Latest CVE Feed
-
7.5
HIGHCVE-2015-4605
The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly restrict a certain offset value, which allows remote attackers to cause a denial of servi... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-4604
The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, does not properly maintain a certain pointer relationship, which allows remote attackers to cause a denial o... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4603
The exception::getTraceAsString function in Zend/zend_exceptions.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to execute arbitrary code via an unexpected data type, related to a "type confusion" issue.... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4602
The __PHP_Incomplete_Class function in ext/standard/incomplete_class.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an une... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4601
PHP before 5.6.7 might allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confusion" issues in (1) ext/soap/php_encoding.c, (2) ext/soap/php_http.c, and ... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4600
The SoapClient implementation in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an unexpected data type, related to "type confu... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-4599
The SoapFault::__toString method in ext/soap/soap.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information, cause a denial of service (application crash), or possibly execute arbitrary cod... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-4598
PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument save... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-4116
Use-after-free vulnerability in the spl_ptr_heap_insert function in ext/spl/spl_heap.c in PHP before 5.5.27 and 5.6.x before 5.6.11 allows remote attackers to execute arbitrary code by triggering a failed SplMinHeap::compare operation.... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2015-3412
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read arbitrary files via crafted input to an application that calls the stream_resolve_include_path fun... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-3411
PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load ... Read more
- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-3152
Oracle MySQL before 5.7.3, Oracle MySQL Connector/C (aka libmysqlclient) before 6.1.3, and MariaDB before 5.5.44 use the --ssl option to mean that SSL is optional, which allows man-in-the-middle attackers to spoof servers via a cleartext-downgrade attack,... Read more
Affected Products : fedora debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_tus mysql enterprise_linux_eus mariadb +2 more products- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-0236
file before 5.18, as used in the Fileinfo component in PHP before 5.6.0, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a zero root_storage value in a CDF file, related to cdf.c and readcdf.c.... Read more
Affected Products : php- Published: May. 16, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0390
Cross-site scripting (XSS) vulnerability in IBM Algorithmics Algo One Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
Affected Products : algo_one- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0381
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value.... Read more
Affected Products : cognos_tm1- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0341
IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which might allow remote attackers to obtain sensitive information by sniffing the network.... Read more
- Published: May. 15, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-1671
Google Chrome before 50.0.2661.102 on Android mishandles / (slash) and \ (backslash) characters, which allows attackers to conduct directory traversal attacks via a file: URL, related to net/base/escape.cc and net/base/filename_util.cc.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1670
Race condition in the ResourceDispatcherHostImpl::BeginRequest function in content/browser/loader/resource_dispatcher_host_impl.cc in Google Chrome before 50.0.2661.102 allows remote attackers to make arbitrary HTTP requests by leveraging access to a rend... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1669
The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overf... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1668
The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.102, uses an improper creation context, which allows remote attackers to bypass the Same Origin Policy via a... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025