Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 7.8
CVE-2018-6084

Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrar…

Fix: 66.0.3359.117+
Fix from $1,950 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16080

A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the conten…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome MEDIUM 6.5
CVE-2018-16088

A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files w…

Fix: 69.0.3497.81+
Fix from $1,600 2019-01-09
Chrome CRITICAL 9.6
CVE-2018-16068

Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM…

Fix: 69.0.3497.81+
Fix from $2,300 2019-01-09
Chrome CRITICAL 9.6
CVE-2017-15402

Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces…

Fix: 62.0.3202.74+
Fix from $2,300 2019-01-09
Mcafee Web Gateway HIGH 7.5
CVE-2019-3581

Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a c…

Fix: 7.8.2.5 / 8.0.2.0+
Fix from $1,950 2019-01-09
Wireshark MEDIUM 5.5
CVE-2019-5716

In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB befor…

Fix: after 2.6.5
Fix from $1,600 2019-01-08
Wireshark MEDIUM 5.5
CVE-2019-5717

In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting t…

Fix: after 2.6.5
Fix from $1,600 2019-01-08
Windows 10 HIGH 8.4
CVE-2019-0550

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-01-08
Windows 10 HIGH 8.4
CVE-2019-0551

A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g…

Patch available
Fix from $1,950 2019-01-08
Msm8996au Firmware HIGH 7.8
CVE-2017-18320

QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions …

Mitigation only
Fix from $1,950 2019-01-03
Debian Linux MEDIUM 6.5
CVE-2018-20662

In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of…

Patch available
Fix from $1,600 2019-01-03
Debian Linux MEDIUM 5.5
CVE-2018-19478

In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file.

Fix: 9.26+
Fix from $1,600 2019-01-02
Core Ftp HIGH 7.5
CVE-2018-20658EPSS 8%

The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comma…

No fix yet
Fix from $1,950 2019-01-02
Xplatform HIGH 7.8
CVE-2018-5197

A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command i…

Mitigation only
Fix from $1,950 2019-01-02
Ubuntu Linux MEDIUM 6.5
CVE-2018-20650

A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data…

Patch available
Fix from $1,600 2019-01-01
Nuclide CRITICAL 9.8
CVE-2018-6333

The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL c…

Fix: 0.290.0+
Fix from $2,300 2018-12-31
Proxygen HIGH 7.5
CVE-2018-6343

Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Cert…

Fix: 2018.11.19.00+
Fix from $1,950 2018-12-31
Proxygen HIGH 7.5
CVE-2018-6347

An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.1…

Fix: 2018.12.31.00+
Fix from $1,950 2018-12-31
Hhvm CRITICAL 9.8
CVE-2018-6334

Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before be…

Fix: after 3.25.1
Fix from $2,300 2018-12-31
Hhvm HIGH 7.5
CVE-2018-6335

A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affec…

Fix: after 3.21.10
Fix from $1,950 2018-12-31
Cim HIGH 7.5
CVE-2018-20614

public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI.

No fix yet
Fix from $1,950 2018-12-30
Mxq Tv Box Firmware HIGH 7.5
CVE-2018-14988

The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework…

Mitigation only
Fix from $1,950 2018-12-28
Arv7519rw22 Livebox 2.1 Firmware HIGH 7.5
CVE-2018-20575

Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-1…

No fix yet
Fix from $1,950 2018-12-28
Ubuntu Linux MEDIUM 6.5
CVE-2018-20551

A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media ann…

Patch available
Fix from $1,600 2018-12-28
Dextuploadx5 CRITICAL 9.8
CVE-2018-5203

DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary f…

Fix: after 2.2.0.0
Fix from $2,300 2018-12-28
Liblas MEDIUM 6.5
CVE-2018-20539

There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that …

No fix yet
Fix from $1,600 2018-12-28
74cms HIGH 8.1
CVE-2018-20519

An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intentio…

No fix yet
Fix from $1,950 2018-12-27
Qt MEDIUM 6.5
CVE-2018-19869

An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp.

Fix: 5.11.3+
Fix from $1,600 2018-12-26
Epia E900 Firmware HIGH 7.5
CVE-2018-20404

ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which ca…

No fix yet
Fix from $1,950 2018-12-26