Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-01-29 CVE-2015-8789 Unspecified vulnerability in Matroska Libebml
Use-after-free vulnerability in the EbmlMaster::Read function in libEBML before 1.3.3 allows context-dependent attackers to have unspecified impact via a "deeply nested element with infinite size" followed by another element of an upper level in an EBML document.
network
low complexity
matroska
critical
9.6
2016-01-28 CVE-2016-0868 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rockwellautomation products
Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers to execute arbitrary code via a crafted web request.
network
low complexity
rockwellautomation CWE-119
critical
9.8
2016-01-27 CVE-2015-6319 SQL Injection vulnerability in multiple products
SQL injection vulnerability in the web-based management interface on Cisco RV220W devices allows remote attackers to execute arbitrary SQL commands via a crafted header in an HTTP request, aka Bug ID CSCuv29574.
network
low complexity
cisco sun CWE-89
critical
9.8
2016-01-27 CVE-2016-1896 7PK - Security Features vulnerability in Lexmark Printer Firmware
Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and YK before YK.02.049 allows remote attackers to bypass authentication by leveraging incorrect detection of the security-jumper status.
network
low complexity
lexmark CWE-254
critical
9.8
2016-01-25 CVE-2016-2051 Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
network
low complexity
google redhat
critical
9.8
2016-01-22 CVE-2016-1984 Credentials Management vulnerability in Harman AMX Firmware 1.2.322/1.3.100
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.
network
low complexity
harman CWE-255
critical
9.8
2016-01-22 CVE-2015-8362 Credentials Management vulnerability in Harman AMX Firmware 1.2.322/1.3.100
The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2016-1984.
network
low complexity
harman CWE-255
critical
9.8
2016-01-22 CVE-2015-6435 OS Command Injection vulnerability in Cisco products
An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via a crafted HTTP request, aka Bug ID CSCur90888.
network
low complexity
cisco CWE-78
critical
9.8
2016-01-22 CVE-2015-6412 Credentials Management vulnerability in Cisco Modular Encoding Platform D9036 Software
Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.
network
low complexity
cisco CWE-255
critical
9.8
2016-01-20 CVE-2016-1929 Improper Input Validation vulnerability in SAP Hana
The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption and process crash) via a crafted HTTP request, related to an unspecified debug function, aka SAP Security Note 2241978.
network
low complexity
sap CWE-20
critical
9.3