Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
K2\(psg1218\) Firmware CRITICAL 9.8
CVE-2017-11495

PHICOMM K2(PSG1218) devices V22.5.11.5 and earlier allow unauthenticated remote code execution via a request to an unspecified ASP script; alternativ…

Fix: after 22.5.11.5
Fix from $2,300 2017-07-20
Safari MEDIUM 6.5
CVE-2017-7060

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "Safari Pr…

Fix: 10.1.2 / 10.3.3+
Fix from $1,600 2017-07-20
Safari MEDIUM 5.5
CVE-2017-7064EPSS 7%

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows is…

Fix: after 12.6.1
Fix from $1,600 2017-07-20
Mac Os X MEDIUM 5.5
CVE-2017-7045

An issue was discovered in certain Apple products. macOS before 10.12.6 is affected. The issue involves the "Intel Graphics Driver" component. It all…

Fix: after 10.12.5
Fix from $1,600 2017-07-20
Iphone Os MEDIUM 6.5
CVE-2017-2517

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. The issue involves the "Safari" component. It allows remote attacke…

Fix: after 10.3.2
Fix from $1,600 2017-07-20
Safari MEDIUM 6.5
CVE-2017-7011

An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. The issue involves the "WebKit" c…

Fix: after 10.3.2
Fix from $1,600 2017-07-20
Wireshark HIGH 7.5
CVE-2017-11407

In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the MQ dissector could crash. This was addressed in epan/dissectors/packet-mq.c by validating the fr…

Fix: after 2.2.7
Fix from $1,950 2017-07-18
Wireshark HIGH 7.5
CVE-2017-11408

In Wireshark 2.2.0 to 2.2.7 and 2.0.0 to 2.0.13, the AMQP dissector could crash. This was addressed in epan/dissectors/packet-amqp.c by checking for …

Patch available
Fix from $1,950 2017-07-18
Wireshark HIGH 7.5
CVE-2017-11410

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the WBXML dissector could go into an infinite loop, triggered by packet injection or a malformed…

Patch available
Fix from $1,950 2017-07-18
Wireshark HIGH 7.5
CVE-2017-11411

In Wireshark through 2.0.13 and 2.2.x through 2.2.7, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissec…

Patch available
Fix from $1,950 2017-07-18
Anti Virus For Linux Server CRITICAL 9.8
CVE-2017-9811EPSS 8%

The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 …

Fix: after 8.0.3.297
Fix from $2,300 2017-07-17
Rsa Identity Governance And Lifecycle HIGH 7.2
CVE-2017-8004

The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions …

Mitigation only
Fix from $1,950 2017-07-17
Junos CRITICAL 9.8
CVE-2017-2345

On Junos OS devices with SNMP enabled, a network based attacker with unfiltered access to the RE can cause the Junos OS snmpd daemon to crash and res…

Mitigation only
Fix from $2,300 2017-07-17
Junos HIGH 7.5
CVE-2017-2347

A denial of service vulnerability in rpd daemon of Juniper Networks Junos OS allows a malformed MPLS ping packet to crash the rpd daemon if MPLS OAM …

Mitigation only
Fix from $1,950 2017-07-17
Junos HIGH 7.5
CVE-2017-2314

Receipt of a malformed BGP OPEN message may cause the routing protocol daemon (rpd) process to crash and restart. By continuously sending specially c…

Mitigation only
Fix from $1,950 2017-07-17
Manageengine Desktop Central CRITICAL 9.8
CVE-2017-11346EPSS 37%

Zoho ManageEngine Desktop Central before build 100092 allows remote attackers to execute arbitrary code via vectors involving the upload of help desk…

Fix: after 10.0
Fix from $2,300 2017-07-17
Exiv2 MEDIUM 6.5
CVE-2017-11340

There is a Segmentation fault in the XmpParser::terminate() function in Exiv2 0.26, related to an exit call. A Crafted input will lead to a remote de…

Mitigation only
Fix from $1,600 2017-07-17
Libsass HIGH 7.5
CVE-2017-11342

There is an illegal address access in ast.cpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.

No fix yet
Fix from $1,950 2017-07-17
Junos HIGH 7.5
CVE-2017-10605

On all vSRX and SRX Series devices, when the DHCP or DHCP relay is configured, specially crafted packet might cause the flowd process to crash, halti…

Mitigation only
Fix from $1,950 2017-07-17
Framadate CRITICAL 9.8
CVE-2017-1000039

Framadate version 1.0 is vulnerable to Formula Injection in the CSV Export resulting possible Information Disclosure and Code Execution

Mitigation only
Fix from $2,300 2017-07-17
Qs HIGH 7.5
CVE-2017-1000048

the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil req…

Mitigation only
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000014

phpMyAdmin 4.0, 4.4, and 4.6 are vulnerable to a DOS weakness in the table editing functionality

Patch available
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000016

A weakness was discovered where an attacker can inject arbitrary values in to the browser cookies. This is a re-issue of an incomplete fix from PMASA…

Mitigation only
Fix from $1,950 2017-07-17
phpMyAdmin HIGH 7.5
CVE-2017-1000018

phpMyAdmin 4.0, 4.4., and 4.6 are vulnerable to a DOS attack in the replication status by using a specially crafted table name

Fix: 4.0.10.19 / 4.4.15.10+
Fix from $1,950 2017-07-17
Fedmsg HIGH 7.5
CVE-2017-1000001

FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.

Fix: after 0.18.1
Fix from $1,950 2017-07-17
HTTP Server CRITICAL 9.1
CVE-2017-9788EPSS 54%

In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or…

Fix: after 2.4.26
Fix from $2,300 2017-07-13
Struts MEDIUM 5.9
CVE-2017-7672EPSS 9%

If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used t…

Mitigation only
Fix from $1,600 2017-07-13
Websphere Mq MEDIUM 6.5
CVE-2017-1285

IBM WebSphere MQ 9.0.1 and 9.0.2 could allow an authenticated user with authority to send a specially crafted message that would cause a channel to r…

Patch available
Fix from $1,600 2017-07-12
Edge MEDIUM 6.5
CVE-2017-8599

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page wit…

Patch available
Fix from $1,600 2017-07-11
Edge MEDIUM 6.5
CVE-2017-8602

Microsoft browsers on Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1…

Patch available
Fix from $1,600 2017-07-11