Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Umbraco Cms CRITICAL 9.8
CVE-2012-1301

The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter.

Mitigation only
Fix from $2,300 2017-04-13
Squashfs HIGH 7.5
CVE-2015-4646EPSS 7%

(1) unsquash-1.c, (2) unsquash-2.c, (3) unsquash-3.c, and (4) unsquash-4.c in Squashfs and sasquatch allow remote attackers to cause a denial of serv…

Fix: after 4.3
Fix from $1,950 2017-04-13
Novabackup Datacenter CRITICAL 9.8
CVE-2016-4898EPSS 5%

The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified att…

Mitigation only
Fix from $2,300 2017-04-13
Novabackup Datacenter CRITICAL 9.8
CVE-2016-4899EPSS 5%

The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified att…

Mitigation only
Fix from $2,300 2017-04-13
Mac Os X HIGH 7.8
CVE-2010-1821

Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.

Mitigation only
Fix from $1,950 2017-04-13
P7 Firmware MEDIUM 5.5
CVE-2015-7740

Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service …

Mitigation only
Fix from $1,600 2017-04-13
Wireshark HIGH 7.5
CVE-2017-7747

In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the PacketBB dissector could crash, triggered by packet injection or a malformed capture file. This …

Patch available
Fix from $1,950 2017-04-12
Enterprise Backup CRITICAL 9.8
CVE-2017-7280

An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sen…

Fix: after 8.2.0-8
Fix from $2,300 2017-04-12
Mod Auth Openidc HIGH 7.5
CVE-2017-6059EPSS 5%

Mod_auth_openidc.c in the Ping Identity OpenID Connect authentication module for Apache (aka mod_auth_openidc) before 2.14 allows remote attackers to…

Fix: 2.1.4+
Fix from $1,950 2017-04-12
Onenote HIGH 7.8
CVE-2017-0197EPSS 18%

Microsoft OneNote 2007 SP3 and Microsoft OneNote 2010 SP2 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Off…

Patch available
Fix from $1,950 2017-04-12
Campaign CRITICAL 9.1
CVE-2017-2989

Adobe Campaign versions Build 8770 and earlier have an input validation bypass that could be exploited to read, write, or delete data from the Campai…

Fix: after 6.11
Fix from $2,300 2017-04-12
Windows 10 HIGH 7.6
CVE-2017-0162

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Win…

Patch available
Fix from $1,950 2017-04-12
Windows 10 HIGH 7.6
CVE-2017-0163

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an au…

Patch available
Fix from $1,950 2017-04-12
Windows 10 MEDIUM 5.4
CVE-2017-0178

A denial of service vulnerability exists when Microsoft Hyper-V running on Windows 10, Windows 10 1511, Windows 10 1607, Windows 8.1, Windows Server …

Patch available
Fix from $1,600 2017-04-12
Windows 10 MEDIUM 5.8
CVE-2017-0179

A denial of service vulnerability exists when Microsoft Hyper-V running on a Windows 10, Windows 8.1, Windows Server 2012 R2, or Windows Server 2016 …

Patch available
Fix from $1,600 2017-04-12
Windows 10 HIGH 7.6
CVE-2017-0180

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a host server fails to properly validate input from an au…

Patch available
Fix from $1,950 2017-04-12
Windows 10 HIGH 7.6
CVE-2017-0181

A remote code execution vulnerability exists when Windows Hyper-V Network Switch running on a Windows 10 or Windows Server 2016 host server fails to …

Patch available
Fix from $1,950 2017-04-12
Windows 10 MEDIUM 5.8
CVE-2017-0182

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows …

Patch available
Fix from $1,600 2017-04-12
Windows 10 MEDIUM 5.8
CVE-2017-0183

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows Server 2008 R2, Windows 8.1, Windows …

Patch available
Fix from $1,600 2017-04-12
Windows 10 MEDIUM 5.4
CVE-2017-0184

A denial of service vulnerability exists when Microsoft Hyper-V running on a host server fails to properly validate input from a privileged user on a…

Patch available
Fix from $1,600 2017-04-12
Windows 10 MEDIUM 5.8
CVE-2017-0185EPSS 6%

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Ser…

Patch available
Fix from $1,600 2017-04-12
Windows 10 MEDIUM 5.8
CVE-2017-0186

A denial of service vulnerability exists when Microsoft Hyper-V Network Switch running on a Windows 10, Windows 8.1, Windows Server 2012, Windows Ser…

Patch available
Fix from $1,600 2017-04-12
Wireshark HIGH 7.5
CVE-2016-7957

In Wireshark 2.2.0, the Bluetooth L2CAP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/…

Patch available
Fix from $1,950 2017-04-12
Wireshark HIGH 7.5
CVE-2016-7958

In Wireshark 2.2.0, the NCP dissector could crash, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/C…

Patch available
Fix from $1,950 2017-04-12
Galaxy S6 HIGH 8.8
CVE-2015-7893EPSS 7%

SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.

No fix yet
Fix from $1,950 2017-04-11
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2016-7467

The TMM SSO plugin in F5 BIG-IP APM 12.0.0 - 12.1.1, 11.6.0 - 11.6.1 HF1, 11.5.4 - 11.5.4 HF2, when configured as a SAML Identity Provider with a Ser…

Mitigation only
Fix from $1,600 2017-04-11
Botan CRITICAL 9.8
CVE-2016-6878

The Curve25519 code in botan before 1.11.31, on systems without a native 128-bit integer type, might allow attackers to have unspecified impact via v…

Fix: after 1.11.30
Fix from $2,300 2017-04-10
Opencv MEDIUM 5.5
CVE-2016-1517

OpenCV 3.0.0 allows remote attackers to cause a denial of service (segfault) via vectors involving corrupt chunks.

Patch available
Fix from $1,600 2017-04-10
Libtiff HIGH 7.8
CVE-2017-7592

The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a…

Mitigation only
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7596

LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote attackers to cause …

Patch available
Fix from $1,950 2017-04-09