Latest CVE Feed
-
6.5
MEDIUMCVE-2016-2191
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2016-2084
F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM ... Read more
Affected Products : big-ip_access_policy_manager big-ip_advanced_firewall_manager big-ip_analytics big-ip_application_acceleration_manager big-ip_application_security_manager big-ip_domain_name_system big-ip_global_traffic_manager big-ip_link_controller big-ip_local_traffic_manager big-ip_policy_enforcement_manager +8 more products- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2058
Multiple cross-site scripting (XSS) vulnerabilities in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow (1) remote Xymon clients to inject arbitrary web script or HTML via a status-message, which is not properly handled in the "detailed status" page, or ... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-2057
lib/xymond_ipc.c in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 use weak permissions (666) for an unspecified IPC message queue, which allows local users to inject arbitrary messages by writing to that queue.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-2056
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2055
xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration directory via a "config" command.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-2054
Multiple buffer overflows in xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a long filename, involving handling a "config" command.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0775
Buffer overflow in the ImagingFliDecode function in libImaging/FliDecode.c in Pillow before 3.1.1 allows remote attackers to cause a denial of service (crash) via a crafted FLI file.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0740
Buffer overflow in the ImagingLibTiffDecode function in libImaging/TiffDecode.c in Pillow before 3.1.1 allows remote attackers to overwrite memory via a crafted TIFF file.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-8807
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to in... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2015-8843
The Foxit Cloud Update Service (FoxitCloudUpdateService) in Foxit Reader 6.1 through 6.2.x and 7.x before 7.2.2, when an update to the Cloud plugin is available, allows local users to gain privileges by writing crafted data to a shared memory region, whic... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-8606
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework before 3.1.16 and 3.2.x before 3.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) Locale or (2) FailedLoginCount parameter to admin/security/E... Read more
Affected Products : silverstripe- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
8.6
HIGHCVE-2015-8555
Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via u... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-8553
Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decoding control bits. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-0777.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
4.4
MEDIUMCVE-2015-8552
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by l... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
6.0
MEDIUMCVE-2015-8551
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by le... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8080
Integer overflow in the getnum function in lua_struct.c in Redis 2.8.x before 2.8.24 and 3.0.x before 3.0.6 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and applicati... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2015-7555
Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-7545
The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 do not properly restrict the allowed protocols, which might allow remote attackers to execute arb... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-0861
model/modelstorage.py in trytond 3.2.x before 3.2.10, 3.4.x before 3.4.8, 3.6.x before 3.6.5, and 3.8.x before 3.8.1 allows remote authenticated users to bypass intended access restrictions and write to arbitrary fields via a sequence of records.... Read more
- Published: Apr. 13, 2016
- Modified: Apr. 12, 2025