Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Mac Os X HIGH 7.3
CVE-2015-8472EPSS 8%

Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25,…

Fix: after 10.11.3
Fix from $1,950 2016-01-21
Hana CRITICAL 9.8
CVE-2016-1928

Buffer overflow in the XS engine (hdbxsengine) in SAP HANA allows remote attackers to cause a denial of service or execute arbitrary code via a craft…

Mitigation only
Fix from $2,300 2016-01-20
Fedora CRITICAL 9.8
CVE-2016-1901

Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Co…

Fix: after 0.11.2
Fix from $2,300 2016-01-20
Jasper MEDIUM 6.5
CVE-2016-1867

The jpc_pi_nextcprl function in JasPer 1.900.1 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a …

Mitigation only
Fix from $1,600 2016-01-20
Openstack MEDIUM 5.4
CVE-2015-5295

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticat…

Fix: 5.0.1 / 2015.1.3+
Fix from $1,600 2016-01-20
Openssh MEDIUM 5.3
CVE-2016-1907EPSS 15%

The ssh_packet_read_poll2 function in packet.c in OpenSSH before 7.1p2 allows remote attackers to cause a denial of service (out-of-bounds read and a…

Mitigation only
Fix from $1,600 2016-01-19
Webaccess HIGH 7.5
CVE-2016-0860EPSS 5%

Buffer overflow in the BwpAlarm subsystem in Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service via a crafted RPC re…

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess HIGH 8.1
CVE-2016-0858

Race condition in Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via…

Fix: after 8.0
Fix from $1,950 2016-01-15
Webaccess CRITICAL 9.8
CVE-2016-0857EPSS 23%

Multiple heap-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 8.0
Fix from $2,300 2016-01-15
Webaccess CRITICAL 9.8
CVE-2016-0856EPSS 16%

Multiple stack-based buffer overflows in Advantech WebAccess before 8.1 allow remote attackers to execute arbitrary code via unspecified vectors.

Fix: after 8.0
Fix from $2,300 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0851

Advantech WebAccess before 8.1 allows remote attackers to cause a denial of service (out-of-bounds memory access) via unspecified vectors.

Fix: after 8.0
Fix from $1,950 2016-01-15
Linux HIGH 8.1
CVE-2016-0778EPSS 22%

The (1) roaming_read and (2) roaming_write functions in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2, when certain proxy …

Fix: after 15.07
Fix from $1,950 2016-01-14
Acrobat Reader CRITICAL 9.8
CVE-2016-0946

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $2,300 2016-01-14
Acrobat Reader CRITICAL 9.8
CVE-2016-0945

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $2,300 2016-01-14
Acrobat Reader CRITICAL 9.8
CVE-2016-0944

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $2,300 2016-01-14
Acrobat Dc CRITICAL 9.8
CVE-2016-0942

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $2,300 2016-01-14
Acrobat Dc HIGH 8.8
CVE-2016-0939EPSS 7%

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $1,950 2016-01-14
Acrobat Reader HIGH 8.8
CVE-2016-0938

The AcroForm plugin in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Re…

Fix: after 15.009.20077
Fix from $1,950 2016-01-14
Acrobat Reader HIGH 8.8
CVE-2016-0936EPSS 8%

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $1,950 2016-01-14
Acrobat Reader CRITICAL 9.8
CVE-2016-0933EPSS 6%

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $2,300 2016-01-14
Acrobat Reader HIGH 8.8
CVE-2016-0931

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $1,950 2016-01-14
Excel HIGH 7.8
CVE-2016-0035EPSS 18%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Excel for Mac 2011, Excel 2016 for Mac, Office Compatibility…

Mitigation only
Fix from $1,950 2016-01-13
Edge HIGH 8.8
CVE-2016-0024EPSS 15%

The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Scripting Engine Memor…

Mitigation only
Fix from $1,950 2016-01-13
Windows 10 HIGH 7.8
CVE-2016-0015EPSS 35%

DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2016-01-13
Excel For Mac HIGH 7.8
CVE-2016-0010EPSS 23%

Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Excel for Mac 2011, PowerPoint for Mac 2011, Word for M…

Mitigation only
Fix from $1,950 2016-01-13
Edge CRITICAL 9.6
CVE-2016-0003EPSS 34%

Microsoft Edge allows remote attackers to execute arbitrary code via unspecified vectors, aka "Microsoft Edge Memory Corruption Vulnerability."

Mitigation only
Fix from $2,300 2016-01-13
Jscript HIGH 7.5
CVE-2016-0002EPSS 22%

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remot…

Mitigation only
Fix from $1,950 2016-01-13
Mac Os X CRITICAL 10.0
CVE-2015-8659

The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.

Fix: after 10.11.3
Fix from $2,300 2016-01-12
P8 Firmware HIGH 7.8
CVE-2015-8306

Buffer overflow in the HIFI driver in Huawei P8 phones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 befor…

Mitigation only
Fix from $1,950 2016-01-12
Big Ip Access Policy Manager CRITICAL 9.8
CVE-2015-8098

F5 BIG-IP APM 11.4.1 before 11.4.1 HF9, 11.5.x before 11.5.3, and 11.6.0 before 11.6.0 HF4 allow remote attackers to cause a denial of service or exe…

Mitigation only
Fix from $2,300 2016-01-12