Latest CVE Feed
-
9.0
HIGHCVE-2016-0766
PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to unspecified custom configuration settings (GUCS) for PL/Java, which allows attackers to gain privileges via... Read more
- EPSS Score: %0.97
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2013-7447
Integer overflow in the gdk_cairo_set_source_pixbuf function in gdk/gdkcairo.c in GTK+ before 3.9.8, as used in eom, gnome-photos, eog, gambas3, thunar, pinpoint, and possibly other applications, allows remote attackers to cause a denial of service (crash... Read more
- EPSS Score: %8.45
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1153
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different vulnerability than CVE-2015-8489.... Read more
Affected Products : office- EPSS Score: %0.58
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1152
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2015-8486.... Read more
Affected Products : office- EPSS Score: %0.24
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1151
Multiple cross-site request forgery (CSRF) vulnerabilities in Cybozu Office 9.9.0 through 10.3.0 allow remote attackers to hijack the authentication of arbitrary users.... Read more
Affected Products : office- EPSS Score: %0.13
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1150
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-779... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1149
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2015-779... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-8489
customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a crafted CSV file, a different vulnerability than CVE-2016-1153.... Read more
Affected Products : office- EPSS Score: %0.58
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8488
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487.... Read more
Affected Products : office- EPSS Score: %0.31
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-8487
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488.... Read more
Affected Products : office- EPSS Score: %0.31
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-8486
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8485, and CVE-2016-1152.... Read more
Affected Products : office- EPSS Score: %0.24
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-8485
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via unspecified vectors, a different vulnerability than CVE-2015-8484, CVE-2015-8486, and CVE-2016-1152.... Read more
Affected Products : office- EPSS Score: %0.24
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-8484
Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a different vulnerability than CVE-2015-8485, CVE-2015-8486, and CVE-2016-1152.... Read more
Affected Products : office- EPSS Score: %0.24
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2015-8483
Open redirect vulnerability in Cybozu Office 10.2.0 through 10.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.... Read more
Affected Products : office- EPSS Score: %0.27
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-7798
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7797, CVE-2016-114... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-7797
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7796, CVE-2015-7798, CVE-2016-114... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-7796
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7795, CVE-2015-7797, CVE-2015-7798, CVE-2016-114... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-7795
Cross-site scripting (XSS) vulnerability in Cybozu Office 9.0.0 through 10.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-7796, CVE-2015-7797, CVE-2015-7798, CVE-2016-114... Read more
Affected Products : office- EPSS Score: %0.52
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-2389
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMII) component 15.0 for SAP NetWeaver 7.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the Path parameter to /Ca... Read more
Affected Products : netweaver- EPSS Score: %80.79
- Published: Feb. 16, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2388
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP request, aka SAP Security Note 2256846.... Read more
- Actively Exploited
- EPSS Score: %47.94
- Published: Feb. 16, 2016
- Modified: Apr. 12, 2025