Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-4364 | 1 Hp | 1 Insight Control Server Deployment | 2016-08-23 | 7.2 HIGH | 8.4 HIGH |
HPE Insight Control server deployment allows local users to gain privileges via unspecified vectors. | |||||
CVE-2016-4365 | 1 Hp | 1 Insight Control Server Deployment | 2016-08-23 | 5.0 MEDIUM | 7.5 HIGH |
HPE Insight Control server deployment allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-4367 | 1 Hp | 1 Universal Cmbd Foundation | 2016-08-23 | 5.0 MEDIUM | 7.5 HIGH |
The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-4369 | 1 Hp | 1 Discovery And Dependency Mapping Inventory | 2016-08-23 | 6.5 MEDIUM | 8.8 HIGH |
HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated users to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |||||
CVE-2015-0529 | 1 Emc | 1 Powerpath Virtual Appliance | 2016-08-23 | 5.0 MEDIUM | N/A |
EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accounts, which makes it easier for remote attackers to obtain potentially sensitive information via a login session. | |||||
CVE-2014-9472 | 3 Bestpractical, Debian, Fedoraproject | 3 Request Tracker, Debian Linux, Fedora | 2016-08-23 | 7.1 HIGH | N/A |
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email. | |||||
CVE-2015-1051 | 2 Context Project, Fedoraproject | 2 Context, Fedora | 2016-08-23 | 5.8 MEDIUM | N/A |
Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter. | |||||
CVE-2013-5987 | 2 Apple, Nvidia | 2 Mac Os X, Gpu Driver | 2016-08-23 | 7.2 HIGH | N/A |
Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass intended access restrictions for the GPU and gain privileges via unknown vectors. | |||||
CVE-2016-4357 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 7.5 HIGH | 8.1 HIGH |
HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028. | |||||
CVE-2016-6493 | 1 Citrix | 2 Xenapp, Xendesktop | 2016-08-23 | 7.5 HIGH | 9.8 CRITICAL |
Citrix XenApp 6.x before 6.5 HRP07 and 7.x before 7.9 and Citrix XenDesktop before 7.9 might allow attackers to weaken an unspecified security mitigation via vectors related to memory permission. | |||||
CVE-2015-7558 | 2 Debian, Gnome | 2 Debian Linux, Librsvg | 2016-08-23 | 5.0 MEDIUM | 7.5 HIGH |
librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via cyclic references in an SVG document. | |||||
CVE-2014-3994 | 1 Reviewboard | 2 Djblets, Reviewboard | 2016-08-23 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in util/templatetags/djblets_js.py in Djblets before 0.7.30 and 0.8.x before 0.8.3 for Django, as used in Review Board, allows remote attackers to inject arbitrary web script or HTML via a JSON object, as demonstrated by the name field when changing a user name. | |||||
CVE-2016-4358 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 4.8 MEDIUM | 8.1 HIGH |
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2029. | |||||
CVE-2016-2029 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 6.4 MEDIUM | 9.1 CRITICAL |
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358. | |||||
CVE-2016-2028 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 5.5 MEDIUM | 8.1 HIGH |
HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4357. | |||||
CVE-2016-2027 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 5.0 MEDIUM | 7.5 HIGH |
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026. | |||||
CVE-2016-2026 | 1 Hp | 2 Matrix Operating Environment, Systems Insight Manager | 2016-08-23 | 5.0 MEDIUM | 7.5 HIGH |
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027. | |||||
CVE-2014-6410 | 1 Linux | 1 Linux Kernel | 2016-08-22 | 4.7 MEDIUM | N/A |
The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode. | |||||
CVE-2011-4077 | 1 Linux | 1 Linux Kernel | 2016-08-22 | 6.9 MEDIUM | N/A |
Buffer overflow in the xfs_readlink function in fs/xfs/xfs_vnodeops.c in XFS in the Linux kernel 2.6, when CONFIG_XFS_DEBUG is disabled, allows local users to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via an XFS image containing a symbolic link with a long pathname. | |||||
CVE-2011-4108 | 1 Openssl | 1 Openssl | 2016-08-22 | 4.3 MEDIUM | N/A |
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack. |