Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4802 | 1 Haxx | 1 Curl | 2016-12-30 | 6.9 MEDIUM | 7.8 HIGH |
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory. | |||||
CVE-2016-7463 | 1 Vmware | 1 Esxi | 2016-12-30 | 3.5 LOW | 5.4 MEDIUM |
Cross-site scripting (XSS) vulnerability in the Host Client in VMware vSphere Hypervisor (aka ESXi) 5.5 and 6.0 allows remote authenticated users to inject arbitrary web script or HTML via a crafted VM. | |||||
CVE-2016-9777 | 1 Linux | 1 Linux Kernel | 2016-12-30 | 6.9 MEDIUM | 7.8 HIGH |
KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h. | |||||
CVE-2016-2934 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-30 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2016-2935 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-30 | 5.0 MEDIUM | 5.3 MEDIUM |
The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request. | |||||
CVE-2015-3724 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3723. | |||||
CVE-2015-3725 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
MobileInstallation in Apple iOS before 8.4 does not ensure the uniqueness of Watch bundle IDs, which allows attackers to cause a denial of service (ID collision and Watch launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-3726 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.6 MEDIUM | N/A |
The Telephony subsystem in Apple iOS before 8.4 allows physically proximate attackers to execute arbitrary code via a crafted (1) SIM or (2) UIM card. | |||||
CVE-2016-2931 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-30 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network. | |||||
CVE-2016-2932 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-30 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks via unspecified vectors. | |||||
CVE-2016-2933 | 1 Ibm | 1 Bigfix Remote Control | 2016-12-30 | 6.8 MEDIUM | 6.8 MEDIUM |
Directory traversal vulnerability in IBM BigFix Remote Control before 9.1.3 allows remote authenticated administrators to read arbitrary files via a crafted request. | |||||
CVE-2015-3713 | 1 Apple | 2 Mac Os X, Quicktime | 2016-12-30 | 6.8 MEDIUM | N/A |
QuickTime in Apple OS X before 10.10.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted movie file. | |||||
CVE-2015-3723 | 1 Apple | 1 Iphone Os | 2016-12-30 | 6.8 MEDIUM | N/A |
CoreGraphics in Apple iOS before 8.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ICC profile in a PDF document, a different vulnerability than CVE-2015-3724. | |||||
CVE-2015-1986 | 1 Ibm | 1 Tivoli Storage Manager Fastback | 2016-12-30 | 10.0 HIGH | N/A |
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938. | |||||
CVE-2015-2019 | 1 Ibm | 1 Tivoli Directory Server | 2016-12-30 | 2.1 LOW | N/A |
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 does not prevent caching of documents retrieved in SSL sessions, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation. | |||||
CVE-2015-3722 | 1 Apple | 1 Iphone Os | 2016-12-30 | 4.3 MEDIUM | N/A |
Application Store in Apple iOS before 8.4 does not ensure the uniqueness of bundle IDs, which allows attackers to cause a denial of service (ID collision and launch outage) via a crafted universal provisioning profile app. | |||||
CVE-2015-1978 | 1 Ibm | 1 Tivoli Directory Server | 2016-12-30 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |||||
CVE-2015-1974 | 1 Ibm | 1 Tivoli Directory Server | 2016-12-30 | 6.5 MEDIUM | N/A |
The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors. | |||||
CVE-2015-1967 | 1 Ibm | 1 Websphere Mq | 2016-12-30 | 4.3 MEDIUM | N/A |
MQ Explorer in IBM WebSphere MQ before 8.0.0.3 does not recognize the absence of the compatibility-mode option, which allows remote attackers to obtain sensitive information by sniffing the network for a session in which TLS is not used. | |||||
CVE-2015-1972 | 1 Ibm | 1 Tivoli Directory Server | 2016-12-30 | 4.3 MEDIUM | N/A |
IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote attackers to obtain sensitive error-log information via a crafted POST request. |