Latest CVE Feed
-
10.0
HIGHCVE-2016-1629
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.... Read more
- EPSS Score: %3.09
- Published: Feb. 21, 2016
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2015-7425
The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Protect for Virtual Environments) 6.3 before 6.3.2.5, 6.4 before 6.4.3.1, and 7.1 before 7.1.4 and Tiv... Read more
- EPSS Score: %9.88
- Published: Feb. 21, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2275
The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via... Read more
- EPSS Score: %0.29
- Published: Feb. 21, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1628
pi.c in OpenJPEG, as used in PDFium in Google Chrome before 48.0.2564.109, does not validate a certain precision value, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a crafted JPEG 2000 image... Read more
- EPSS Score: %0.91
- Published: Feb. 21, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2045
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.... Read more
- EPSS Score: %0.30
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2044
libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more
- EPSS Score: %0.40
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2043
Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the norma... Read more
- EPSS Score: %0.40
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2042
phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an... Read more
- EPSS Score: %0.60
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2041
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restriction... Read more
- EPSS Score: %1.08
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2040
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search... Read more
- EPSS Score: %0.51
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2039
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.... Read more
- EPSS Score: %0.54
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2038
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more
- EPSS Score: %0.93
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1927
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-fo... Read more
Affected Products : phpmyadmin- EPSS Score: %0.62
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1335
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a con... Read more
Affected Products : asr_5000_series_software- EPSS Score: %2.91
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-1156
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.... Read more
- EPSS Score: %0.41
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-1154
SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : ec-cube_help_plugin- EPSS Score: %0.88
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-7769
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.59
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2271
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.... Read more
Affected Products : xen- EPSS Score: %0.07
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-2270
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.... Read more
- EPSS Score: %0.28
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2509
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitiv... Read more
Affected Products : hirschmann_firmware hirschmann_l2b hirschmann_l2e hirschmann_l2p hirschmann_l3e hirschmann_l3p- EPSS Score: %0.02
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025