Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4258 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262. | |||||
CVE-2016-4259 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262. | |||||
CVE-2016-4260 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4261, and CVE-2016-4262. | |||||
CVE-2016-4261 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, and CVE-2016-4262. | |||||
CVE-2016-4262 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4256, CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, and CVE-2016-4261. | |||||
CVE-2016-4263 | 1 Adobe | 1 Digital Editions | 2017-08-12 | 10.0 HIGH | 9.8 CRITICAL |
Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2016-4304 | 1 Kaspersky | 1 Internet Security | 2017-08-12 | 2.1 LOW | 5.5 MEDIUM |
A denial of service vulnerability exists in the syscall filtering functionality of the Kaspersky Internet Security KLIF driver. A specially crafted native api call request can cause a access violation exception in KLIF kernel driver resulting in local denial of service. An attacker can run program from user-mode to trigger this vulnerability. | |||||
CVE-2016-4305 | 1 Kaspersky | 1 Internet Security | 2017-08-12 | 2.1 LOW | 5.5 MEDIUM |
A denial of service vulnerability exists in the syscall filtering functionality of Kaspersky Internet Security KLIF driver. A specially crafted native api call can cause a access violation in KLIF kernel driver resulting in local denial of service. An attacker can run program from user-mode to trigger this vulnerability. | |||||
CVE-2016-4306 | 1 Kaspersky | 1 Total Security | 2017-08-12 | 2.1 LOW | 5.5 MEDIUM |
Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cause the driver to return out-of-bounds kernel memory, potentially leaking sensitive information such as privileged tokens or kernel memory addresses that may be useful in bypassing kernel mitigations. An unprivileged user can run a program from user-mode to trigger this vulnerability. | |||||
CVE-2016-4307 | 1 Kaspersky | 1 Internet Security | 2017-08-12 | 2.1 LOW | 5.5 MEDIUM |
A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability. | |||||
CVE-2016-4382 | 1 Hp | 1 Performance Center | 2017-08-12 | 6.0 MEDIUM | 8.3 HIGH |
HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to a "remote user validation failure" issue. | |||||
CVE-2016-4620 | 1 Apple | 1 Iphone Os | 2017-08-12 | 4.3 MEDIUM | 3.3 LOW |
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to directory metadata for SMS draft directories, which allows attackers to discover text-message recipients via a crafted app. | |||||
CVE-2016-4704 | 1 Apple | 1 Xcode | 2017-08-12 | 7.2 HIGH | 7.8 HIGH |
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4705. | |||||
CVE-2016-4705 | 1 Apple | 1 Xcode | 2017-08-12 | 7.2 HIGH | 7.8 HIGH |
otool in Apple Xcode before 8 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via unspecified vectors, a different vulnerability than CVE-2016-4704. | |||||
CVE-2016-4719 | 1 Apple | 2 Iphone Os, Watchos | 2017-08-12 | 4.3 MEDIUM | 5.5 MEDIUM |
The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attackers to discover physical locations via a crafted application. | |||||
CVE-2016-4740 | 1 Apple | 1 Iphone Os | 2017-08-12 | 1.9 LOW | 2.9 LOW |
Apple iOS before 10, when Handoff for Messages is used, does not ensure that a Messages signin has occurred before displaying messages, which might allow attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-4741 | 1 Apple | 1 Iphone Os | 2017-08-12 | 4.3 MEDIUM | 5.9 MEDIUM |
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software updates via vectors related to lack of an HTTPS session for retrieving updates. | |||||
CVE-2016-4746 | 1 Apple | 1 Iphone Os | 2017-08-12 | 5.0 MEDIUM | 5.3 MEDIUM |
The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain sensitive information in opportunistic circumstances by leveraging an unintended correction. | |||||
CVE-2016-4747 | 1 Apple | 1 Iphone Os | 2017-08-12 | 4.3 MEDIUM | 3.7 LOW |
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle attackers to discover mail credentials via unspecified vectors. | |||||
CVE-2016-4749 | 1 Apple | 1 Iphone Os | 2017-08-12 | 2.1 LOW | 3.3 LOW |
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users to discover cleartext AirPrint preview content by reading a temporary file. |