Total
10666 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-2854 | 1 Blue Coat | 8 Ssl Visibility Appliance Sv1800, Ssl Visibility Appliance Sv1800 Firmware, Ssl Visibility Appliance Sv2800 and 5 more | 2016-12-03 | 4.3 MEDIUM | N/A |
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remote attackers to conduct clickjacking attacks via vectors involving an IFRAME element. | |||||
CVE-2015-2790 | 1 Foxitsoftware | 3 Enterprise Reader, Foxit Reader, Phantompdf | 2016-12-03 | 4.3 MEDIUM | N/A |
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory corruption and crash) via a crafted (1) Ubyte Size in a DataSubBlock structure or (2) LZWMinimumCodeSize in a GIF image. | |||||
CVE-2015-2776 | 2 Debian, Gaia-gis | 2 Debian Linux, Freexl | 2016-12-03 | 4.3 MEDIUM | N/A |
The parse_SST function in FreeXL before 1.0.0i allows remote attackers to cause a denial of service (memory consumption) via a crafted shared strings table in a workbook. | |||||
CVE-2015-2765 | 1 Websense | 1 Triton Ap Email | 2016-12-03 | 4.3 MEDIUM | N/A |
The Email Security Gateway in Websense TRITON AP-EMAIL before 8.0.0 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |||||
CVE-2015-2753 | 2 Debian, Gaia-gis | 2 Debian Linux, Freexl | 2016-12-03 | 6.8 MEDIUM | N/A |
FreeXL before 1.0.0i allows remote attackers to cause a denial of service (stack corruption) or possibly execute arbitrary code via a crafted sector in a workbook. | |||||
CVE-2015-2684 | 2 Debian, Shibboleth | 2 Debian Linux, Service Provider | 2016-12-03 | 4.0 MEDIUM | N/A |
Shibboleth Service Provider (SP) before 2.5.4 allows remote authenticated users to cause a denial of service (crash) via a crafted SAML message. | |||||
CVE-2014-9093 | 4 Canonical, Debian, Fedoraproject and 1 more | 4 Ubuntu Linux, Debian Linux, Fedora and 1 more | 2016-12-03 | 7.5 HIGH | N/A |
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file. | |||||
CVE-2013-7019 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-03 | 6.8 MEDIUM | N/A |
The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data. | |||||
CVE-2013-7015 | 1 Ffmpeg | 1 Ffmpeg | 2016-12-03 | 6.8 MEDIUM | N/A |
The flashsv_decode_frame function in libavcodec/flashsv.c in FFmpeg before 2.1 does not properly validate a certain height value, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Flash Screen Video data. | |||||
CVE-2016-8579 | 1 Docker2aci Project | 1 Docker2aci | 2016-12-02 | 2.1 LOW | 4.0 MEDIUM |
docker2aci <= 0.12.3 has an infinite loop when handling local images with cyclic dependency chain. | |||||
CVE-2016-1843 | 1 Apple | 1 Mac Os X | 2016-12-01 | 5.0 MEDIUM | 7.5 HIGH |
The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1998 | 1 Hp | 1 Service Manager | 2016-12-01 | 10.0 HIGH | 9.8 CRITICAL |
HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |||||
CVE-2016-1997 | 1 Hp | 2 Operations Orchestration, Operations Orchestration Content | 2016-12-01 | 10.0 HIGH | 9.8 CRITICAL |
HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library. | |||||
CVE-2016-1800 | 1 Apple | 1 Mac Os X | 2016-12-01 | 9.3 HIGH | 8.8 HIGH |
Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2016-1407 | 1 Cisco | 7 Asr 9001, Asr 9006, Asr 9010 and 4 more | 2016-12-01 | 5.0 MEDIUM | 7.5 HIGH |
Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of service (session drop) by making many connection attempts to open TCP ports, aka Bug ID CSCux95576. | |||||
CVE-2016-1400 | 1 Cisco | 1 Telepresence Video Communication Server | 2016-12-01 | 5.0 MEDIUM | 7.5 HIGH |
Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via a crafted URI in a SIP header, aka Bug ID CSCuy43258. | |||||
CVE-2016-1382 | 1 Cisco | 2 Web Security Appliance, Web Security Appliance \(wsa\) | 2016-12-01 | 7.8 HIGH | 7.5 HIGH |
Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allows remote attackers to cause a denial of service (proxy-process reload) via a crafted request, aka Bug ID CSCuu02529. | |||||
CVE-2016-1380 | 1 Cisco | 1 Web Security Appliance | 2016-12-01 | 7.8 HIGH | 7.5 HIGH |
Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) via a crafted HTTP POST request, aka Bug ID CSCuo12171. | |||||
CVE-2016-0895 | 1 Emc | 1 Rsa Data Loss Prevention | 2016-12-01 | 4.3 MEDIUM | 4.3 MEDIUM |
EMC RSA Data Loss Prevention 9.6 before SP2 P5 allows remote attackers to conduct clickjacking attacks via web-site elements with crafted transparency or opacity. | |||||
CVE-2016-0381 | 1 Ibm | 1 Cognos Tm1 | 2016-12-01 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Cognos TM1 10.2.2 before FP5, when the host/pmhub/pm/admin AdminGroups setting is empty, allows remote authenticated users to cause a denial of service (configuration outage) via a non-empty value. |