Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Total 210374 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-6040 1 Ibm 1 Rational Collaborative Lifecycle Management 2017-02-08 6.0 MEDIUM 5.0 MEDIUM
IBM Jazz Foundation could allow an authenticated user to take over a previously logged in user due to session expiration not being enforced.
CVE-2016-6099 1 Ibm 1 Security Key Lifecycle Manager 2017-02-08 5.0 MEDIUM 5.3 MEDIUM
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.
CVE-2015-0176 1 Ibm 1 Websphere Mq 2017-02-08 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in MQ XR WebSockets Listener in WMQ Telemetry in IBM WebSphere MQ 8.0 before 8.0.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URI that is included in an error response.
CVE-2017-5882 1 Sanadata 1 Sanacms 2017-02-07 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
CVE-2016-8928 1 Ibm 1 Kenexa Lms 2017-02-07 6.5 MEDIUM 7.6 HIGH
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-6163 1 Gnome 1 Librsvg 2017-02-07 4.3 MEDIUM 5.5 MEDIUM
The rsvg_pattern_fix_fallback function in rsvg-paint_server.c in librsvg2 2.40.2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted svg file.
CVE-2016-6234 1 Lepton Project 1 Lepton 2017-02-07 4.3 MEDIUM 5.5 MEDIUM
The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file.
CVE-2016-5966 1 Ibm 1 Security Privileged Identity Manager 2017-02-07 4.3 MEDIUM 5.9 MEDIUM
IBM Security Privileged Identity Manager Virtual Appliance could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVE-2016-6124 1 Ibm 1 Kenexa Lms On Cloud 2017-02-07 6.5 MEDIUM 8.8 HIGH
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
CVE-2016-6236 1 Lepton Project 1 Lepton 2017-02-07 4.3 MEDIUM 5.5 MEDIUM
The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file.
CVE-2016-6116 1 Ibm 1 Security Key Lifecycle Manager 2017-02-07 4.3 MEDIUM 5.9 MEDIUM
IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.
CVE-2016-4352 1 Libavformat Project 1 Libavformat 2017-02-07 4.3 MEDIUM 5.5 MEDIUM
Integer overflow in the demuxer function in libmpdemux/demux_gif.c in Mplayer allows remote attackers to cause a denial of service (crash) via large dimensions in a gif file.
CVE-2016-8929 1 Ibm 1 Kenexa Lms 2017-02-07 5.5 MEDIUM 5.4 MEDIUM
IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2016-6084 1 Ibm 1 Bigfix Platform 2017-02-07 3.3 LOW 6.5 MEDIUM
IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.
CVE-2016-5988 1 Ibm 1 Security Privileged Identity Manager 2017-02-07 4.0 MEDIUM 6.5 MEDIUM
IBM Security Privileged Identity Manager Virtual Appliance could disclose sensitive information in generated error messages that would be available to an authenticated user.
CVE-2016-5990 1 Ibm 1 Security Privileged Identity Manager 2017-02-07 6.5 MEDIUM 6.3 MEDIUM
IBM Security Privileged Identity Manager Virtual Appliance allows an authenticated user to upload malicious files that would be automatically executed by the server.
CVE-2016-6126 1 Ibm 1 Kenexa Lms On Cloud 2017-02-07 4.0 MEDIUM 6.5 MEDIUM
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVE-2016-7544 2 Cryptopp, Microsoft 2 Crypto\+\+, Windows 2017-02-07 5.0 MEDIUM 7.5 HIGH
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.
CVE-2016-6065 1 Ibm 1 Security Guardium 2017-02-07 7.2 HIGH 7.8 HIGH
IBM Security Guardium Database Activity Monitor appliance could allow a local user to inject commands that would be executed as root.
CVE-2016-8933 1 Ibm 1 Kenexa Lms 2017-02-07 4.0 MEDIUM 6.5 MEDIUM
IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.