Latest CVE Feed
-
5.8
MEDIUMCVE-2015-8688
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.... Read more
Affected Products : gajim- EPSS Score: %0.56
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-8685
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.... Read more
- EPSS Score: %0.21
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
6.2
MEDIUMCVE-2015-8675
Huawei S5300 Campus Series switches with software before V200R005SPH008 do not mask the password when uploading files, which allows physically proximate attackers to obtain sensitive password information by reading the display.... Read more
- EPSS Score: %0.03
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1898
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains an arbitrary line of ... Read more
- EPSS Score: %33.18
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-1897
FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (HLS) M3U8 file, leading to an external HTTP request in which the URL string contains the first line of a lo... Read more
- EPSS Score: %57.76
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0860
Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC request.... Read more
- EPSS Score: %1.28
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0859
Integer overflow in the Kernel service in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted RPC request.... Read more
- EPSS Score: %1.79
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0858
Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted request.... Read more
- EPSS Score: %1.15
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0857
Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %8.21
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0856
Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %60.94
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0855
Directory traversal vulnerability in Advantech WebAccess before 8.1 allows remote attackers to list arbitrary virtual-directory files via unspecified vectors.... Read more
- EPSS Score: %3.55
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0854
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess Dashboard Viewer in Advantech WebAccess before 8.1 allows remote attackers to write to files of arbitrary types via unspecified vector... Read more
- EPSS Score: %73.70
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0853
Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.... Read more
- EPSS Score: %0.52
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0852
Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecified vectors.... Read more
- EPSS Score: %0.17
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0851
Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.... Read more
- EPSS Score: %0.24
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-8281
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows attackers to bypass filesystem encryption via XOR calculations.... Read more
Affected Products : web_viewer- EPSS Score: %0.16
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8280
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.... Read more
Affected Products : web_viewer- EPSS Score: %0.49
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
8.6
HIGHCVE-2015-8279
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.... Read more
Affected Products : web_viewer- EPSS Score: %52.23
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6467
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.... Read more
- EPSS Score: %0.62
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6423
The DCERPC Inspection implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 through 9.5.1 allows remote authenticated users to bypass an intended DCERPC-only ACL by sending arbitrary network traffic, aka Bug ID CSCuu67782.... Read more
- EPSS Score: %0.15
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025