Skip to main content

CWE archive

CWE-254 CVEs

Programmatic archive

414 CVEs tagged with CWE-25437 Critical, 126 High, 220 Medium, 31 Low, 0 Unrated.

CVE-2016-4781

Published Feb 20, 2017

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "SpringBoard" component, which allows physically proximate attackers to bypa…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-4721

Published Feb 20, 2017

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. The issue involves the "IDS - Connectivity" component, which allo…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4689

Published Feb 20, 2017

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Mail" component, which does not alert the user to an S/MIME email signature…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-10224

Published Feb 13, 2017

An issue was discovered in Sauter NovaWeb web HMI. The application uses a protection mechanism that relies on the existence or values of a cookie, but it does not properly ensure…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3102

Published Feb 9, 2017

The Script Security plugin before 1.18.1 in Jenkins might allow remote attackers to bypass a Groovy sandbox protection mechanism via a plugin that performs (1) direct field access…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8911

Published Feb 1, 2017

IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a r…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5949

Published Feb 1, 2017

IBM Kenexa LCMS Premier on Cloud could allow an authenticated user to obtain sensitive user data with a specially crafted HTTP request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5898

Published Feb 1, 2017

IBM Jazz Reporting Service (JRS) could allow a remote attacker to obtain sensitive information, caused by not restricting JSON serialization. By sending a direct request, an attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5117

Published Jan 31, 2017

OpenNTPD before 6.0p1 does not validate the CN for HTTPS constraint requests, which allows remote attackers to bypass the man-in-the-middle mitigations via a crafted timestamp con…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7331

Published Jan 30, 2017

The mcollective-puppet-agent plugin before 1.11.1 for Puppet allows remote attackers to execute arbitrary code via vectors involving the --server argument.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-7976

Published Jan 30, 2017

The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspec…

CVSS 4.3 · Medium

CVE-2016-8329

Published Jan 27, 2017

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Mobile Application Platform). Supported versions that are affected ar…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8314

Published Jan 27, 2017

Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 a…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2016-8310

Published Jan 27, 2017

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 1…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2016-8306

Published Jan 27, 2017

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1,…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-8303

Published Jan 27, 2017

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 1…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5623

Published Jan 27, 2017

Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5545

Published Jan 27, 2017

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox prior to 5.0.32 and prior to…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-1551

Published Jan 27, 2017

ntpd in NTP 4.2.8p3 and NTPsec a5fb34b9cc89b92a8fef2f459004865c93bb7f92 relies on the underlying operating system to protect it from requests that impersonate reference clocks. Be…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 101-125 of 414 CVEsPage 5 of 17