Latest CVE Feed
-
5.3
MEDIUMCVE-2015-6485
Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3030M RTUs with firmware before C3414-500-S02J2, allow remote attackers to obtain sensitive information fro... Read more
Affected Products : telvent_rtu_firmware sage_1410 sage_1430 sage_1450 sage_2400 sage_3030m sage_landac_ii-2 sage_2300- EPSS Score: %0.42
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-2088
resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option.... Read more
Affected Products : bind- EPSS Score: %48.56
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
8.6
HIGHCVE-2016-1286
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c.... Read more
Affected Products : ubuntu_linux fedora debian_linux leap junos opensuse linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit bind +37 more products- EPSS Score: %54.99
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1285
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed pack... Read more
Affected Products : ubuntu_linux fedora debian_linux leap junos opensuse linux_enterprise_server linux_enterprise_desktop linux_enterprise_software_development_kit bind +37 more products- EPSS Score: %64.26
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0886
EMC Documentum xCP 2.1 before patch 24 and 2.2 before patch 12 allows remote authenticated users to obtain sensitive user-account metadata via a members/xcp_member API call.... Read more
Affected Products : documentum_xcp- EPSS Score: %0.20
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6184
The CAttrArray object implementation in Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and memory corruption) via a malformed Cascading Style Sheets (CSS) token seque... Read more
- EPSS Score: %49.66
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1327
Buffer overflow in the web server on Cisco DPC2203 and EPC2203 devices with firmware r1_customer_image allows remote attackers to execute arbitrary code via a crafted HTTP request, aka Bug ID CSCuv05935.... Read more
- EPSS Score: %3.58
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1326
The administration interface on Cisco DPQ3925 devices with firmware r1 allows remote attackers to cause a denial of service (device restart) via a crafted HTTP request, aka Bug ID CSCup48105.... Read more
- EPSS Score: %0.32
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1325
The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCus49506.... Read more
- EPSS Score: %0.18
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1312
The HTTPS inspection engine in the Content Security and Control Security Services Module (CSC-SSM) 6.6 before 6.6.1164.0 for Cisco ASA 5500 devices allows remote attackers to cause a denial of service (memory consumption or device reload) via a flood of H... Read more
- EPSS Score: %0.74
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2774
ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attackers to cause a denial of service (INSIST assertion failure or request-processing outage) by establishing ... Read more
- EPSS Score: %69.96
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1009
Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %6.14
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-1008
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain priv... Read more
- EPSS Score: %0.12
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1007
Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %6.14
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0954
Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
Affected Products : digital_editions- EPSS Score: %33.66
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0134
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 2010 SP2 and 2013 SP1, Off... Read more
Affected Products : office word word_viewer sharepoint_server office_compatibility_pack office_web_apps_server word_for_mac- EPSS Score: %38.56
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-0133
The USB Mass Storage Class driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows physically proximate attackers to execut... Read more
Affected Products : windows_10 windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_vista- EPSS Score: %0.49
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0132
Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML documents, which allows remote attackers to spoof signatures via a modified document, aka ".NET XML Validation Sec... Read more
Affected Products : .net_framework- EPSS Score: %32.65
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-0130
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0116, CVE-2016-0123, CV... Read more
Affected Products : edge- EPSS Score: %20.18
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-0129
Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0116, CVE-2016-0123, CV... Read more
Affected Products : edge- EPSS Score: %20.18
- Published: Mar. 09, 2016
- Modified: Apr. 12, 2025