Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2016-5244EPSS 6%
The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remot…
Fedora
after 4.6.3
MEDIUM 5.5
CVE-2016-5243
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which a…
Linux Kernel
after 4.6.3
MEDIUM 5.5
CVE-2014-9903
The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to o…
Linux Kernel
Patch available
HIGH 7.5
CVE-2016-1193
Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.
Garoon
No fix yet
HIGH 7.3
CVE-2016-5722
Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP…
Ocean Stor Firmware
Mitigation only
HIGH 7.5
CVE-2015-8289
The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote atta…
D3600 Firmware
after 1.0.0.49
MEDIUM 6.5
CVE-2016-1225
Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.
Internet Security
No fix yet
MEDIUM 6.5
CVE-2016-4816
BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive…
Wzr 600dhp3 Firmware
after 2.16
HIGH 7.5
CVE-2016-1427
The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…
Prime Network Registrar
Mitigation only
MEDIUM 5.5
CVE-2016-3234EPSS 24%
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 20…
Office
Mitigation only
MEDIUM 5.5
CVE-2016-3215EPSS 34%
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information fr…
Windows 10
Patch available
MEDIUM 6.5
CVE-2016-3201EPSS 24%
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive infor…
Edge
Mitigation only
MEDIUM 5.5
CVE-2016-0028EPSS 23%
Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 …
Outlook Web Access
Mitigation only
HIGH 7.5
CVE-2016-5367
Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWP…
Honor Ws851 Firmware
after 1.1.21.1
CRITICAL 9.1
CVE-2015-8869EPSS 5%
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive in…
Fedora
after 4.02.3
MEDIUM 5.5
CVE-2016-2500
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allow…
Android
Mitigation only
MEDIUM 5.5
CVE-2016-2499
AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does …
Android
Mitigation only
MEDIUM 5.5
CVE-2016-2498
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a c…
Android
Patch available
HIGH 7.5
CVE-2015-8268
The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.
Uptime Infrastructure Monitor
Mitigation only
MEDIUM 5.5
CVE-2016-1582
LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access …
Ubuntu Linux
Mitigation only
MEDIUM 6.5
CVE-2016-2149
Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de…
Openshift
Mitigation only
MEDIUM 5.5
CVE-2016-2142
Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local …
Openshift
Mitigation only
HIGH 7.5
CVE-2016-4367EPSS 8%
The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive infor…
Universal Cmbd Foundation
Mitigation only
HIGH 7.5
CVE-2016-2027
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerabil…
Matrix Operating Environment
after 7.5
HIGH 7.5
CVE-2016-2026
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerabil…
Systems Insight Manager
after 7.5
MEDIUM 5.5
CVE-2015-5231
The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via …
Checkpoint\/restore In Userspace
Mitigation only
CRITICAL 9.1
CVE-2015-5041
The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…
Satellite
6.0.16.20 / 6.1.8.20+
MEDIUM 6.5
CVE-2016-1698
The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not val…
Debian Linux
after 51.0.2704.63
MEDIUM 6.5
CVE-2016-1687
The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers…
Debian Linux
after 50.0.2661.102
MEDIUM 6.5
CVE-2016-1677
uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to o…
Chrome
after 50.0.2661.102