VRT 391,810 CVEs tracked · 15,472 in RASP scope · data as of 40 minutes ago
Reset
More filters (3)
Columns
Protection: fullPublished from 2016-07-01Published to 2016-07-31
Overview 13 matches, all in RASP scope, all protected · 0 KEV · 1 public PoC · 0 CISA SSVC · 1 EPSS ≥ 0.5 · 0 disputed
13matches, all in RASP scope, all protected 0KEV0.0% 1public PoC7.7% 0CISA SSVC0.0% 1EPSS ≥ 0.57.7% 0disputed0.0%
Critical 5 38.5% High 5 38.5% Medium 3 23.1% Low 0 0.0% None 0 0.0% Unknown 0 0.0%
Protected by RASP 7 53.8% Rule in development 0 0.0% Mitigation candidate 0 0.0% No exploit published 0 0.0% No fix identified 0 0.0% Mitigated by environment configuration 6 46.2% Queued for review 0 0.0% Not applicable 0 0.0% Out of RASP scope 0 0.0% Rejected 0 0.0%
blocked by ARMR today 13 100.0% not blocked 0 0.0% not established 0 0.0% unrecorded 0 0.0%
Exploited in the wild 0 0.0% Working exploit published 1 7.7% Proof of concept only 0 0.0% Forecast only 0 0.0% No public exploit 12 92.3%
split by peak 13 / month
Unknown: 0None: 0Low: 0Medium: 3High: 5Critical: 5 Rejected: 0Out of RASP scope: 0Not applicable: 0Queued for review: 0Mitigated by environment configuration: 6No fix identified: 0No exploit published: 0Mitigation candidate: 0Rule in development: 0Protected by RASP: 7 unrecorded: 0not established: 0not blocked: 0blocked by ARMR today: 13 No public exploit: 12Forecast only: 0Proof of concept only: 0Working exploit published: 1Exploited in the wild: 0 July 2016: 13 CVEs
Jul 16
13 matches CSV JSON
CVE Severity Published Status Exploitation Description
CVE-2016-3610 Critical 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3598.
CVE-2016-3606 Critical 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 7u101 and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.
CVE-2016-3598 Critical 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Libraries, a different vulnerability than CVE-2016-3610.
CVE-2016-3587 Critical 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Hotspot.
CVE-2016-3550 Medium 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92 and Java SE Embedded 8u91 allows remote attackers to affect confidentiality via vectors related to Hotspot.
CVE-2016-3510 Critical 2016-07-21 Protected by RASP Working exploit published Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to WLS Core Components, a different vulnerability than CVE-2016-3586.
CVE-2016-3458 Medium 2016-07-21 Mitigated by environment configuration No public exploit Unspecified vulnerability in Oracle Java SE 6u115, 7u101, and 8u92; and Java SE Embedded 8u91 allows remote attackers to affect integrity via vectors related to CORBA.
CVE-2016-4974 High 2016-07-13 Protected by RASP No public exploit Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which might allow remote authenticated users with permission to send messages to deserialize arbitrary objects and execute arbitrary code by leveraging a crafted serialized object in a JMS ObjectMessage that is handled by the getObject function.
CVE-2016-4216 High 2016-07-13 Protected by RASP No public exploit XMPCore in Adobe XMP Toolkit for Java before 5.1.3 allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2015-3192 Medium 2016-07-12 Protected by RASP No public exploit Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.
CVE-2016-1182 High 2016-07-04 Protected by RASP No public exploit ActionServlet.java in Apache Struts 1 1.x through 1.3.10 does not properly restrict the Validator configuration, which allows remote attackers to conduct cross-site scripting (XSS) attacks or cause a denial of service via crafted input, a related issue to CVE-2015-0899.
CVE-2016-1181 High 2016-07-04 Protected by RASP No public exploit ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart request, a related issue to CVE-2015-0899.
CVE-2015-0899 High 2016-07-04 Protected by RASP No public exploit The MultiPageValidator implementation in Apache Struts 1 1.1 through 1.3.10 allows remote attackers to bypass intended access restrictions via a modified page parameter.