Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Tamobileapp MEDIUM 5.3
CVE-2017-17226

The TripAdvisor app with the versions before TAMobileApp-24.6.4 pre-installed in some Huawei mobile phones have an arbitrary URL loading vulnerabilit…

Fix: 24.6.4+
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 6.5
CVE-2017-17304

The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the…

Mitigation only
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 5.5
CVE-2017-17148

Huawei DP300 V500R002C00 have a DoS vulnerability due to the lack of validation when the malloc is called. An authenticated local attacker can craft …

Mitigation only
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 6.5
CVE-2017-17168

The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the…

Mitigation only
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 6.5
CVE-2017-17169

The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the…

Mitigation only
Fix from $1,600 2018-03-09
Dp300 Firmware MEDIUM 6.5
CVE-2017-17170

The CIDAM Protocol on some Huawei Products has multiple input validation vulnerabilities due to insufficient validation of specific messages when the…

Mitigation only
Fix from $1,600 2018-03-09
Secure Access Control System CRITICAL 9.8
CVE-2018-0147 KEVEPSS 18%

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated,…

Mitigation only
Fix from $2,300 2018-03-08
Identity Services Engine HIGH 8.8
CVE-2018-0213

A vulnerability in the credential reset functionality for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain …

Mitigation only
Fix from $1,950 2018-03-08
Identity Services Engine MEDIUM 5.3
CVE-2018-0214

A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary com…

Mitigation only
Fix from $1,600 2018-03-08
Bleach CRITICAL 9.8
CVE-2018-7753

An issue was discovered in Bleach 2.1.x before 2.1.3. Attributes that have URI values weren't properly sanitized if the values contained character en…

Patch available
Fix from $2,300 2018-03-07
Linux Kernel MEDIUM 5.5
CVE-2017-18221

The __munlock_pagevec function in mm/mlock.c in the Linux kernel before 4.11.4 allows local users to cause a denial of service (NR_MLOCK accounting c…

Fix: 4.11.4+
Fix from $1,600 2018-03-07
Antman CRITICAL 9.8
CVE-2018-7739EPSS 53%

antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demon…

Fix: after 0.9.0c
Fix from $2,300 2018-03-07
Dp300 Firmware MEDIUM 5.5
CVE-2017-17138

PEM module of DP300 V500R002C00; IPS Module V500R001C00; V500R001C30; NGFW Module V500R001C00; V500R002C00; NIP6300 V500R001C00; V500R001C30; NIP6600…

Mitigation only
Fix from $1,600 2018-03-05
Aws Lambda Multipart Parser HIGH 7.5
CVE-2018-7560

index.js in the Anton Myshenin aws-lambda-multipart-parser NPM package before 0.1.2 has a Regular Expression Denial of Service (ReDoS) issue via a cr…

Fix: after 0.1.1
Fix from $1,950 2018-03-04
Embos\/ip Ftp Server HIGH 7.5
CVE-2018-7449EPSS 8%

SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR com…

No fix yet
Fix from $1,950 2018-03-04
Dualdesk HIGH 7.5
CVE-2018-7583EPSS 38%

Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.

No fix yet
Fix from $1,950 2018-03-04
Identity Manager HIGH 7.2
CVE-2017-9279

NetIQ Identity Manager before 4.5.6.1 allowed uploading files with double extensions or non-image content in the Themes handling of the User Applicat…

Fix: 4.5.6.1+
Fix from $1,950 2018-03-02
PostgreSQL HIGH 8.8
CVE-2018-1058EPSS 13%

A flaw was found in the way Postgresql allowed a user to modify the behavior of a query for other users. An attacker with a user account could use th…

Fix: 9.3.22 / 9.4.17+
Fix from $1,950 2018-03-02
Amazon Music HIGH 8.8
CVE-2018-1169

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction …

Mitigation only
Fix from $1,950 2018-03-02
Operations Orchestration HIGH 7.5
CVE-2018-6490

Denial of Service vulnerability in Micro Focus Operations Orchestration Software, version 10.x. This vulnerability could be remotely exploited to all…

Mitigation only
Fix from $1,950 2018-03-02
Linux Enterprise Software Development Kit MEDIUM 5.3
CVE-2017-14804

The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of …

Mitigation only
Fix from $1,600 2018-03-01
Libzypp HIGH 8.1
CVE-2017-7435

In libzypp before 20170803 it was possible to add unsigned YUM repositories without warning to the user that could lead to man in the middle or malic…

Fix: after 16.15.2
Fix from $1,950 2018-03-01
Libzypp HIGH 8.1
CVE-2017-7436

In libzypp before 20170803 it was possible to retrieve unsigned packages without a warning to the user which could lead to man in the middle or malic…

Fix: after 16.15.2
Fix from $1,950 2018-03-01
Libzypp CRITICAL 9.8
CVE-2017-9269

In libzypp before August 2018 GPG keys attached to YUM repositories were not correctly pinned, allowing malicious repository mirrors to silently down…

Mitigation only
Fix from $2,300 2018-03-01
Cryptctl CRITICAL 9.1
CVE-2017-9270

In cryptctl before version 2.0 a malicious server could send RPC requests that could overwrite files outside of the cryptctl key database.

Mitigation only
Fix from $2,300 2018-03-01
Big Ip Local Traffic Manager HIGH 7.5
CVE-2017-6150

Under certain conditions for F5 BIG-IP systems 13.0.0 or 12.1.0 - 12.1.3.1, using FastL4 profiles, when the Reassemble IP Fragments option is disable…

Fix: after 12.1.3.1
Fix from $1,950 2018-03-01
Big Ip Application Security Manager HIGH 7.5
CVE-2017-6154

On F5 BIG-IP systems running 13.0.0, 12.1.0 - 12.1.3.1, or 11.6.1 - 11.6.2, the BIG-IP ASM bd daemon may core dump memory under some circumstances wh…

Fix: after 12.1.3.1
Fix from $1,950 2018-03-01
Enterprise Linux Desktop HIGH 7.5
CVE-2018-7549

In params.c in zsh through 5.4.2, there is a crash during a copy of an empty hash table, as demonstrated by typeset -p.

Fix: after 5.4.2
Fix from $1,950 2018-02-27
Traffic Server HIGH 8.6
CVE-2017-5660

There is a vulnerability in Apache Traffic Server (ATS) 6.2.0 and prior and 7.0.0 and prior with the Host header and line folding. This can have issu…

Fix: after 6.2.0
Fix from $1,950 2018-02-27
Traffic Server HIGH 7.5
CVE-2017-7671

There is a DOS attack vulnerability in Apache Traffic Server (ATS) 5.2.0 to 5.3.2, 6.0.0 to 6.2.0, and 7.0.0 with the TLS handshake. This issue can c…

Fix: after 6.2.0
Fix from $1,950 2018-02-27