Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cf Release CRITICAL 9.8
CVE-2016-8218

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validati…

Fix: after 203
Fix from $2,300 2017-06-13
Cloud Foundry Elastic Runtime CRITICAL 9.8
CVE-2017-2773

An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23…

Mitigation only
Fix from $2,300 2017-06-13
Cloud Foundry Uaa Bosh HIGH 7.5
CVE-2017-4994

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions pr…

Fix: after 262
Fix from $1,950 2017-06-13
Ip Phone 8800 Series MEDIUM 5.9
CVE-2017-6656

A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,600 2017-06-13
Appgoat HIGH 8.8
CVE-2017-2179

Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a differe…

Fix: after 3.0.2
Fix from $1,950 2017-06-09
Wnc01wh Firmware MEDIUM 6.5
CVE-2016-7821

Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen v…

Fix: after 1.0.0.8
Fix from $1,600 2017-06-09
Socat HIGH 7.5
CVE-2015-1379

The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash).

Fix: after 1.7.2.4
Fix from $1,950 2017-06-08
S2300 Firmware HIGH 7.5
CVE-2015-3913

The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request …

Mitigation only
Fix from $1,950 2017-06-08
Ansible HIGH 8.8
CVE-2014-3498

The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.

Fix: after 1.6.5
Fix from $1,950 2017-06-08
Debian Linux HIGH 7.5
CVE-2017-9022

The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause …

Fix: after 5.5.2
Fix from $1,950 2017-06-08
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2017-6638

A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to …

Fix: after 4.4.00243
Fix from $1,950 2017-06-08
Cxf Fediz HIGH 7.5
CVE-2015-5175EPSS 9%

Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service.

Fix: after 1.1.2
Fix from $1,950 2017-06-07
Libdwarf MEDIUM 6.5
CVE-2015-8538

dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV).

Fix: after 2015-11-14
Fix from $1,600 2017-06-07
Domino CRITICAL 9.8
CVE-2016-6087

IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange v…

Patch available
Fix from $2,300 2017-06-07
Maximo Asset Management HIGH 8.8
CVE-2016-9977

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existi…

Patch available
Fix from $1,950 2017-06-07
Trusted Firmware A HIGH 7.5
CVE-2017-7564

In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secu…

Fix: after 1.3
Fix from $1,950 2017-06-07
Android MEDIUM 6.5
CVE-2015-3830

The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a vi…

No fix yet
Fix from $1,600 2017-06-06
Sudo HIGH 8.2
CVE-2017-1000368

Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function result…

Fix: after 1.8.20
Fix from $1,950 2017-06-05
Hadoop HIGH 7.5
CVE-2017-7669

In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W…

Mitigation only
Fix from $1,950 2017-06-05
Wireshark HIGH 7.5
CVE-2017-9350

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Wireshark HIGH 7.5
CVE-2017-9353EPSS 11%

In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address.

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Wireshark HIGH 7.5
CVE-2017-9354

In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an…

Fix: after 2.2.6
Fix from $1,950 2017-06-02
Chicken HIGH 7.5
CVE-2017-9334

An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, wh…

Fix: after 4.12.0
Fix from $1,950 2017-06-01
Horizon Daas MEDIUM 5.5
CVE-2017-4897

VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by t…

Fix: after 6.1.6
Fix from $1,600 2017-05-31
Laravel MEDIUM 6.1
CVE-2017-9303

Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to condu…

Mitigation only
Fix from $1,600 2017-05-29
Openvswitch MEDIUM 6.5
CVE-2017-9263

In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons…

Patch available
Fix from $1,600 2017-05-29
Linux Kernel MEDIUM 5.5
CVE-2017-9242

The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb dat…

Fix: after 4.11.3
Fix from $1,600 2017-05-27
Fortiwlc Sd HIGH 7.2
CVE-2017-3134

An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'co…

Fix: after 8.2.4
Fix from $1,950 2017-05-27
Serverprotect CRITICAL 9.8
CVE-2017-9034EPSS 6%

Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root…

Patch available
Fix from $2,300 2017-05-26
Cf Release MEDIUM 6.5
CVE-2016-2165

The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior …

Fix: after 231
Fix from $1,600 2017-05-25