Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Chrome HIGH 8.8
CVE-2017-5092

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Windows allowed a remote attacker to potential…

Fix: 60.0.3112.78+
Fix from $1,950 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5093

Inappropriate implementation in modal dialog handling in Blink in Google Chrome prior to 60.0.3112.78 for Mac, Windows, Linux, and Android allowed a …

Fix: 60.0.3112.78+
Fix from $1,600 2017-10-27
Chrome HIGH 8.8
CVE-2017-5097

Insufficient validation of untrusted input in Skia in Google Chrome prior to 60.0.3112.78 for Linux allowed a remote attacker to perform an out of bo…

Fix: after 60.0.3112.76
Fix from $1,950 2017-10-27
Chrome HIGH 8.8
CVE-2017-5099

Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially g…

Fix: after 60.0.3112.76
Fix from $1,950 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5067

An insufficient watchdog timer in navigation in Google Chrome prior to 58.0.3029.81 for Linux, Windows, and Mac allowed a remote attacker to spoof th…

Fix: 58.0.3029.81+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.3
CVE-2017-5071

Insufficient validation of untrusted input in V8 in Google Chrome prior to 59.0.3071.86 for Linux, Windows and Mac, and 59.0.3071.92 for Android allo…

Fix: 59.0.3071.86 / 59.0.3071.92+
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5072

Inappropriate implementation in Omnibox in Google Chrome prior to 59.0.3071.92 for Android allowed a remote attacker to perform domain spoofing with …

Fix: 59.0.3071.92+
Fix from $1,600 2017-10-27
Daeja Viewone HIGH 7.5
CVE-2017-1210

IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to lo…

Mitigation only
Fix from $1,950 2017-10-24
Keystone HIGH 8.8
CVE-2017-15879EPSS 6%

CSV Injection (aka Excel Macro Injection or Formula Injection) exists in admin/server/api/download.js and lib/list/getCSVData.js in KeystoneJS before…

Fix: after 4.0.0
Fix from $1,950 2017-10-24
Salt HIGH 7.5
CVE-2017-14696

SaltStack Salt before 2016.3.8, 2016.11.x before 2016.11.8, and 2017.7.x before 2017.7.2 allows remote attackers to cause a denial of service via a c…

Fix: after 2016.3.7
Fix from $1,950 2017-10-24
Iphone Os MEDIUM 5.5
CVE-2017-7118

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Messages" component. It allows remote attackers…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Mac Os X MEDIUM 5.5
CVE-2017-7119

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "IOFireWireFamily" component. It allows att…

Fix: after 10.12.6
Fix from $1,600 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7121

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7122

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7123

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7124

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7125

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Mac Os X CRITICAL 9.8
CVE-2017-7126

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the third-party "file" product. Versions before…

Fix: after 10.12.6
Fix from $2,300 2017-10-23
Safari MEDIUM 6.5
CVE-2017-7106

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Iphone Os MEDIUM 5.5
CVE-2017-7072

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "iBooks" component. It allows remote attackers t…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Mac Os X MEDIUM 5.5
CVE-2017-7074

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "AppSandbox" component. It allows attackers…

Fix: after 10.12.6
Fix from $1,600 2017-10-23
Safari MEDIUM 6.5
CVE-2017-7085

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. The issue involves the "Safari" component…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Debian Linux HIGH 7.8
CVE-2013-6049

apt-listbugs before 0.1.10 creates temporary files insecurely, which allows attackers to have unspecified impact via unknown vectors.

Mitigation only
Fix from $1,950 2017-10-20
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2017-6141

In F5 BIG-IP LTM, AAM, AFM, APM, ASM, Link Controller, PEM, and WebSafe 12.1.0 through 12.1.2, certain values in a TLS abbreviated handshake when usi…

Mitigation only
Fix from $1,600 2017-10-20
Kx Hjb1000 Firmware HIGH 7.5
CVE-2017-2132

Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to delete arbitrary files in a specific directory…

Mitigation only
Fix from $1,950 2017-10-20
Prtg Network Monitor MEDIUM 6.7
CVE-2017-15651

PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding i…

Mitigation only
Fix from $1,600 2017-10-20
Data Protection Advisor HIGH 8.8
CVE-2017-10955EPSS 6%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication…

Mitigation only
Fix from $1,950 2017-10-19
Prime Network Analysis Module MEDIUM 5.3
CVE-2017-12285EPSS 12%

A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary fi…

Mitigation only
Fix from $1,600 2017-10-19
Jabber MEDIUM 5.5
CVE-2017-12286

A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affec…

Mitigation only
Fix from $1,600 2017-10-19
Nx Os MEDIUM 6.7
CVE-2017-12301

A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser an…

Mitigation only
Fix from $1,600 2017-10-19