Latest CVE Feed
-
5.5
MEDIUMCVE-2016-2271
VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.... Read more
Affected Products : xen- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-2270
Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.... Read more
- Published: Feb. 19, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-2509
The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitiv... Read more
Affected Products : hirschmann_firmware hirschmann_l2b hirschmann_l2e hirschmann_l2p hirschmann_l3e hirschmann_l3p- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
5.9
MEDIUMCVE-2016-1987
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.... Read more
Affected Products : hp-ux_ipfilter- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0069
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0068.... Read more
Affected Products : internet_explorer- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0068
Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.... Read more
Affected Products : internet_explorer- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.1
CRITICALCVE-2015-8151
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-8150
Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8149
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-8148
The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.... Read more
Affected Products : encryption_management_server- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2015-5970
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.... Read more
Affected Products : zenworks_configuration_management- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0795
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.... Read more
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0794
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.... Read more
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
8.1
HIGHCVE-2015-7547
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary cod... Read more
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2015-8287
Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL.... Read more
- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-8286
Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.... Read more
Affected Products : raysharp_firmware- Published: Feb. 18, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2398
Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions.... Read more
Affected Products : xfinity_home_security_system- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
5.3
MEDIUMCVE-2016-1334
Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.... Read more
Affected Products : small_business_wireless_access_points_firmware- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2016-1333
Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.... Read more
Affected Products : ios- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-2397
The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.... Read more
- Published: Feb. 17, 2016
- Modified: Apr. 12, 2025