Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1617
The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more
Affected Products : chrome- EPSS Score: %0.64
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1616
The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more
Affected Products : chrome- EPSS Score: %1.18
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1615
The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.... Read more
Affected Products : chrome- EPSS Score: %0.76
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1614
The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive ... Read more
Affected Products : chrome- EPSS Score: %0.79
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-1613
Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, rel... Read more
Affected Products : chrome- EPSS Score: %0.87
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
7.6
HIGHCVE-2016-1612
The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of servic... Read more
Affected Products : chrome- EPSS Score: %1.03
- Published: Jan. 25, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7417
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.... Read more
Affected Products : websphere_application_server- EPSS Score: %0.17
- Published: Jan. 23, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2015-6317
Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.... Read more
Affected Products : identity_services_engine_software- EPSS Score: %0.14
- Published: Jan. 23, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2016-1572
mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.... Read more
- EPSS Score: %0.05
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
6.3
MEDIUMCVE-2016-1571
The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address ... Read more
- EPSS Score: %0.30
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
8.5
HIGHCVE-2016-1570
The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier... Read more
Affected Products : xen- EPSS Score: %0.20
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-7744
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attacker... Read more
- EPSS Score: %3.42
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-6925
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.... Read more
Affected Products : wolfssl- EPSS Score: %0.90
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6015
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
- EPSS Score: %19.92
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6014
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
- EPSS Score: %19.92
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6013
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more
- EPSS Score: %19.92
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1984
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerabil... Read more
Affected Products : amx_firmware- EPSS Score: %4.08
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-1135
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WH... Read more
Affected Products : whr-1166dhp_firmware whr-300hp2_firmware wmr-300_firmware bhr-4grv2_firmware wex-300_firmware whr-600d_firmware wmr-433_firmware wsr-1166dhp_firmware whr-300hp2 whr-1166dhp +6 more products- EPSS Score: %0.24
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1134
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earl... Read more
Affected Products : whr-1166dhp_firmware whr-300hp2_firmware wmr-300_firmware bhr-4grv2_firmware wex-300_firmware whr-600d_firmware wmr-433_firmware wsr-1166dhp_firmware whr-300hp2 whr-1166dhp +6 more products- EPSS Score: %0.10
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8362
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerab... Read more
Affected Products : amx_firmware- EPSS Score: %7.47
- Published: Jan. 22, 2016
- Modified: Apr. 12, 2025