Total
1059 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-3883 | 1 Google | 1 Android | 2017-08-12 | 4.3 MEDIUM | 5.5 MEDIUM |
internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not properly construct warnings about premium SMS messages, which allows attackers to spoof the premium-payment confirmation dialog via a crafted application, aka internal bug 28557603. | |||||
CVE-2016-3898 | 1 Google | 1 Android | 2017-08-12 | 4.3 MEDIUM | 5.5 MEDIUM |
Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of service (loss of locked-screen 911 TTY functionality) via a crafted application that modifies the TTY mode by broadcasting an intent, aka internal bug 29832693. | |||||
CVE-2016-3880 | 1 Google | 1 Android | 2017-08-12 | 7.1 HIGH | 5.5 MEDIUM |
Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 25747670. | |||||
CVE-2016-3899 | 1 Google | 1 Android | 2017-08-12 | 7.1 HIGH | 5.5 MEDIUM |
OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not validate a certain pointer, which allows remote attackers to cause a denial of service (device hang or reboot) via a crafted media file, aka internal bug 29421811. | |||||
CVE-2016-3863 | 1 Google | 1 Android | 2017-08-12 | 6.8 MEDIUM | 7.8 HIGH |
Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allow remote attackers to execute arbitrary code via a crafted media file, aka internal bug 29161888. | |||||
CVE-2015-7887 | 1 Netapp | 1 Snapcenter Server | 2017-08-10 | 6.5 MEDIUM | 8.1 HIGH |
NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. | |||||
CVE-2014-9830 | 1 Imagemagick | 1 Imagemagick | 2017-08-08 | 6.8 MEDIUM | 8.8 HIGH |
coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file. | |||||
CVE-2014-9831 | 1 Imagemagick | 1 Imagemagick | 2017-08-08 | 6.8 MEDIUM | 8.8 HIGH |
coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file. | |||||
CVE-2014-9827 | 1 Imagemagick | 1 Imagemagick | 2017-08-08 | 6.8 MEDIUM | 8.8 HIGH |
coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file. | |||||
CVE-2014-9828 | 1 Imagemagick | 1 Imagemagick | 2017-08-08 | 6.8 MEDIUM | 8.8 HIGH |
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file. | |||||
CVE-2016-5283 | 1 Mozilla | 1 Firefox | 2017-07-29 | 6.8 MEDIUM | 8.8 HIGH |
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized. | |||||
CVE-2016-4694 | 1 Apple | 2 Mac Os X, Os X Server | 2017-07-29 | 7.5 HIGH | 9.1 CRITICAL |
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue, a related issue to CVE-2016-5387. | |||||
CVE-2016-4760 | 2 Apple, Microsoft | 4 Iphone Os, Itunes, Safari and 1 more | 2017-07-29 | 4.3 MEDIUM | 6.5 MEDIUM |
WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against non-HTTP Safari sessions by leveraging HTTP/0.9 support. | |||||
CVE-2016-6958 | 3 Adobe, Apple, Microsoft | 6 Acrobat, Acrobat Dc, Acrobat Reader Dc and 3 more | 2017-07-29 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass intended access restrictions via unspecified vectors. | |||||
CVE-2016-5273 | 1 Mozilla | 1 Firefox | 2017-07-29 | 6.8 MEDIUM | 8.8 HIGH |
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site. | |||||
CVE-2016-5604 | 1 Oracle | 1 Enterprise Manager Base Platform | 2017-07-28 | 3.3 LOW | 6.3 MEDIUM |
Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563. | |||||
CVE-2016-8293 | 1 Oracle | 1 Peoplesoft Enterprise Peopletools | 2017-07-28 | 5.8 MEDIUM | 8.2 HIGH |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Integration Broker, a different vulnerability than CVE-2016-5529 and CVE-2016-5530. | |||||
CVE-2016-8292 | 1 Oracle | 1 Peoplesoft Enterprise Human Capital Management Talent Acquisition Manager | 2017-07-28 | 5.8 MEDIUM | 4.2 MEDIUM |
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to Talent Acquisition Manager. | |||||
CVE-2016-8291 | 1 Oracle | 1 Peoplesoft Enterprise Peopletools | 2017-07-28 | 5.8 MEDIUM | 8.2 HIGH |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to affect confidentiality and integrity via vectors related to Mobile Application Platform. | |||||
CVE-2016-8285 | 1 Oracle | 1 Peoplesoft Enterprise Human Capital Management Candidate Gateway | 2017-07-28 | 4.9 MEDIUM | 4.8 MEDIUM |
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.2 allows remote administrators to affect confidentiality and integrity via vectors related to Candidate Gateway. |