Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Tcmu Runner MEDIUM 5.5
CVE-2017-1000201

The tcmu-runner daemon in tcmu-runner version 1.0.5 to 1.2.0 is vulnerable to a local denial of service attack

Patch available
Fix from $1,600 2017-11-17
Android HIGH 7.5
CVE-2017-0858

Another vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-64836894.

Patch available
Fix from $1,950 2017-11-16
Android HIGH 7.8
CVE-2017-11027

In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing UBI image, size is not…

Patch available
Fix from $1,950 2017-11-16
Airwatch HIGH 7.8
CVE-2017-4931

VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add malicious data to an enrolled d…

Fix: 9.2.0+
Fix from $1,950 2017-11-16
Firepower Extensible Operating System MEDIUM 5.3
CVE-2017-12299

A vulnerability exists in the process of creating default IP blocks during device initialization for Cisco ASA Next-Generation Firewall Services that…

Mitigation only
Fix from $1,600 2017-11-16
Secure Firewall Management Center MEDIUM 5.8
CVE-2017-12300

A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file pol…

Mitigation only
Fix from $1,600 2017-11-16
Meeting Server MEDIUM 5.8
CVE-2017-12311

A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server…

Mitigation only
Fix from $1,600 2017-11-16
Advanced Malware Protection For Endpoints MEDIUM 6.7
CVE-2017-12312

An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker t…

Mitigation only
Fix from $1,600 2017-11-16
Packet Tracer MEDIUM 6.7
CVE-2017-12313

An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local atta…

Mitigation only
Fix from $1,600 2017-11-16
Trusted Boot HIGH 7.8
CVE-2017-16837

Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to…

Patch available
Fix from $1,950 2017-11-16
Karaf MEDIUM 5.5
CVE-2014-0219

Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sen…

Fix: 4.0.10+
Fix from $1,600 2017-11-15
Anti.virus HIGH 7.8
CVE-2017-14961

In IKARUS anti.virus 2.16.7, the ntguard.sys driver contains an Arbitrary Write vulnerability because of not validating input values from IOCtl 0x830…

No fix yet
Fix from $1,950 2017-11-15
Psftpd MEDIUM 5.3
CVE-2017-15270EPSS 7%

The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by atta…

No fix yet
Fix from $1,600 2017-11-15
Debian Linux MEDIUM 6.1
CVE-2017-8811

The implementation of raw message parameter expansion in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows HTML mangling…

Fix: after 1.27.3
Fix from $1,600 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8814

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attackers to replace text inside tags via a …

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Debian Linux HIGH 7.5
CVE-2017-8815

The language converter in MediaWiki before 1.27.4, 1.28.x before 1.28.3, and 1.29.x before 1.29.2 allows attribute injection attacks via glossary rul…

Fix: after 1.27.3
Fix from $1,950 2017-11-15
Edge MEDIUM 6.1
CVE-2017-11863

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows an attacker to trick…

Patch available
Fix from $1,600 2017-11-15
Grootfs HIGH 7.8
CVE-2017-14388

Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the groo…

Mitigation only
Fix from $1,950 2017-11-13
Iphone Os MEDIUM 5.5
CVE-2017-13849EPSS 6%

An issue was discovered in certain Apple products. iOS before 11.1 is affected. tvOS before 11.1 is affected. watchOS before 4.1 is affected. The iss…

Fix: 4.1 / 11.1+
Fix from $1,600 2017-11-13
Iphone Os MEDIUM 5.5
CVE-2017-13804

An issue was discovered in certain Apple products. iOS before 11.1 is affected. macOS before 10.13.1 is affected. tvOS before 11.1 is affected. watch…

Fix: 4.1 / 10.13.1+
Fix from $1,600 2017-11-13
Mac Os X HIGH 7.8
CVE-2017-13807

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Audio" component. It allows remote attac…

Fix: after 10.13.0
Fix from $1,950 2017-11-13
Mac Os X HIGH 7.8
CVE-2017-13809

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "AppleScript" component. It allows remote…

Fix: after 10.13.0
Fix from $1,950 2017-11-13
Safari MEDIUM 6.5
CVE-2017-13789

An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote atta…

Fix: after 11.0
Fix from $1,600 2017-11-13
Safari MEDIUM 6.5
CVE-2017-13790

An issue was discovered in certain Apple products. Safari before 11.0.1 is affected. The issue involves the "Safari" component. It allows remote atta…

Fix: after 11.0
Fix from $1,600 2017-11-13
Libebml2 MEDIUM 6.5
CVE-2017-12782

The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafte…

Fix: after 2012-08-26
Fix from $1,600 2017-11-10
Libebml2 MEDIUM 6.5
CVE-2017-12783

The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a c…

Fix: after 2012-08-26
Fix from $1,600 2017-11-10
Libebml2 MEDIUM 6.5
CVE-2017-12801

The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a …

Fix: after 2012-08-26
Fix from $1,600 2017-11-10
Libebml2 MEDIUM 6.5
CVE-2017-12802

The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via…

Fix: after 2012-08-26
Fix from $1,600 2017-11-10
Fox515t Firmware MEDIUM 5.5
CVE-2017-14025

An Improper Input Validation issue was discovered in ABB FOX515T release 1.0. An improper input validation vulnerability has been identified, allowin…

Mitigation only
Fix from $1,600 2017-11-06
Triton Ap Email HIGH 7.5
CVE-2017-11177

TRITON AP-EMAIL 8.2 before 8.2 IB does not properly restrict file access in an unspecified directory.

No fix yet
Fix from $1,950 2017-11-06