Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Officescan CRITICAL 9.8
CVE-2017-11393EPSS 15%

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable instal…

Patch available
Fix from $2,300 2017-08-03
Officescan CRITICAL 9.8
CVE-2017-11394EPSS 62%

Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable instal…

Patch available
Fix from $2,300 2017-08-03
Pan Os CRITICAL 9.8
CVE-2017-8390EPSS 5%

The DNS Proxy in Palo Alto Networks PAN-OS before 6.1.18, 7.x before 7.0.16, 7.1.x before 7.1.11, and 8.x before 8.0.3 allows remote attackers to exe…

Fix: after 6.1.17
Fix from $2,300 2017-08-02
Libquicktime MEDIUM 6.5
CVE-2017-12143

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_info in lqt_quicktime.c, which allows attackers to cause a deni…

Patch available
Fix from $1,600 2017-08-02
Libquicktime MEDIUM 6.5
CVE-2017-12145

In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of ser…

Patch available
Fix from $1,600 2017-08-02
Outlook HIGH 7.8
CVE-2017-8571EPSS 5%

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, and Outlook 2016 as packaged in Microsoft Office allows a securi…

Patch available
Fix from $1,950 2017-08-01
Infosphere Master Data Management Server MEDIUM 6.5
CVE-2016-9717

HTTP Parameter Override is identified in the IBM Infosphere Master Data Management (MDM) 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 product. It enables a…

Patch available
Fix from $1,600 2017-07-31
Infosphere Master Data Management Server MEDIUM 5.7
CVE-2016-9719

IBM InfoSphere Master Data Management Server 10.1. 11.0. 11.3, 11.4, 11.5, and 11.6 could allow a remote attacker to hijack the clicking action of th…

Patch available
Fix from $1,600 2017-07-31
I HIGH 7.5
CVE-2017-1460

IBM i OSPF 6.1, 7.1, 7.2, and 7.3 is vulnerable when a rogue router spoofs its origin. Routing tables are affected by a missing LSA, which may lead t…

Mitigation only
Fix from $1,950 2017-07-31
Mx011anm Firmware MEDIUM 6.8
CVE-2017-9497

The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitr…

Mitigation only
Fix from $1,600 2017-07-31
Gpu Driver HIGH 7.8
CVE-2017-6254

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a pointer passed f…

Mitigation only
Fix from $1,950 2017-07-28
Gpu Driver HIGH 7.8
CVE-2017-6255

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where an improper input …

Mitigation only
Fix from $1,950 2017-07-28
Gpu Driver HIGH 7.8
CVE-2017-6256

NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a value passed fro…

Mitigation only
Fix from $1,950 2017-07-28
HTTP Server HIGH 7.5
CVE-2016-2161EPSS 20%

In Apache HTTP Server versions 2.4.0 to 2.4.23, malicious input to mod_auth_digest can cause the server to crash, and each instance continues to cras…

Mitigation only
Fix from $1,950 2017-07-27
Ffmpeg HIGH 7.5
CVE-2017-11665

The ff_amf_get_field_value function in libavformat/rtmppkt.c in FFmpeg 3.3.2 allows remote RTMP servers to cause a denial of service (Segmentation Vi…

Patch available
Fix from $1,950 2017-07-27
Web Vulnerability Scanner CRITICAL 9.8
CVE-2017-11673

Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a malformed PRE fil…

No fix yet
Fix from $2,300 2017-07-27
Libtiff MEDIUM 6.5
CVE-2017-11613

In LibTIFF 4.0.8, there is a denial of service vulnerability in the TIFFOpen function. A crafted input will lead to a denial of service attack. Durin…

Mitigation only
Fix from $1,600 2017-07-26
Graphicsmagick HIGH 8.8
CVE-2017-11638

GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a differe…

Mitigation only
Fix from $1,950 2017-07-26
Web Security Appliance HIGH 7.2
CVE-2017-6746

A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform command injec…

Mitigation only
Fix from $1,950 2017-07-25
Web Security Appliance HIGH 7.5
CVE-2017-6751

A vulnerability in the web proxy functionality of the Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to forward t…

Mitigation only
Fix from $1,950 2017-07-25
Nss Compat Ossl CRITICAL 9.8
CVE-2015-3278

The cipherstring parsing code in nss_compat_ossl while in multi-keyword mode does not match the expected set of ciphers for a given cipher combinatio…

Mitigation only
Fix from $2,300 2017-07-25
Xz HIGH 7.8
CVE-2015-4035

scripts/xzgrep.in in xzgrep 5.2.x before 5.2.0, before 5.0.0 does not properly process file names containing semicolons, which allows remote attacker…

Fix: after 4.999.9
Fix from $1,950 2017-07-25
Intense Pc Firmware MEDIUM 6.7
CVE-2017-9457

Intense PC Phoenix SecureCore UEFI firmware does not perform capsule signature validation before upgrading the system firmware. The absence of signat…

No fix yet
Fix from $1,600 2017-07-25
Linux HIGH 7.5
CVE-2015-7703

The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configurat…

Mitigation only
Fix from $1,950 2017-07-24
Libsass HIGH 7.5
CVE-2017-11555

There is an illegal address access in the Eval::operator function in eval.cpp in LibSass 3.4.5. A crafted input will lead to a remote denial of servi…

No fix yet
Fix from $1,950 2017-07-23
Exiv2 HIGH 7.5
CVE-2017-11553

There is an illegal address access in the extend_alias_table function in localealias.c of Exiv2 0.26. A crafted input will lead to remote denial of s…

No fix yet
Fix from $1,950 2017-07-23
Security Guardium HIGH 7.5
CVE-2017-1267

IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the…

Patch available
Fix from $1,950 2017-07-21
Phpmybackuppro HIGH 8.8
CVE-2015-3639

phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by sto…

Fix: after 2.5
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2015-5194EPSS 5%

The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via …

Patch available
Fix from $1,950 2017-07-21
Fedora HIGH 7.5
CVE-2015-5195EPSS 7%

ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or …

Fix: after 4.2.7
Fix from $1,950 2017-07-21