Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Config Model HIGH 7.3
CVE-2017-0373

The gen_class_pod implementation in lib/Config/Model/Utils/GenClassPod.pm in Config-Model (aka libconfig-model-perl) before 2.102 has a dangerous "us…

Fix: after 2.101
Fix from $1,950 2017-05-23
Autotrace CRITICAL 9.8
CVE-2017-9188

libautotrace.a in AutoTrace 0.31.1 has a "left shift ... cannot be represented in type int" issue in input-bmp.c:516:63.

Mitigation only
Fix from $2,300 2017-05-23
Chrome CRITICAL 9.8
CVE-2016-5178

Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other…

Fix: after 53.0.2785.129
Fix from $2,300 2017-05-23
Teradata Express HIGH 7.5
CVE-2015-5401

Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote a…

Fix: after 15.00.02.08
Fix from $1,950 2017-05-23
Debian Linux MEDIUM 6.5
CVE-2017-9141

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c becau…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9142

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing check…

Patch available
Fix from $1,600 2017-05-22
Debian Linux MEDIUM 6.5
CVE-2017-9144

In ImageMagick 7.0.5-5, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c.

Patch available
Fix from $1,600 2017-05-22
Mac Os X MEDIUM 5.5
CVE-2017-2540

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "WindowServer" component. It allows attac…

Fix: after 10.12.4
Fix from $1,600 2017-05-22
Mac Os X HIGH 7.8
CVE-2017-2535

An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Security" component. It allows attackers…

Fix: after 10.12.4
Fix from $1,950 2017-05-22
Safari MEDIUM 6.5
CVE-2017-2495

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "Safari" c…

Fix: after 10.3.1
Fix from $1,600 2017-05-22
Safari MEDIUM 6.5
CVE-2017-2511

An issue was discovered in certain Apple products. Safari before 10.1.1 is affected. The issue involves the "Safari" component. It allows remote atta…

Fix: after 10.1
Fix from $1,600 2017-05-22
Prime Collaboration Provisioning MEDIUM 6.5
CVE-2017-6637

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote …

Mitigation only
Fix from $1,600 2017-05-22
Nx Os HIGH 7.8
CVE-2017-6649

A vulnerability in the CLI of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local …

Mitigation only
Fix from $1,950 2017-05-22
Nx Os HIGH 7.8
CVE-2017-6650

A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authen…

Mitigation only
Fix from $1,950 2017-05-22
Backhaul Radios HIGH 7.5
CVE-2017-9131

An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an acc…

Fix: after 2.2.1
Fix from $1,950 2017-05-21
Pegasus HIGH 7.3
CVE-2017-9046

winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For exampl…

No fix yet
Fix from $1,950 2017-05-21
Allen Disk HIGH 7.5
CVE-2017-9090

reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST[…

Patch available
Fix from $1,950 2017-05-19
Allen Disk HIGH 7.5
CVE-2017-9091

/admin/loginc.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code']) == 1, which leads to CAPTCHA bypass by emptying $_POST['capt…

Patch available
Fix from $1,950 2017-05-19
Telepresence Ix5000 HIGH 7.5
CVE-2017-6652

A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary file…

Mitigation only
Fix from $1,950 2017-05-18
WordPress HIGH 7.5
CVE-2017-9065

In WordPress before 4.7.5, there is a lack of capability checks for post meta data in the XML-RPC API.

Fix: after 4.7.4
Fix from $1,950 2017-05-18
Binutils HIGH 7.8
CVE-2017-9043

readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a den…

Patch available
Fix from $1,950 2017-05-18
B2j Contact CRITICAL 9.8
CVE-2017-5215

The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protect…

Fix: after 2.1.12
Fix from $2,300 2017-05-17
Debian Linux HIGH 7.8
CVE-2017-8849

smb4k before 2.0.1 allows local users to gain root privileges by leveraging failure to verify arguments to the mount helper DBUS service.

Fix: after 2.0.0
Fix from $1,950 2017-05-17
Telepresence Ce HIGH 7.5
CVE-2017-3825

A vulnerability in the ICMP ingress packet processing of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an unauthenticated, remo…

Mitigation only
Fix from $1,950 2017-05-16
Aironet Access Point Firmware HIGH 7.5
CVE-2017-3873

A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Poin…

Mitigation only
Fix from $1,950 2017-05-16
Android HIGH 7.8
CVE-2014-9933

Due to missing input validation in all Android releases from CAF using the Linux kernel, HLOS can write to fuses for which it should not have access.

Patch available
Fix from $1,950 2017-05-16
Openvpn HIGH 7.5
CVE-2017-7478EPSS 12%

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue…

No fix yet
Fix from $1,950 2017-05-15
Pcmanfm MEDIUM 5.5
CVE-2017-8934

PCManFM 1.2.5 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (application unavailability).

Mitigation only
Fix from $1,600 2017-05-15
Manageengine Desktop Central CRITICAL 10.0
CVE-2017-7213EPSS 8%

Zoho ManageEngine Desktop Central before build 100082 allows remote attackers to obtain control over all connected active desktops via unspecified ve…

Patch available
Fix from $2,300 2017-05-15
Money Forward For Apppass HIGH 7.8
CVE-2016-4838

The Android Apps Money Forward (prior to v7.18.0), Money Forward for The Gunma Bank (prior to v1.2.0), Money Forward for SHIGA BANK (prior to v1.2.0)…

Fix: 1.2.0 / 1.3.0+
Fix from $1,950 2017-05-12