Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Suse Linux Enterprise Desktop HIGH 7.8
CVE-2016-5759

The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.

Mitigation only
Fix from $1,950 2017-09-08
Asr 5500 Firmware MEDIUM 5.3
CVE-2017-12217

A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution …

Mitigation only
Fix from $1,600 2017-09-07
Asyncos MEDIUM 5.8
CVE-2017-12218

A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Ap…

Mitigation only
Fix from $1,600 2017-09-07
Ir800 Integrated Services Router Firmware MEDIUM 6.4
CVE-2017-12223

A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to…

Mitigation only
Fix from $1,600 2017-09-07
Prime Collaboration Provisioning MEDIUM 6.5
CVE-2017-6792

A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to ove…

Mitigation only
Fix from $1,600 2017-09-07
Meeting Server MEDIUM 6.7
CVE-2017-6794

A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and…

Mitigation only
Fix from $1,600 2017-09-07
Debian Linux HIGH 8.8
CVE-2017-14169

In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi…

Patch available
Fix from $1,950 2017-09-07
Svn Workbench HIGH 8.8
CVE-2015-0853

svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu i…

Fix: after 1.6.2
Fix from $1,950 2017-09-06
Linux Audit MEDIUM 5.3
CVE-2015-5186

Audit before 2.4.4 in Linux does not sanitize escape characters in filenames.

Fix: after 2.4.3
Fix from $1,600 2017-09-06
Asterisk HIGH 7.5
CVE-2017-14098EPSS 47%

In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact…

Patch available
Fix from $1,950 2017-09-02
Debian Linux HIGH 7.5
CVE-2017-12874

The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid…

Patch available
Fix from $1,950 2017-09-01
Hivemanager Classic HIGH 7.8
CVE-2017-14105

HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature doe…

Patch available
Fix from $1,950 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-12869

The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica…

Fix: after 1.14.13
Fix from $1,950 2017-09-01
Livesafe MEDIUM 5.9
CVE-2017-3898

A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo…

Fix: after 16.0.2
Fix from $1,600 2017-09-01
Debian Linux HIGH 7.5
CVE-2017-0900EPSS 8%

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie…

Fix: after 2.6.12
Fix from $1,950 2017-08-31
Debian Linux HIGH 7.5
CVE-2017-0901EPSS 26%

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th…

Patch available
Fix from $1,950 2017-08-31
Async Http Client HIGH 7.5
CVE-2017-14063

Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if …

Fix: 2.0.35+
Fix from $1,950 2017-08-31
7km Pac Switched Ethernet Profinet Expansion Module Firmware MEDIUM 6.5
CVE-2017-9945

In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a speci…

Fix: after 2.1.2
Fix from $1,600 2017-08-30
Ofbiz HIGH 8.8
CVE-2016-4462

By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar…

Mitigation only
Fix from $1,950 2017-08-30
Wireshark HIGH 7.5
CVE-2017-13767

In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/pac…

Patch available
Fix from $1,950 2017-08-30
Cognos Analytics MEDIUM 6.1
CVE-2017-1428

IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web …

Patch available
Fix from $1,600 2017-08-29
Struts HIGH 7.5
CVE-2015-5209EPSS 9%

Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto…

Mitigation only
Fix from $1,950 2017-08-29
Question2answer HIGH 7.5
CVE-2017-12775

qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.

Fix: after 1.7.4
Fix from $1,950 2017-08-29
Foxit Reader HIGH 8.8
CVE-2017-10952EPSS 15%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is requ…

No fix yet
Fix from $1,950 2017-08-29
SQLite MEDIUM 5.5
CVE-2017-13685

The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted…

Mitigation only
Fix from $1,600 2017-08-29
Libraw HIGH 7.5
CVE-2017-13735

There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of serv…

Mitigation only
Fix from $1,950 2017-08-29
Pki Core HIGH 7.5
CVE-2015-0234

Multiple temporary file creation vulnerabilities in pki-core 10.2.0.

Patch available
Fix from $1,950 2017-08-29
Kgb Bot HIGH 7.5
CVE-2015-1554

kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash).

No fix yet
Fix from $1,950 2017-08-28
Fli4l HIGH 8.8
CVE-2015-1443

The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code.

Fix: after 3.10.0
Fix from $1,950 2017-08-28
Flightgear HIGH 7.5
CVE-2017-13709

In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the con…

No fix yet
Fix from $1,950 2017-08-27