Latest CVE Feed
-
8.8
HIGHCVE-2016-1667
The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.0.2661.102, does not prevent script execution during node-adoption operations, which allows remote attacke... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1666
Multiple unspecified vulnerabilities in Google Chrome before 50.0.2661.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-1665
The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison operators, which allows remote attackers to obtain sensitive information via crafted JavaScript code.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1664
The HistoryController::UpdateForCommit function in content/renderer/history_controller.cc in Google Chrome before 50.0.2661.94 mishandles the interaction between subframe forward navigations and other forward navigations, which allows remote attackers to ... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1663
The SerializedScriptValue::transferArrayBuffers function in WebKit/Source/bindings/core/v8/SerializedScriptValue.cpp in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.94, mishandles certain array-buffer data structures, which allows r... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1662
extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unsp... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.3
HIGHCVE-2016-1661
Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same Origin Policy check, which allows remote attackers to cause a denial of service (memory corruption) or pos... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1660
Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-4325
Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.... Read more
Affected Products : xprintserver_firmware- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2298
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.7
HIGHCVE-2016-2297
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to execute arbitrary commands via an "access command shell-like feature."... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.4
CRITICALCVE-2016-2296
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pages, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-1207
Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject... Read more
Affected Products : wn-g300r3_firmware wn-g300r2_firmware wn-g300r_firmware wn-g300r2 wn-g300r3 wn-g300r- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1206
The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2016
Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, def... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-2015
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.... Read more
Affected Products : system_management_homepage- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1209
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in a POST request.... Read more
Affected Products : ninja_forms- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1208
The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.... Read more
- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-8530
Stack-based buffer overflow in the Initialize function in an ActiveX control in IBM SPSS Statistics 19 and 20 before 20.0.0.2-IF0008, 21 before 21.0.0.2-IF0010, 22 before 22.0.0.2-IF0011, 23 before 23.0.0.3-IF0001, and 24 before 24.0.0.0-IF0003 allows rem... Read more
Affected Products : spss_statistics- Published: May. 14, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1399
The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 15.2(2)EB1 on Industrial Ethernet 5000 devices allows remote attackers to cause a denial of service (packet... Read more
Affected Products : ios ios ie-5000-12s12p-10g ie-5000-16s12p ie-4000-16gt4g-e ie-4000-16t4g-e ie-4000-4gc4gp4g-e ie-4000-4gs8gp4g-e ie-4000-4s8p4g-e ie-4000-4t4p4g-e +6 more products- Published: May. 14, 2016
- Modified: Apr. 12, 2025