CSV
14,719 results for "vulnerability" Page 4
CVE-2016-3427 CRITICAL KEV Exploit

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.

Apr 21, 2016 81 affected product(s) NVD
9.8
CVSS
92.3%
EPSS
⚡ 96.9
CVE-2016-2386 CRITICAL KEV Exploit

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2101079.

Feb 16, 2016 1 affected product(s) NVD
9.8
CVSS
71.1%
EPSS
⚡ 90.5
CVE-2016-2004 CRITICAL Exploit

HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary code via unspecified vectors related to lack of authentication. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2623.

Apr 21, 2016 3 affected product(s) NVD
9.8
CVSS
94.3%
EPSS
⚡ 77.5
CVE-2016-0638 CRITICAL

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, 12.1.3, and 12.2.1 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Messaging Service.

Apr 21, 2016 4 affected product(s) NVD
9.8
CVSS
62.9%
EPSS
⚡ 58.1
CVE-2016-2842 CRITICAL

The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cause a denial of service (out-of-bounds write or memory consumption) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-0799.

Mar 3, 2016 32 affected product(s) NVD
9.8
CVSS
53.7%
EPSS
⚡ 55.3
CVE-2016-3141 CRITICAL

Use-after-free vulnerability in wddx.c in the WDDX extension in PHP before 5.5.33 and 5.6.x before 5.6.19 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact by triggering a wddx_deserialize call on XML data containing a crafted var element.

Mar 31, 2016 21 affected product(s) NVD
9.8
CVSS
36.0%
EPSS
⚡ 50
CVE-2016-0799 CRITICAL

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (overflow and out-of-bounds read) or possibly have unspecified other impact via a long string, as demonstrated by a large amount of ASN.1 data, a different vulnerability than CVE-2016-2842.

Mar 3, 2016 35 affected product(s) NVD
9.8
CVSS
32.4%
EPSS
⚡ 48.9
CVE-2016-0705 CRITICAL

Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a malformed DSA private key.

Mar 3, 2016 61 affected product(s) NVD
9.8
CVSS
26.3%
EPSS
⚡ 47.1
CVE-2016-0951 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0952 and CVE-2016-0953.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-0952 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0953.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-0953 CRITICAL

Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0951 and CVE-2016-0952.

Feb 10, 2016 2 affected product(s) NVD
9.8
CVSS
20.6%
EPSS
⚡ 45.4
CVE-2016-1988 CRITICAL

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1989.

Mar 15, 2016 5 affected product(s) NVD
9.8
CVSS
10.6%
EPSS
⚡ 42.4
CVE-2016-1989 CRITICAL

HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988.

Mar 15, 2016 5 affected product(s) NVD
9.8
CVSS
10.6%
EPSS
⚡ 42.4
CVE-2016-0639 CRITICAL

Unspecified vulnerability in Oracle MySQL 5.6.29 and earlier and 5.7.11 and earlier allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Pluggable Authentication.

Apr 21, 2016 4 affected product(s) NVD
9.8
CVSS
10.1%
EPSS
⚡ 42.2
CVE-2016-0746 CRITICAL

Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.

Feb 15, 2016 9 affected product(s) NVD
9.8
CVSS
8.6%
EPSS
⚡ 41.8
CVE-2015-8833 CRITICAL

Use-after-free vulnerability in the create_smp_dialog function in gtk-dialog.c in the Off-the-Record Messaging (OTR) pidgin-otr plugin before 4.0.2 for Pidgin allows remote attackers to execute arbitrary code via vectors related to the "Authenticate buddy" menu item.

Apr 12, 2016 1 affected product(s) NVD
9.8
CVSS
7.0%
EPSS
⚡ 41.3
CVE-2016-1007 CRITICAL

Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1009.

Mar 9, 2016 6 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-1009 CRITICAL

Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-1007.

Mar 9, 2016 6 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-1962 CRITICAL

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.

Mar 13, 2016 18 affected product(s) NVD
9.8
CVSS
6.1%
EPSS
⚡ 41
CVE-2016-3974 CRITICAL

XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denial of service, conduct SMB Relay attacks, or access arbitrary files via a crafted XML request to _tc~monitoring~webservice~web/ServerNodesWSService, aka SAP Security Note 2235994.

Apr 7, 2016 1 affected product(s) NVD
9.1
CVSS
15.1%
EPSS
⚡ 40.9