Latest CVE Feed
-
5.4
MEDIUMCVE-2016-2040
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search... Read more
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2039
libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.... Read more
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2038
phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more
- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1927
The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-fo... Read more
Affected Products : phpmyadmin- Published: Feb. 20, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1335
The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a con... Read more
Affected Products : asr_5000_series_software- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.7
MEDIUMCVE-2016-1156
LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.... Read more
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2016-1154
SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : ec-cube_help_plugin- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2015-7769
baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : basercms- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2271
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.... Read more
Affected Products : xen- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-2270
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.... Read more
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2509
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitiv... Read more
Affected Products : hirschmann_firmware hirschmann_l2b hirschmann_l2e hirschmann_l2p hirschmann_l3e hirschmann_l3p- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-1987
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.... Read more
Affected Products : hp-ux_ipfilter- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0069
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0068.... Read more
Affected Products : internet_explorer- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0068
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.... Read more
Affected Products : internet_explorer- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2015-8151
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-8150
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8149
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8148
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2015-5970
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.... Read more
Affected Products : zenworks_configuration_management- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0795
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.... Read more
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025