Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Nifi HIGH 7.5
CVE-2017-12632

A malicious host header in an incoming HTTP request could cause NiFi to load resources from an external server. The fix to sanitize host headers and …

Fix: after 1.4.0
Fix from $1,950 2018-01-23
Nifi CRITICAL 9.8
CVE-2017-15697

A malicious X-ProxyContextPath or X-Forwarded-Context header containing external resources or embedded code could cause remote code execution. The fi…

Fix: after 1.4.0
Fix from $2,300 2018-01-23
L2683a Firmware CRITICAL 9.8
CVE-2017-2750EPSS 6%

Insufficient Solution DLL Signature Validation allows potential execution of arbitrary code in HP LaserJet Enterprise printers, HP PageWide Enterpris…

Fix: 2308937_578483 / 2308937_578486+
Fix from $2,300 2018-01-23
Debian Linux MEDIUM 5.3
CVE-2017-15105

A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be u…

Fix: 1.6.8+
Fix from $1,600 2018-01-23
Recursor MEDIUM 5.3
CVE-2017-15093

When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x…

Fix: after 4.0.6
Fix from $1,600 2018-01-23
Enterprise Manager MEDIUM 6.5
CVE-2017-16594

This vulnerability allows remote attackers to create arbitrary files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build …

Mitigation only
Fix from $1,600 2018-01-23
Gitstack CRITICAL 9.8
CVE-2018-5955EPSS 75%

An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a…

Fix: after 2.3.10
Fix from $2,300 2018-01-21
Zillya\! Antivirus HIGH 7.8
CVE-2018-5956

In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other …

Mitigation only
Fix from $1,950 2018-01-21
Zillya\! Antivirus HIGH 7.8
CVE-2018-5957

In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other …

Mitigation only
Fix from $1,950 2018-01-21
Zillya\! Antivirus HIGH 7.8
CVE-2018-5958

In Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other …

Mitigation only
Fix from $1,950 2018-01-21
Yandex Browser HIGH 7.5
CVE-2017-7325

Yandex Browser before 16.9.0 allows remote attackers to spoof the address bar via window.open.

Fix: 16.9.0+
Fix from $1,950 2018-01-19
Android MEDIUM 5.7
CVE-2017-17860

In Samsung Gear products, Bluetooth link key is updated to the different key which is same with attacker's link key. It can be attacked without user'…

No fix yet
Fix from $1,600 2018-01-18
Debian Linux MEDIUM 6.5
CVE-2017-12197

It was found that libpam4j up to and including 1.8 did not properly validate user accounts when authenticating. A user with a valid password for a di…

Fix: after 1.8
Fix from $1,600 2018-01-18
Nx Os HIGH 7.5
CVE-2018-0090

A vulnerability in management interface access control list (ACL) configuration of Cisco NX-OS System Software could allow an unauthenticated, remote…

Mitigation only
Fix from $1,950 2018-01-18
Minnowboard 3 Firmware MEDIUM 5.5
CVE-2017-5699

Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs.

Fix: 0.65+
Fix from $1,600 2018-01-18
Antivirus MEDIUM 5.5
CVE-2017-16556

In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations.

Fix: 14.2.0137 / 15.1.0.53+
Fix from $1,600 2018-01-16
Antivirus MEDIUM 5.5
CVE-2017-17429

In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW int…

Fix: 14.2.0137 / 15.1.0.53+
Fix from $1,600 2018-01-16
Anti Malware HIGH 7.8
CVE-2018-5713

In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified …

No fix yet
Fix from $1,950 2018-01-16
Anti Malware HIGH 7.8
CVE-2018-5714

In Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified …

No fix yet
Fix from $1,950 2018-01-16
Algo Risk Application MEDIUM 5.4
CVE-2016-0207

IBM Algorithmics One-Algo Risk Application (ARA) 4.9.1 through 5.1.0 allows remote authenticated users to conduct clickjacking attacks via unspecifie…

Fix: after 5.1.0
Fix from $1,600 2018-01-16
Db2 MEDIUM 6.5
CVE-2016-0215

IBM DB2 9.7, 10.1 before FP6, and 10.5 before FP8 on AIX, Linux, HP, Solaris and Windows allow remote authenticated users to cause a denial of servic…

Patch available
Fix from $1,600 2018-01-16
Debian Linux HIGH 7.5
CVE-2017-13194

A vulnerability in the Android media framework (libvpx) related to odd frame width. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android …

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13198

A vulnerability in the Android media framework (ex) related to composition of frames lacking a color map. Product: Android. Versions: 7.0, 7.1.1, 7.1…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13214

In the hardware HEVC decoder, some media files could cause a page fault. This could lead to a remote denial of service of a critical system process w…

Mitigation only
Fix from $1,950 2018-01-12
Android HIGH 8.8
CVE-2017-13176

In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privileg…

Patch available
Fix from $1,950 2018-01-12
Android HIGH 7.5
CVE-2017-13186

A vulnerability in the Android media framework (libavc) related to incorrect use of mmco parameters. Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8…

Patch available
Fix from $1,950 2018-01-12
Skybox Platform CRITICAL 9.8
CVE-2015-9246

An issue was discovered in Skybox Platform before 7.5.201. Remote Unauthenticated Code Execution exists via a WAR archive containing a JSP file. The …

Fix: 7.5.201+
Fix from $2,300 2018-01-12
Cups HIGH 8.8
CVE-2014-8166

The browsing feature in the server in CUPS does not filter ANSI escape sequences from shared printer names, which might allow remote attackers to exe…

Fix: 1.6+
Fix from $1,950 2018-01-12
Android HIGH 7.8
CVE-2017-15845

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, an invalid input of firmware size (ne…

Patch available
Fix from $1,950 2018-01-10
Gyazo MEDIUM 5.5
CVE-2014-4994

lib/gyazo/client.rb in the gyazo gem 1.0.0 for Ruby allows local users to write to arbitrary files via a symlink attack on a temporary file, related …

No fix yet
Fix from $1,600 2018-01-10