Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
International Components For Unicode CRITICAL 9.8
CVE-2016-7415EPSS 6%

Stack-based buffer overflow in the Locale class in common/locid.cpp in International Components for Unicode (ICU) through 57.1 for C/C++ allows remot…

Fix: after 57.1
Fix from $2,300 2016-09-17
PHP CRITICAL 9.8
CVE-2016-7414EPSS 7%

The ZIP signature-verification feature in PHP before 5.6.26 and 7.x before 7.0.11 does not ensure that the uncompressed_filesize field is large enoug…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
PHP HIGH 8.1
CVE-2016-7412EPSS 9%

ext/mysqlnd/mysqlnd_wireprotocol.c in PHP before 5.6.26 and 7.x before 7.0.11 does not verify that a BIT field has the UNSIGNED_FLAG flag, which allo…

Fix: after 5.6.25
Fix from $1,950 2016-09-17
Acrobat CRITICAL 9.8
CVE-2016-6937EPSS 7%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-09-17
Digital Editions CRITICAL 9.8
CVE-2016-4262

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4261

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4260

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4259

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4258EPSS 5%

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4257EPSS 5%

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Digital Editions CRITICAL 9.8
CVE-2016-4256EPSS 5%

Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…

Fix: after 4.5.1
Fix from $2,300 2016-09-16
Excel HIGH 7.8
CVE-2016-3381EPSS 15%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote…

Mitigation only
Fix from $1,950 2016-09-14
Edge HIGH 7.5
CVE-2016-3377EPSS 16%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2016-09-14
Internet Explorer HIGH 7.5
CVE-2016-3375EPSS 17%

The OLE Automation mechanism and VBScript scripting engine in Microsoft Internet Explorer 9 through 11, Windows Vista SP2, Windows Server 2008 SP2 an…

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.5
CVE-2016-3369EPSS 12%

Microsoft Windows 10 Gold and 1511 allows attackers to cause a denial of service via unspecified vectors, aka "Windows Denial of Service Vulnerabilit…

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 8.8
CVE-2016-3368EPSS 18%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Win…

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3365EPSS 20%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services …

Mitigation only
Fix from $1,950 2016-09-14
Visio HIGH 7.8
CVE-2016-3364EPSS 19%

Microsoft Visio 2016 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability."

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3363EPSS 20%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, and Excel Viewer allow remote…

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3362EPSS 17%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, Excel Services …

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3361EPSS 17%

Microsoft Excel 2010 SP2 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Memory Corruption Vulnerabil…

Mitigation only
Fix from $1,950 2016-09-14
Office Compatibility Pack HIGH 7.8
CVE-2016-3360EPSS 17%

Microsoft PowerPoint 2007 SP3, PowerPoint 2010 SP2, PowerPoint 2013 SP1, PowerPoint 2013 RT SP1, PowerPoint 2016 for Mac, Office Compatibility Pack S…

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3359EPSS 17%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to execute arbitrary code via a craf…

Mitigation only
Fix from $1,950 2016-09-14
Excel HIGH 7.8
CVE-2016-3358EPSS 18%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel 2016 for Mac, Office Compatibility Pack SP3, Excel Vie…

Mitigation only
Fix from $1,950 2016-09-14
Office HIGH 7.8
CVE-2016-3357EPSS 55%

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 2016 for Mac, Word Viewer, Word…

No fix yet
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3356EPSS 19%

The Graphics Device Interface (GDI) in Microsoft Windows 10 1607 allows remote attackers to execute arbitrary code via a crafted document, aka "GDI R…

Mitigation only
Fix from $1,950 2016-09-14
Edge HIGH 7.5
CVE-2016-3350EPSS 15%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via…

Mitigation only
Fix from $1,950 2016-09-14
Edge HIGH 7.5
CVE-2016-3330EPSS 14%

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Micros…

Mitigation only
Fix from $1,950 2016-09-14
Edge HIGH 7.5
CVE-2016-3295EPSS 15%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corrup…

Mitigation only
Fix from $1,950 2016-09-14
Edge HIGH 7.5
CVE-2016-3294EPSS 14%

Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Micros…

Mitigation only
Fix from $1,950 2016-09-14