Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2016-09-25 CVE-2016-4696 NULL Pointer Dereference vulnerability in Apple mac OS X
AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.
local
low complexity
apple CWE-476
7.8
2016-09-25 CVE-2016-4611 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Apple Tvos
WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE-2016-4734, and CVE-2016-4735.
network
low complexity
apple CWE-119
8.8
2016-09-24 CVE-2016-5793 Unquoted Search Path or Element vulnerability in Moxa Active OPC Server 2.4.18
Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
local
low complexity
moxa CWE-428
8.8
2016-09-24 CVE-2016-4845 Cross-Site Request Forgery (CSRF) vulnerability in Iodata products
Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content.
network
low complexity
iodata CWE-352
8.8
2016-09-24 CVE-2016-6413 Permissions, Privileges, and Access Controls vulnerability in Cisco Application Policy Infrastructure Controller 1.3(2F)
The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.
local
low complexity
cisco CWE-264
7.8
2016-09-24 CVE-2016-6411 Improper Input Validation vulnerability in Cisco Firesight System Software 6.0.1
Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585.
network
low complexity
cisco CWE-20
7.5
2016-09-24 CVE-2016-6409 Resource Management Errors vulnerability in Cisco IOS 15.6(1)T
The Data in Motion (DMo) component in Cisco IOS 15.6(1)T and IOS XE, when the IOx feature set is enabled, allows remote attackers to cause a denial of service (out-of-bounds access) via crafted traffic, aka Bug ID CSCuy54015.
network
low complexity
cisco CWE-399
7.5
2016-09-24 CVE-2016-6408 XXE vulnerability in Cisco Prime Home 5.2.0
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCvb17814.
network
low complexity
cisco CWE-611
7.5
2016-09-22 CVE-2016-6414 OS Command Injection vulnerability in Cisco IOS 15.6(1)T1
iox in Cisco IOS, possibly 15.6 and earlier, and IOS XE, possibly 3.18 and earlier, allows local users to execute arbitrary IOx Linux commands on the guest OS via crafted iox command-line options, aka Bug ID CSCuz59223.
local
low complexity
cisco CWE-78
7.8
2016-09-22 CVE-2016-6373 OS Command Injection vulnerability in Cisco Cloud Services Platform 2100 2.0.0Base
The web-based GUI in Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote authenticated administrators to execute arbitrary OS commands as root via crafted platform commands, aka Bug ID CSCva00541.
network
low complexity
cisco CWE-78
7.2