Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Linux Kernel HIGH 7.0
CVE-2017-0613

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t…

Patch available
Fix from $1,950 2017-05-12
Linux Kernel HIGH 7.0
CVE-2017-0620

An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary…

Fix: after 7.1.2
Fix from $1,950 2017-05-12
Windows 10 MEDIUM 5.9
CVE-2017-0280EPSS 8%

The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows…

Patch available
Fix from $1,600 2017-05-12
Windows 10 MEDIUM 5.9
CVE-2017-0269EPSS 7%

The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows…

Patch available
Fix from $1,600 2017-05-12
Windows 10 MEDIUM 5.9
CVE-2017-0273EPSS 7%

The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows…

Patch available
Fix from $1,600 2017-05-12
Asp.net Model View Controller HIGH 7.3
CVE-2017-0249EPSS 8%

An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

No fix yet
Fix from $1,950 2017-05-12
Asp.net Model View Controller MEDIUM 5.3
CVE-2017-0256EPSS 5%

A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.

Mitigation only
Fix from $1,600 2017-05-12
Asp.net Model View Controller HIGH 7.5
CVE-2017-0247EPSS 17%

A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-pa…

Patch available
Fix from $1,950 2017-05-12
Windows Server 2008 MEDIUM 5.9
CVE-2017-0171

Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and W…

Patch available
Fix from $1,600 2017-05-12
Windows 10 HIGH 7.6
CVE-2017-0212

Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to …

Patch available
Fix from $1,950 2017-05-12
Oxygenos MEDIUM 5.9
CVE-2017-5948

An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenien…

No fix yet
Fix from $1,600 2017-05-11
Big Ip Websafe HIGH 7.5
CVE-2016-7476

The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, …

Mitigation only
Fix from $1,950 2017-05-11
Pcs 7 MEDIUM 6.5
CVE-2017-6865

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET…

Mitigation only
Fix from $1,600 2017-05-11
Libtiff MEDIUM 5.5
CVE-2016-10371

The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion …

Mitigation only
Fix from $1,600 2017-05-10
Gpu Driver HIGH 7.8
CVE-2017-0346

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where…

Mitigation only
Fix from $1,950 2017-05-09
Gpu Driver HIGH 7.8
CVE-2017-0350

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver…

Mitigation only
Fix from $1,950 2017-05-09
Gpu Driver MEDIUM 5.5
CVE-2017-0353

All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking…

Mitigation only
Fix from $1,600 2017-05-09
Gpu Driver MEDIUM 5.5
CVE-2017-0355

All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access …

Mitigation only
Fix from $1,600 2017-05-09
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-9253

In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the w…

Mitigation only
Fix from $1,950 2017-05-09
Xenmobile Server MEDIUM 5.3
CVE-2016-6877

Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host head…

Fix: after 10.3.6.310
Fix from $1,600 2017-05-05
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9692

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-suppli…

Patch available
Fix from $1,950 2017-05-05
OpenSSL HIGH 7.5
CVE-2017-3733EPSS 7%

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this…

Patch available
Fix from $1,950 2017-05-04
Small Business Rv Series Router Firmware MEDIUM 5.8
CVE-2017-6620

A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated,…

Mitigation only
Fix from $1,600 2017-05-03
Imanager MEDIUM 5.3
CVE-2017-7428

NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.

No fix yet
Fix from $1,600 2017-05-03
Debian Linux CRITICAL 9.8
CVE-2016-10243EPSS 6%

TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.

Patch available
Fix from $2,300 2017-05-02
Pexip Infinity CRITICAL 9.8
CVE-2017-6551

Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co…

Fix: after 14.1
Fix from $2,300 2017-05-02
Binutils HIGH 7.5
CVE-2017-8396

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the ex…

Patch available
Fix from $1,950 2017-05-01
Irfanview HIGH 7.8
CVE-2017-7721

IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.

Fix: after 4.44
Fix from $1,950 2017-04-30
Fuse HIGH 7.5
CVE-2017-7957

XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during…

Fix: after 1.4.9
Fix from $1,950 2017-04-29
X86 Fuji Firmware HIGH 7.5
CVE-2017-2153

SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause…

Mitigation only
Fix from $1,950 2017-04-28