU proces... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-4348
The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via circular definitions in an SVG document.... Read more
- Published: May. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-3739
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7.49.0, when using SSLv3 or making a TLS connection to a URL that uses a numerical IP address, allow remote... Read more
Affected Products : curl- Published: May. 20, 2016
- Modified: Apr. 12, 2025