Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2016-2055

    xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.... Read more

    Affected Products : debian_linux xymon
    • EPSS Score: %68.00
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-2054

    Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.... Read more

    Affected Products : debian_linux xymon
    • EPSS Score: %4.09
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0775

    Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.... Read more

    Affected Products : debian_linux pillow
    • EPSS Score: %1.37
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0740

    Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.... Read more

    Affected Products : debian_linux pillow
    • EPSS Score: %0.27
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2015-8807

    Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to in... Read more

    Affected Products : fedora debian_linux groupware
    • EPSS Score: %0.68
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.4

    HIGH
    CVE-2015-8843

    The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, whic... Read more

    Affected Products : foxit_reader reader
    • EPSS Score: %0.00
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2015-8606

    Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/E... Read more

    Affected Products : silverstripe
    • EPSS Score: %0.41
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 8.6

    HIGH
    CVE-2015-8555

    Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via u... Read more

    Affected Products : xen xenserver
    • EPSS Score: %0.55
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-8553

    Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.... Read more

    Affected Products : enterprise_linux xen
    • EPSS Score: %0.27
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 4.4

    MEDIUM
    CVE-2015-8552

    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by l... Read more

    • EPSS Score: %0.19
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 6.0

    MEDIUM
    CVE-2015-8551

    The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by le... Read more

    • EPSS Score: %0.07
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8080

    Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and applicati... Read more

    Affected Products : debian_linux leap openstack opensuse redis
    • EPSS Score: %1.21
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2015-7555

    Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.... Read more

    Affected Products : fedora giflib
    • EPSS Score: %0.30
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2015-7545

    The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arb... Read more

    • EPSS Score: %22.02
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-0861

    model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.... Read more

    Affected Products : debian_linux trytond
    • EPSS Score: %0.25
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-4007

    Multiple unspecified vulnerabilities in the obs-service-extract_file package before 0.3-5.1 in openSUSE Leap 42.1 and before 0.3-3.1 in openSUSE 13.2 allow attackers to execute arbitrary commands via a service definition, related to executing unzip with "... Read more

    Affected Products : leap opensuse
    • EPSS Score: %1.31
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-2780

    Untrusted search path vulnerability in Huawei UTPS before UTPS-V200R003B015D15SP00C983 allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL in an unspecified directory.... Read more

    Affected Products : utps_firmware
    • EPSS Score: %0.02
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 5.7

    MEDIUM
    CVE-2016-2116

    Memory leak in the jas_iccprof_createfrombuf function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (memory consumption) via a crafted ICC color profile in a JPEG 2000 image file.... Read more

    Affected Products : ubuntu_linux jasper
    • EPSS Score: %9.33
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1577

    Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a dif... Read more

    Affected Products : ubuntu_linux jasper
    • EPSS Score: %9.81
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2016-1496

    The graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 allows attackers to cause a ... Read more

    Affected Products : p8_firmware p8
    • EPSS Score: %0.07
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292318 Results