Latest CVE Feed
-
9.8
CRITICALCVE-2015-4116
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2015-3412
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path fun... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load ... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-3152
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack,... Read more
Affected Products : fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_tus mysql enterprise_linux_eus mariadb +2 more products- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-0236
file before 5.18, as used in the Fileinfo component in PHP before 5.6.0, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a zero root_storage value in a CDF file, related to cdf.c and readcdf.c.... Read more
Affected Products : php- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0390
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : algo_one- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0381
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value.... Read more
Affected Products : cognos_tm1- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0341
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1671
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1670
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a rend... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1669
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overf... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1668
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1667
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attacke... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1666
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1665
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1664
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to ... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1663
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows r... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1662
extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unsp... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2016-1661
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or pos... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1660
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025