Latest CVE Feed
-
7.8
HIGHCVE-2015-7362
Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local users to gain privileges via the helper/subroc setuid program.... Read more
Affected Products : forticlient- EPSS Score: %0.04
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
4.7
MEDIUMCVE-2015-7328
Puppet Server in Puppet Enterprise before 3.8.x before 3.8.3 and 2015.2.x before 2015.2.3 uses world-readable permissions for the private key of the Certification Authority (CA) certificate during the initial installation and configuration, which might al... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.03
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6856
Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a 0x0022201c IOCTL call.... Read more
Affected Products : pre-boot_authentication_driver- EPSS Score: %0.08
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2015-5259
Integer overflow in the read_string function in libsvn_ra_svn/marshal.c in Apache Subversion 1.9.x before 1.9.3 allows remote attackers to execute arbitrary code via an svn:// protocol string, which triggers a heap-based buffer overflow and an out-of-boun... Read more
Affected Products : subversion- EPSS Score: %40.68
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-5254
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.... Read more
- EPSS Score: %80.39
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1131
Buffer overflow in the CL_vsprintf function in Takumi Yamada DX Library before 3.16 allows remote attackers to execute arbitrary code via a crafted string.... Read more
Affected Products : dx_library- EPSS Score: %1.39
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-8261
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized XML objects, which allows remote attackers to conduct SQL injection attacks via a crafted SOAP request.... Read more
- EPSS Score: %4.36
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
8.4
HIGHCVE-2015-6862
HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.... Read more
Affected Products : ucmdb_browser- EPSS Score: %0.47
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2015-6434
Cisco Prime Infrastructure does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.24
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-6433
SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.16
- Published: Jan. 08, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6647
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24441554.... Read more
Affected Products : android- EPSS Score: %0.17
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-6646
The System V IPC implementation in the kernel in Android before 6.0 2016-01-01 allows attackers to cause a denial of service (global kernel resource consumption) by leveraging improper interaction between IPC resource allocation and the memory manager, ak... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2015-6645
SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a crafted application, aka internal bug 23591205.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2015-6644
Bouncy Castle in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information via a crafted application, aka internal bug 24106146.... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2015-6643
Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset protection mechanism via unspecified vectors, aka internal bug 25290269.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-6642
The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, via unknown vectors, as demonstrated by obtaining Signature or SignatureOrSy... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
3.1
LOWCVE-2015-6641
Bluetooth in Android 6.0 before 2016-01-01 allows remote attackers to obtain sensitive Contacts information by leveraging pairing, aka internal bug 23607427.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6640
The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is accessed in a certain update action, which allows attackers to gain privileges or cause a denial of service ... Read more
Affected Products : android- EPSS Score: %0.10
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6639
The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application that leverages QSEECOM access, aka internal bug 24446875.... Read more
Affected Products : android- EPSS Score: %7.80
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2015-6638
The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 24673908.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jan. 06, 2016
- Modified: Apr. 12, 2025