Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-1190 | 1 Cybozu | 1 Garoon | 2016-06-27 | 4.0 MEDIUM | 6.5 MEDIUM |
Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors. | |||||
CVE-2016-1189 | 1 Cybozu | 1 Garoon | 2016-06-27 | 5.5 MEDIUM | 8.1 HIGH |
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to bypass intended restrictions on reading, creating, or modifying a portlet via unspecified vectors. | |||||
CVE-2016-1188 | 1 Cybozu | 1 Garoon | 2016-06-27 | 4.0 MEDIUM | 6.5 MEDIUM |
Cybozu Garoon 3.x and 4.x before 4.2.1 allows remote authenticated users to send spoofed e-mail messages via unspecified vectors. | |||||
CVE-2016-3713 | 1 Linux | 1 Linux Kernel | 2016-06-27 | 5.6 MEDIUM | 7.1 HIGH |
The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write to the kvm_arch_vcpu data structure, and consequently obtain sensitive information or cause a denial of service (system crash), via a crafted ioctl call. | |||||
CVE-2016-4528 | 1 Advantech | 1 Webaccess | 2016-06-27 | 4.3 MEDIUM | 5.0 MEDIUM |
Buffer overflow in Advantech WebAccess before 8.1_20160519 allows local users to cause a denial of service via a crafted DLL file. | |||||
CVE-2015-4703 | 1 Rename Project | 1 Rename | 2016-06-27 | 5.0 MEDIUM | 5.3 MEDIUM |
Absolute path traversal vulnerability in mysqldump_download.php in the WordPress Rename plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the dumpfname parameter. | |||||
CVE-2015-4396 | 1 Keyword Research Project | 1 Keyword Research | 2016-06-27 | 5.1 MEDIUM | N/A |
Multiple cross-site request forgery (CSRF) vulnerabilities in the Keyword Research module 6.x-1.x before 6.x-1.2 for Drupal allow remote attackers to hijack the authentication of users with the "kwresearch admin site keywords" permission for requests that (1) create, (2) delete, or (3) set priorities to keywords via unspecified vectors. | |||||
CVE-2015-4467 | 1 Libmspack Project | 1 Libmspack | 2016-06-27 | 4.3 MEDIUM | N/A |
The chmd_init_decomp function in chmd.c in libmspack before 0.5 does not properly validate the reset interval, which allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted CHM file. | |||||
CVE-2014-6579 | 1 Oracle | 1 Peoplesoft Products | 2016-06-27 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52 and 8.53 allows remote authenticated users to affect confidentiality via unknown vectors related to Integration Broker. | |||||
CVE-2014-6576 | 1 Oracle | 1 Fusion Middleware | 2016-06-24 | 5.5 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Adaptive Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via vectors related to OAM Integration. | |||||
CVE-2014-6565 | 1 Oracle | 1 Jd Edwards Enterpriseone Tools | 2016-06-24 | 7.5 HIGH | N/A |
Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 9.1.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Portal SEC. | |||||
CVE-2014-6569 | 1 Oracle | 1 Fusion Middleware | 2016-06-24 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect confidentiality via vectors related to CIE Related Components. | |||||
CVE-2014-6571 | 1 Oracle | 1 Fusion Middleware | 2016-06-24 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Fusion Middleware 11.1.1.7.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Listener, a different vulnerability than CVE-2011-1944. | |||||
CVE-2014-6548 | 1 Oracle | 1 Fusion Middleware | 2016-06-24 | 4.6 MEDIUM | N/A |
Unspecified vulnerability in the Oracle SOA Suite component in Oracle Fusion Middleware 11.1.1.7 allows local users to affect confidentiality, integrity, and availability via vectors related to B2B Engine. | |||||
CVE-2014-6556 | 1 Oracle | 1 E-business Suite | 2016-06-24 | 4.6 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL. | |||||
CVE-2014-6573 | 1 Oracle | 1 Enterprise Manager Grid Control | 2016-06-24 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 11.1.3 and 12.1.4 allows remote attackers to affect integrity via unknown vectors related to User Interface Framework. | |||||
CVE-2014-9714 | 1 Facebook | 1 Hiphop Virtual Machine | 2016-06-24 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the WddxPacket::recursiveAddVar function in HHVM (aka the HipHop Virtual Machine) before 3.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted string to the wddx_serialize_value function. | |||||
CVE-2014-6566 | 1 Oracle | 1 Peoplesoft Products | 2016-06-24 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via unknown vectors related to Portal. | |||||
CVE-2014-6574 | 1 Oracle | 1 Supply Chain Products Suite | 2016-06-24 | 4.3 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Agile PLM for Process component in Oracle Supply Chain Products Suite 6.1.0.3 allows remote attackers to affect integrity via unknown vectors related to Testing Protocol Library. | |||||
CVE-2014-4279 | 1 Oracle | 1 Peoplesoft Products | 2016-06-24 | 3.5 LOW | N/A |
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.53 allows remote authenticated users to affect integrity via vectors related to PIA Core Technology. |