Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Junos HIGH 7.5
CVE-2018-0020

Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a re…

Mitigation only
Fix from $1,950 2018-04-11
Dp300 Firmware MEDIUM 5.3
CVE-2017-17308

SCCPX module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, …

Mitigation only
Fix from $1,600 2018-04-11
Workload Control Center CRITICAL 9.8
CVE-2018-8954EPSS 7%

CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request.

Mitigation only
Fix from $2,300 2018-04-11
Mdm9607 Firmware CRITICAL 9.8
CVE-2017-18074

In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM…

Mitigation only
Fix from $2,300 2018-04-11
FreeBSD HIGH 7.5
CVE-2017-1081

In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a k…

Fix: after 11.0
Fix from $1,950 2018-04-10
Etherpad HIGH 8.1
CVE-2018-9327

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document…

Fix: 1.6.4+
Fix from $1,950 2018-04-07
Debian Linux HIGH 8.8
CVE-2018-9846

In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled …

Fix: after 1.3.5
Fix from $1,950 2018-04-07
Ubuntu Linux HIGH 7.8
CVE-2018-1000156EPSS 5%

GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)…

No fix yet
Fix from $1,950 2018-04-06
Micrologix 1400 B Firmware HIGH 7.5
CVE-2017-12088

An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below.…

Fix: after 21.2
Fix from $1,950 2018-04-05
Sitaware MEDIUM 5.3
CVE-2018-9115EPSS 6%

Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can f…

No fix yet
Fix from $1,600 2018-04-04
Android HIGH 7.5
CVE-2016-10235

A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#…

Mitigation only
Fix from $1,950 2018-04-04
Android HIGH 7.8
CVE-2017-13287

In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to lo…

Mitigation only
Fix from $1,950 2018-04-04
Android MEDIUM 5.3
CVE-2017-13295

A denial of service vulnerability in the Android framework (package installer). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. …

Mitigation only
Fix from $1,600 2018-04-04
Android HIGH 7.5
CVE-2017-13300

A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1. Android ID: A-71567394.

Mitigation only
Fix from $1,950 2018-04-04
Android HIGH 7.5
CVE-2017-13301

A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-66498711.

No fix yet
Fix from $1,950 2018-04-04
Android HIGH 7.5
CVE-2017-13302

A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-69969749.

Mitigation only
Fix from $1,950 2018-04-04
Android CRITICAL 9.8
CVE-2017-13284

In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lea…

Mitigation only
Fix from $2,300 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9256

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting th…

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9258

In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9259

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the b…

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9260

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c b…

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Wireshark HIGH 7.5
CVE-2018-9262

In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN…

Fix: after 2.4.5
Fix from $1,950 2018-04-04
Brave Browser HIGH 7.5
CVE-2016-10718EPSS 12%

Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service.

Fix: 0.13.0+
Fix from $1,950 2018-04-04
Stealth Svg HIGH 7.5
CVE-2018-8049

The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux…

Fix: 3.0.1999 / 3.2.030+
Fix from $1,950 2018-04-03
Ruby HIGH 7.5
CVE-2018-8779EPSS 7%

In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open method…

Fix: 2.2.10 / 2.3.7+
Fix from $1,950 2018-04-03
Android CRITICAL 9.8
CVE-2017-18147

In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve…

No fix yet
Fix from $2,300 2018-04-03
Etcd MEDIUM 5.5
CVE-2018-1099

DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in…

Fix: after 3.3.1
Fix from $1,600 2018-04-03
Big Ip Application Security Manager HIGH 7.5
CVE-2016-7472

F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request.

Mitigation only
Fix from $1,950 2018-04-03
Mac Os X HIGH 7.8
CVE-2018-4175

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows att…

Fix: 10.13.4+
Fix from $1,950 2018-04-03
Mac Os X MEDIUM 5.5
CVE-2018-4176

An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Images" component. It allows attack…

Fix: 10.13.4+
Fix from $1,600 2018-04-03