Top technology
Linux 13140
Google 12537
Microsoft 12388
Oracle 7054
Apple 6692
Ibm 6393
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2901
Apache 2864
Redhat 2604
HIGH 7.5
CVE-2016-6379
Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record…
iOS
Mitigation only
HIGH 7.5
CVE-2016-6384
Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device re…
iOS
after 15.6
CRITICAL 9.8
CVE-2016-6646
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…
Emc Unisphere
Mitigation only
HIGH 8.8
CVE-2016-6645
The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…
Emc Unisphere
Mitigation only
CRITICAL 9.8
CVE-2016-0913
The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsof…
Networker Module For Microsoft Applications
after 8.2.3.6
HIGH 7.5
CVE-2016-8278
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attackers to cause a denial of ser…
Usg9520
Mitigation only
MEDIUM 6.5
CVE-2016-8277
Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a den…
Usg9520
Mitigation only
HIGH 8.8
CVE-2016-1244EPSS 5%
The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.
Debian Linux
Patch available
HIGH 7.8
CVE-2016-1240EPSS 10%
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …
Tomcat
No fix yet
HIGH 7.5
CVE-2016-2776EPSS 89%
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which al…
Linux
after 9.9.9
MEDIUM 6.5
CVE-2016-6901
Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software befo…
Ar Firmware
Mitigation only
MEDIUM 5.9
CVE-2016-6153
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive i…
SQLite
after 3.12.2
CRITICAL 9.8
CVE-2016-4972
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and pyt…
Mitaka Murano
after 2.0.0
HIGH 7.5
CVE-2016-7162
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a sym…
Ubuntu Linux
Patch available
HIGH 7.5
CVE-2016-3110
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…
Jboss Enterprise Application Platform
Mitigation only
MEDIUM 5.7
CVE-2016-5947
IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking atta…
Tivoli Storage Productivity Center
Patch available
MEDIUM 6.5
CVE-2016-5174
browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a full…
Chrome
after 53.0.2785.101
HIGH 7.8
CVE-2016-4753
Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrar…
Iphone Os
3.0 / 10.0+
HIGH 8.8
CVE-2016-4728
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote…
Safari
10.0 / 12.5.1+
MEDIUM 5.9
CVE-2016-4722
The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attac…
Iphone Os
after 10.11.6
HIGH 7.5
CVE-2016-4711
CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a …
Iphone Os
after 10.11.6
MEDIUM 5.5
CVE-2016-4706
cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.
Mac Os X
after 10.11.6
MEDIUM 6.2
CVE-2016-4701
Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environme…
Mac Os X
after 10.11.6
HIGH 7.8
CVE-2016-4698
AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance …
Iphone Os
after 10.11.6
MEDIUM 6.5
CVE-2016-6412
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid…
iOS
Mitigation only
HIGH 7.5
CVE-2016-6411
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote …
Firesight System Software
Mitigation only
MEDIUM 6.5
CVE-2016-6410
The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent…
iOS
Mitigation only
CRITICAL 9.8
CVE-2016-6374
Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…
Cloud Services Platform 2100
Mitigation only
HIGH 7.4
CVE-2016-5284
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinnin…
Firefox
after 48.0.2
HIGH 8.8
CVE-2016-5272
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast …
Firefox
after 48.0.2