Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.4

    HIGH
    CVE-2016-0843

    The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application, aka internal bug 25801197.... Read more

    Affected Products : android
    • EPSS Score: %0.02
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0842

    The H.264 decoder in libstagefright in Android 6.x before 2016-04-01 mishandles Memory Management Control Operation (MMCO) data, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media f... Read more

    Affected Products : android
    • EPSS Score: %0.79
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0841

    media/libmedia/mediametadataretriever.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 mishandles cleared service binders, which allows remote attackers to execute arbitrary code or cause a ... Read more

    Affected Products : android
    • EPSS Score: %1.22
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0840

    Multiple stack-based buffer underflows in decoder/ih264d_parse_cavlc.c in mediaserver in Android 6.x before 2016-04-01 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal... Read more

    Affected Products : android
    • EPSS Score: %0.79
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0839

    post_proc/volume_listener.c in mediaserver in Android 6.x before 2016-04-01 mishandles deleted effect context, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal ... Read more

    Affected Products : android
    • EPSS Score: %1.22
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0838

    Sonivox in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not check for a negative number of samples, which allows remote attackers to execute arbitrary code or cause a denial of service (me... Read more

    Affected Products : android
    • EPSS Score: %2.23
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0837

    MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memor... Read more

    Affected Products : android
    • EPSS Score: %1.22
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0836

    Stack-based buffer overflow in decoder/impeg2d_vld.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 25812590.... Read more

    Affected Products : android
    • EPSS Score: %0.67
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0835

    decoder/impeg2d_dec_hdr.c in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file that triggers a certain negative value, aka internal bug ... Read more

    Affected Products : android
    • EPSS Score: %4.02
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-0834

    An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 26220548.... Read more

    Affected Products : android
    • EPSS Score: %0.67
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 8.4

    HIGH
    CVE-2016-1340

    Heap-based buffer overflow in Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted libclimeta.so filename arguments, aka Bug ID CSCux68837.... Read more

    • EPSS Score: %0.09
    • Published: Apr. 16, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-1339

    Cisco Unified Computing System (UCS) Platform Emulator 2.5(2)TS4, 3.0(2c)A, and 3.0(2c)TS9 allows local users to gain privileges via crafted arguments on a ucspe-copy command line, aka Bug ID CSCux68832.... Read more

    • EPSS Score: %0.23
    • Published: Apr. 16, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-5271

    The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might all... Read more

    Affected Products : openstack tripleo_heat_templates
    • EPSS Score: %0.34
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2016-3144

    Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.... Read more

    Affected Products : fedora block_class
    • EPSS Score: %0.22
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2015-7676

    Ipswitch MOVEit File Transfer (formerly DMZ) 8.1 and earlier, when configured to support file view on download, allows remote authenticated users to conduct cross-site scripting (XSS) attacks by uploading HTML files.... Read more

    Affected Products : moveit_dmz
    • EPSS Score: %0.01
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 8.1

    HIGH
    CVE-2015-5348

    Apache Camel 2.6.x through 2.14.x, 2.15.x before 2.15.5, and 2.16.x before 2.16.1, when using (1) camel-jetty or (2) camel-servlet as a consumer in Camel routes, allow remote attackers to execute arbitrary commands via a crafted serialized Java object in ... Read more

    Affected Products : camel
    • EPSS Score: %6.83
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2016-3961

    Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a denial of service (guest OS crash) by attempting to access a hugetlbfs mapped area.... Read more

    Affected Products : ubuntu_linux xen
    • EPSS Score: %0.13
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2212

    The getOrderByStatusUrlKey function in the Mage_Rss_Helper_Order class in app/code/core/Mage/Rss/Helper/Order.php in Magento Enterprise Edition before 1.14.2.3 and Magento Community Edition before 1.9.2.3 allows remote attackers to obtain sensitive order ... Read more

    Affected Products : magento
    • EPSS Score: %0.13
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2146

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POS... Read more

    Affected Products : fedora mod_auth_mellon
    • EPSS Score: %0.65
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2145

    The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.... Read more

    Affected Products : fedora mod_auth_mellon
    • EPSS Score: %0.80
    • Published: Apr. 15, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292118 Results