Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Android CRITICAL 9.8
CVE-2015-0574

In all Qualcomm products with Android releases from CAF using the Linux kernel, the validation of filesystem access was insufficient.

No fix yet
Fix from $2,300 2017-08-18
Open Uri Cached HIGH 7.8
CVE-2015-3649

The open-uri-cached rubygem allows local users to execute arbitrary Ruby code by creating a directory under /tmp containing "openuri-" followed by a …

Mitigation only
Fix from $1,950 2017-08-18
Data Ontap MEDIUM 5.9
CVE-2017-12859

NetApp Data ONTAP before 8.2.5, when operating in 7-Mode in NFS environments, allows remote attackers to cause a denial of service via unspecified ve…

Fix: after 8.2.4
Fix from $1,600 2017-08-18
Unity Editor CRITICAL 9.8
CVE-2017-12939

A Remote Code Execution vulnerability was identified in all Windows versions of Unity Editor, e.g., before 5.3.8p2, 5.4.x before 5.4.5p5, 5.5.x befor…

Patch available
Fix from $2,300 2017-08-18
Asr 5000 Software MEDIUM 6.7
CVE-2017-6773

A vulnerability in the CLI of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticate…

Mitigation only
Fix from $1,600 2017-08-17
GitLab HIGH 8.8
CVE-2017-12426

GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before …

Fix: after 8.17.7
Fix from $1,950 2017-08-14
Subversion CRITICAL 9.8
CVE-2017-9800EPSS 18%

A maliciously constructed svn+ssh:// URL would cause Subversion clients before 1.8.19, 1.9.x before 1.9.7, and 1.10.0.x through 1.10.0-alpha3 to run …

Fix: after 1.8.18
Fix from $2,300 2017-08-11
1g L2 7 Slb HIGH 8.2
CVE-2017-3752

An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo …

Fix: after 21.0.24.0
Fix from $1,950 2017-08-09
Android HIGH 7.8
CVE-2017-0712

A elevation of privilege vulnerability in the Android framework (wi-fi service). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Patch available
Fix from $1,950 2017-08-09
Android HIGH 7.8
CVE-2017-0721

A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android I…

Patch available
Fix from $1,950 2017-08-09
Android MEDIUM 5.5
CVE-2017-0724

A denial of service vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A…

Patch available
Fix from $1,600 2017-08-09
Ethernet Diagnostics Driver Iqvw32.sys HIGH 7.8
CVE-2015-2291 KEVEPSS 9%

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a de…

Patch available
Fix from $1,950 2017-08-09
Windows 10 HIGH 8.8
CVE-2017-8664

Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow…

Patch available
Fix from $1,950 2017-08-08
Gnutls HIGH 7.5
CVE-2016-4456

The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.

Mitigation only
Fix from $1,950 2017-08-08
Windows 10 MEDIUM 6.8
CVE-2017-8623EPSS 6%

Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service vulnerability when it fails to properly validate input f…

Patch available
Fix from $1,600 2017-08-08
Simatic Logon HIGH 7.5
CVE-2017-9938

A vulnerability was discovered in Siemens SIMATIC Logon (All versions before V1.6) that could allow specially crafted packets sent to the SIMATIC Log…

Fix: after 1.5
Fix from $1,950 2017-08-08
Imagemagick MEDIUM 6.5
CVE-2017-12670

In ImageMagick 7.0.6-3, missing validation was found in coders/mat.c, leading to an assertion failure in the function DestroyImage in MagickCore/imag…

Patch available
Fix from $1,600 2017-08-07
Imagemagick MEDIUM 6.5
CVE-2017-12676

In ImageMagick 7.0.6-3, a memory leak vulnerability was found in the function ReadOneJNGImage in coders/png.c, which allows attackers to cause a deni…

Patch available
Fix from $1,600 2017-08-07
Ghostscript HIGH 8.8
CVE-2016-7976EPSS 25%

The PS Interpreter in Ghostscript 9.18 and 9.20 allows remote attackers to execute arbitrary code via crafted userparams.

Mitigation only
Fix from $1,950 2017-08-07
Linux HIGH 7.5
CVE-2015-7691EPSS 7%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) vi…

Mitigation only
Fix from $1,950 2017-08-07
Linux HIGH 7.5
CVE-2015-7692EPSS 7%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). …

Mitigation only
Fix from $1,950 2017-08-07
Linux MEDIUM 6.5
CVE-2015-7702EPSS 5%

The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). …

Mitigation only
Fix from $1,600 2017-08-07
Debian Linux HIGH 7.5
CVE-2015-7704EPSS 11%

The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" …

Mitigation only
Fix from $1,950 2017-08-07
Xenserver CRITICAL 9.8
CVE-2015-7705EPSS 12%

The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of …

Fix: 4.2.8 / 4.3.77+
Fix from $2,300 2017-08-07
Debian Linux MEDIUM 5.9
CVE-2015-7852EPSS 12%

ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response pa…

Patch available
Fix from $1,600 2017-08-07
Debian Linux MEDIUM 6.5
CVE-2015-7855EPSS 31%

The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertio…

Fix: 4.2.8 / 4.3.77+
Fix from $1,600 2017-08-07
Zend Framework CRITICAL 9.1
CVE-2015-1555

Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using s…

Mitigation only
Fix from $2,300 2017-08-07
Commons Email HIGH 7.5
CVE-2017-9801EPSS 6%

When a call-site passes a subject for an email that contains line-breaks in Apache Commons Email 1.0 through 1.4, the caller can add arbitrary SMTP h…

Mitigation only
Fix from $1,950 2017-08-07
Prime Collaboration Provisioning MEDIUM 6.5
CVE-2017-6759

A vulnerability in the UpgradeManager of the Cisco Prime Collaboration Provisioning Tool 12.1 could allow an authenticated, remote attacker to write …

Mitigation only
Fix from $1,600 2017-08-07
Meeting Server HIGH 7.5
CVE-2017-6763

A vulnerability in the implementation of the H.264 protocol in Cisco Meeting Server (CMS) 2.1.4 could allow an unauthenticated, remote attacker to ca…

Mitigation only
Fix from $1,950 2017-08-07