Latest CVE Feed
-
7.0
HIGHCVE-2016-1531
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.... Read more
Affected Products : exim- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-0792
Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via serialized data in an XML file, related to XStream and groovy.util.Expando.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0791
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to bypass a CSRF protection mechanism via a brute-force approach.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-0790
Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to determine API tokens via a brute-force approach.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-0789
CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-0788
The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-2511
Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2216
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicod... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-2086
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-0729
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) o... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2015-2774
Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a variant of CVE-2014-3566 (aka POODLE).... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2016-2510
BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8681
The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with so... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8680
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-8679
The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230 and Mate S smartpho... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8319
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, a... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8318
Heap-based buffer overflow in the HIFI driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, a... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-8307
The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B230, GRA-UL00 before GRA-UL00C00B230, and GRA-UL10 before GRA-UL10C00B230, and Mate S smartphones with... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-3975
Cross-site scripting (XSS) vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to inject arbitrary web script or HTML via the navigationTarget parameter to irj/servlet/prt/portal/prteventname/XXX/prtroot/com.sapportals.navigatio... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-3974
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monito... Read more
- Published: Apr. 07, 2016
- Modified: Apr. 12, 2025