Latest CVE Feed
-
7.7
HIGHCVE-2015-7974
NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."... Read more
- EPSS Score: %3.67
- Published: Jan. 26, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1298
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.... Read more
Affected Products : unified_contact_center_express- EPSS Score: %0.23
- Published: Jan. 26, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-6337
Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CSCuw47... Read more
Affected Products : application_policy_infrastructure_controller_enterprise_module- EPSS Score: %0.25
- Published: Jan. 26, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-2052
Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from ... Read more
- EPSS Score: %0.47
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2051
Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- EPSS Score: %0.30
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-1620
Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
Affected Products : chrome- EPSS Score: %1.43
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-1619
Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read) o... Read more
Affected Products : chrome- EPSS Score: %0.80
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1618
Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vect... Read more
Affected Products : chrome- EPSS Score: %0.91
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1617
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more
Affected Products : chrome- EPSS Score: %0.64
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1616
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more
Affected Products : chrome- EPSS Score: %1.18
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1615
The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.... Read more
Affected Products : chrome- EPSS Score: %0.76
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1614
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive ... Read more
Affected Products : chrome- EPSS Score: %0.79
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-1613
Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, rel... Read more
Affected Products : chrome- EPSS Score: %0.87
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-1612
The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of servic... Read more
Affected Products : chrome- EPSS Score: %1.03
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7417
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.17
- Published: Jan. 23, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6317
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.... Read more
Affected Products : identity_services_engine_software- EPSS Score: %0.14
- Published: Jan. 23, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-1572
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.... Read more
- EPSS Score: %0.05
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2016-1571
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address ... Read more
- EPSS Score: %0.30
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2016-1570
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier... Read more
Affected Products : xen- EPSS Score: %0.20
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-7744
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attacker... Read more
- EPSS Score: %3.42
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025