Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 MEDIUM 6.6
CVE-2017-11885EPSS 39%

Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi…

Patch available
Fix from $1,600 2017-12-12
Business Application Software Integrated Solution MEDIUM 6.5
CVE-2017-16691

SAP Note Assistant tool (SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31,7.40, from 7.50 to 7.52) supports upload of digitally signed note…

Mitigation only
Fix from $1,600 2017-12-12
Dolphin HIGH 8.8
CVE-2017-17551

The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulnerability when attempting to re…

Mitigation only
Fix from $1,950 2017-12-11
Pan Os CRITICAL 9.8
CVE-2017-15944 KEVEPSS 98%

Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrar…

Fix: 6.1.19 / 7.0.19+
Fix from $2,300 2017-12-11
Enterprise Linux MEDIUM 5.5
CVE-2017-15121

A non-privileged user is able to mount a fuse filesystem on RHEL 6 or 7 and crash a system if an application punches a hole in a file that does not e…

Mitigation only
Fix from $1,600 2017-12-07
Android HIGH 8.8
CVE-2017-0872

A remote code execution vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-6529…

Patch available
Fix from $1,950 2017-12-06
Android MEDIUM 6.5
CVE-2017-0873

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android …

Mitigation only
Fix from $1,600 2017-12-06
Android MEDIUM 6.5
CVE-2017-0874

A denial of service vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID…

Mitigation only
Fix from $1,600 2017-12-06
Android HIGH 8.8
CVE-2017-0876

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-64964675.

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 8.8
CVE-2017-0877

A remote code execution vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0. Android ID A-66372937.

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 8.8
CVE-2017-0878

A remote code execution vulnerability in the Android media framework (libhevc). Product: Android. Versions: 8.0. Android ID A-65186291.

Mitigation only
Fix from $1,950 2017-12-06
Android MEDIUM 6.5
CVE-2017-13148

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android …

Mitigation only
Fix from $1,600 2017-12-06
Linux Kernel HIGH 7.8
CVE-2017-15868

The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, whic…

Fix: 3.2.97 / 3.10.108+
Fix from $1,950 2017-12-05
Android CRITICAL 9.8
CVE-2017-14908

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the SafeSwitch test application does …

Mitigation only
Fix from $2,300 2017-12-05
Android CRITICAL 9.8
CVE-2017-14909

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a count value that is read from a fil…

No fix yet
Fix from $2,300 2017-12-05
Android CRITICAL 9.8
CVE-2017-14914

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, handles in the global client structur…

No fix yet
Fix from $2,300 2017-12-05
Struts MEDIUM 6.2
CVE-2017-15707EPSS 10%

In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malici…

Fix: after 2.5.14
Fix from $1,600 2017-12-01
Otter CRITICAL 9.8
CVE-2017-17086

Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (cr…

Fix: after 1.7.4
Fix from $2,300 2017-12-01
Dir 605l Model B Firmware HIGH 7.5
CVE-2017-17065

An issue was discovered on D-Link DIR-605L Model B before FW2.11betaB06_hbrf devices, related to the code that handles the authentication values for …

Mitigation only
Fix from $1,950 2017-11-30
Ios Xr MEDIUM 5.3
CVE-2017-12355

A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthen…

Mitigation only
Fix from $1,600 2017-11-30
Webex Meetings Server CRITICAL 9.6
CVE-2017-12367

A "Cisco WebEx Network Recording Player Denial of Service Vulnerability" exists in Cisco WebEx Network Recording Player for Advanced Recording Format…

Mitigation only
Fix from $2,300 2017-11-30
Webex Meeting Center MEDIUM 5.0
CVE-2017-12297

A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Re…

Mitigation only
Fix from $1,600 2017-11-30
Ip Phone 8800 Series Firmware MEDIUM 5.8
CVE-2017-12328

A vulnerability in Session Initiation Protocol (SIP) call handling in Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.7
CVE-2017-12334

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An atta…

Mitigation only
Fix from $1,600 2017-11-30
Nx Os MEDIUM 6.0
CVE-2017-12338

A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to read the contents of arbitrary files. The v…

Mitigation only
Fix from $1,600 2017-11-30
Winamp Pro MEDIUM 5.5
CVE-2017-16951

Winamp Pro 5.66 Build 3512 allows remote attackers to cause a denial of service via a crafted WAV, WMV, AU, ASF, AIFF, or AIF file.

No fix yet
Fix from $1,600 2017-11-28
Kmplayer MEDIUM 5.5
CVE-2017-16952

KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.

No fix yet
Fix from $1,600 2017-11-28
Scaleio HIGH 7.5
CVE-2017-8019

An issue was discovered in EMC ScaleIO 2.0.1.x. A vulnerability in message parsers (MDM, SDS, and LIA) could potentially allow an unauthenticated rem…

Mitigation only
Fix from $1,950 2017-11-28
Mathjs CRITICAL 9.8
CVE-2017-1001003

math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an obje…

Fix: 3.17.0+
Fix from $2,300 2017-11-27
Typed Function HIGH 8.8
CVE-2017-1001004

typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name cou…

Fix: 0.10.6+
Fix from $1,950 2017-11-27