Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Graphicsmagick HIGH 8.8
CVE-2017-16547

The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, wh…

Patch available
Fix from $1,950 2017-11-06
Linux Kernel MEDIUM 6.6
CVE-2017-16538

drivers/media/usb/dvb-usb-v2/lmedm04.c in the Linux kernel through 4.13.11 allows local users to cause a denial of service (general protection fault …

Fix: after 4.13.11
Fix from $1,600 2017-11-04
Vir.it Explorer HIGH 7.8
CVE-2017-16237

In Vir.IT eXplorer Anti-Virus before 8.5.42, the driver file (VIAGLT64.SYS) contains an Arbitrary Write vulnerability because of not validating input…

Fix: 8.5.42+
Fix from $1,950 2017-11-03
Aironet 1562 Firmware MEDIUM 6.5
CVE-2017-12273

A vulnerability in 802.11 association request frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthe…

Mitigation only
Fix from $1,600 2017-11-02
Aironet 1562 Firmware MEDIUM 6.5
CVE-2017-12274

A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points …

Mitigation only
Fix from $1,600 2017-11-02
Wireless Lan Controller Software HIGH 7.4
CVE-2017-12275

A vulnerability in the implementation of 802.11v Basic Service Set (BSS) Transition Management functionality in Cisco Wireless LAN Controllers could …

Mitigation only
Fix from $1,950 2017-11-02
Prime Collaboration Provisioning HIGH 8.1
CVE-2017-12276

A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an aut…

Fix: 12.3+
Fix from $1,950 2017-11-02
Firepower Extensible Operating System HIGH 8.8
CVE-2017-12277

A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security…

Fix: after 1.1.3
Fix from $1,950 2017-11-02
Webkitgtk\+ MEDIUM 5.3
CVE-2017-1000122

The UNIX IPC layer in WebKit, including WebKitGTK+ prior to 2.16.3, does not properly validate certain message metadata, allowing a compromised secon…

Fix: 2.16.3+
Fix from $1,600 2017-11-01
Docker MEDIUM 6.5
CVE-2017-14992

Lack of content verification in Docker-CE (Also known as Moby) versions 1.12.6-0, 1.10.3, 17.03.0, 17.03.1, 17.03.2, 17.06.0, 17.06.1, 17.06.2, 17.09…

Fix: after 1.10.3
Fix from $1,600 2017-11-01
Foxit Reader HIGH 8.8
CVE-2017-10953

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is req…

Patch available
Fix from $1,950 2017-10-31
Httpclient CRITICAL 9.8
CVE-2013-4366

http/impl/client/HttpClientBuilder.java in Apache HttpClient 4.3.x before 4.3.1 does not ensure that X509HostnameVerifier is not null, which allows a…

Patch available
Fix from $2,300 2017-10-30
Cordova File Transfer HIGH 7.5
CVE-2014-0072EPSS 8%

ios/CDVFileTransfer.m in the Apache Cordova File-Transfer standalone plugin (org.apache.cordova.file-transfer) before 0.4.2 for iOS and the File-Tran…

Fix: after 2.9.0
Fix from $1,950 2017-10-30
Juddi MEDIUM 5.3
CVE-2009-1197

Apache jUDDI before 2.0 allows attackers to spoof entries in log files via vectors related to error logging of keys from uddiget.jsp.

Mitigation only
Fix from $1,600 2017-10-30
Struts HIGH 8.8
CVE-2016-3090EPSS 6%

The TextParseUtil.translateVariables method in Apache Struts 2.x before 2.3.20 allows remote attackers to execute arbitrary code via a crafted OGNL e…

Mitigation only
Fix from $1,950 2017-10-30
Debian Linux HIGH 7.5
CVE-2017-16227EPSS 13%

The aspath_put function in bgpd/bgp_aspath.c in Quagga before 1.2.2 allows remote attackers to cause a denial of service (session drop) via BGP UPDAT…

Fix: after 1.2.1
Fix from $1,950 2017-10-29
Converto Video Downloader \& Converter HIGH 7.5
CVE-2017-15956

ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.

No fix yet
Fix from $1,950 2017-10-29
Linux Kernel HIGH 7.8
CVE-2017-15951

The KEYS subsystem in the Linux kernel before 4.13.10 does not correctly synchronize the actions of updating versus finding a key in the "negative" s…

Fix: 4.4.95 / 4.9.59+
Fix from $1,950 2017-10-28
Cordova MEDIUM 5.3
CVE-2015-1835EPSS 7%

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to …

Fix: after 3.7.1
Fix from $1,600 2017-10-27
Ox HIGH 7.5
CVE-2017-15928

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has state…

No fix yet
Fix from $1,950 2017-10-27
Fortios MEDIUM 6.5
CVE-2017-14182

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresp…

Mitigation only
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5104

Inappropriate implementation in interstitials in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to spoof the contents of the o…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5105

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5106

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a remote attacker to p…

Fix: after 60.0.3112.78
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5110

Inappropriate implementation of the web payments API on blob: and data: schemes in Web Payments in Google Chrome prior to 60.0.3112.78 for Mac, Windo…

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Chrome HIGH 8.8
CVE-2017-5121EPSS 5%

Inappropriate use of JIT optimisation in V8 in Google Chrome prior to 61.0.3163.100 for Linux, Windows, and Mac allowed a remote attacker to execute …

Fix: 61.0.3163.100+
Fix from $1,950 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5076

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed …

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5086

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Windows and Mac allowed a remote attacker to perform domain spo…

Fix: 59.0.3071.86+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5089

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.104 for Mac allowed a remote attacker to perform domain spoofing via a…

Fix: 59.0.3071.104+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5090

Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.115 for Mac allowed a remote attacker to perform domain spoofing via a…

Fix: 59.0.3071.115+
Fix from $1,600 2017-10-27