Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Request Tracker HIGH 8.8
CVE-2017-5944

The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authen…

Mitigation only
Fix from $1,950 2017-07-03
Mcollective Sshkey Security MEDIUM 6.5
CVE-2017-2298

The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compro…

Fix: after 0.5.0
Fix from $1,600 2017-06-30
Antivirus Engine MEDIUM 5.5
CVE-2017-10674

Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call.

Mitigation only
Fix from $1,600 2017-06-30
Libtiff HIGH 7.5
CVE-2017-10688EPSS 6%

In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a…

No fix yet
Fix from $1,950 2017-06-29
Emc Vasa Provider Virtual Appliance CRITICAL 9.8
CVE-2017-4997

EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exp…

Fix: after 8.3.0
Fix from $2,300 2017-06-29
Defense4all HIGH 8.8
CVE-2014-8149

OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files.

Fix: after 1.1.0
Fix from $1,950 2017-06-27
P7 L09 Firmware HIGH 7.5
CVE-2015-2245

Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash).

No fix yet
Fix from $1,950 2017-06-27
Teamspeak Client HIGH 7.5
CVE-2017-9982

TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the &#…

No fix yet
Fix from $1,950 2017-06-27
Openvpn MEDIUM 6.5
CVE-2017-7522EPSS 5%

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with a…

Fix: after 2.3.16
Fix from $1,600 2017-06-27
Virtio Win HIGH 7.5
CVE-2015-3215

The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de…

Patch available
Fix from $1,950 2017-06-26
Evolved Programmable Network Manager HIGH 8.0
CVE-2017-6662

A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an aut…

Mitigation only
Fix from $1,950 2017-06-26
Horde Image MEDIUM 5.7
CVE-2017-9773

Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver.

No fix yet
Fix from $1,600 2017-06-21
Gdb MEDIUM 5.5
CVE-2017-9778

GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file ca…

Fix: after 8.0
Fix from $1,600 2017-06-21
Captivate CRITICAL 9.8
CVE-2017-3098EPSS 6%

Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and writ…

Fix: after 9.0
Fix from $2,300 2017-06-20
Projectsend CRITICAL 9.8
CVE-2017-9741

install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TA…

No fix yet
Fix from $2,300 2017-06-18
Thrift MEDIUM 6.5
CVE-2015-3254

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vecto…

Fix: after 0.9.2
Fix from $1,600 2017-06-16
Dir 605l Firmware HIGH 7.5
CVE-2017-9675EPSS 9%

On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.

No fix yet
Fix from $1,950 2017-06-15
Outlook MEDIUM 6.5
CVE-2017-8545

A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerabil…

Patch available
Fix from $1,600 2017-06-15
Ranger CRITICAL 9.8
CVE-2017-7676

Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u…

Fix: after 0.7.0
Fix from $2,300 2017-06-14
Android MEDIUM 5.5
CVE-2016-10337

In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed.

No fix yet
Fix from $1,600 2017-06-13
Android HIGH 7.8
CVE-2016-10338

In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.

No fix yet
Fix from $1,950 2017-06-13
Android MEDIUM 5.5
CVE-2017-7366

In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.

Patch available
Fix from $1,600 2017-06-13
Android HIGH 7.8
CVE-2017-7369

In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel s…

Patch available
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2014-9962

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command.

No fix yet
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2014-9965

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call.

No fix yet
Fix from $1,950 2017-06-13
Android HIGH 7.8
CVE-2015-9033

In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer.

Mitigation only
Fix from $1,950 2017-06-13
Context Service Development Kit CRITICAL 9.8
CVE-2017-6667

A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthentic…

Mitigation only
Fix from $2,300 2017-06-13
Email Security Appliance Firmware HIGH 7.5
CVE-2017-6671

A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2017-06-13
Firesight System HIGH 7.5
CVE-2017-6674

A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to…

Mitigation only
Fix from $1,950 2017-06-13
Ultra Services Framework HIGH 7.5
CVE-2017-6680

A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary…

Mitigation only
Fix from $1,950 2017-06-13