Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Libtiff HIGH 7.8
CVE-2017-7597

tif_dirread.c in LibTIFF 4.0.7 has an "outside the range of representable values of type float" undefined behavior issue, which might allow remote at…

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7599

LibTIFF 4.0.7 has an "outside the range of representable values of type short" undefined behavior issue, which might allow remote attackers to cause …

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7600

LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers t…

Patch available
Fix from $1,950 2017-04-09
Libtiff HIGH 7.8
CVE-2017-7601

LibTIFF 4.0.7 has a "shift exponent too large for 64-bit type long" undefined behavior issue, which might allow remote attackers to cause a denial of…

Patch available
Fix from $1,950 2017-04-09
Libaacplus HIGH 7.8
CVE-2017-7604

au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial …

No fix yet
Fix from $1,950 2017-04-09
Imagemagick MEDIUM 6.5
CVE-2017-7606

coders/rle.c in ImageMagick 7.0.5-4 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might al…

Patch available
Fix from $1,600 2017-04-09
Elfutils MEDIUM 5.5
CVE-2017-7609

elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory co…

Patch available
Fix from $1,600 2017-04-09
Debian Linux MEDIUM 5.5
CVE-2017-7613

elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of s…

Patch available
Fix from $1,600 2017-04-09
Registered Envelope Service MEDIUM 6.1
CVE-2017-3889

A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a…

Mitigation only
Fix from $1,600 2017-04-07
Wireless Lan Controller Firmware HIGH 7.5
CVE-2016-9219

A vulnerability with IPv6 UDP ingress packet processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,950 2017-04-06
Openflow HIGH 7.5
CVE-2015-1611

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to "fake LL…

Patch available
Fix from $1,950 2017-04-04
Openflow HIGH 7.5
CVE-2015-1612

OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reus…

Patch available
Fix from $1,950 2017-04-04
Safari HIGH 7.5
CVE-2016-10222

runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial…

Mitigation only
Fix from $1,950 2017-04-03
Ruby HIGH 7.5
CVE-2017-6181

The parse_char_class function in regparse.c in the Onigmo (aka Oniguruma-mod) regular expression library, as used in Ruby 2.4.0, allows remote attack…

Mitigation only
Fix from $1,950 2017-04-03
Anyoffice MEDIUM 6.5
CVE-2016-8275

Huawei AnyOffice V200R006C00 could allow an authenticated, remote attacker to cause the software to deny services by uploading an XML bomb.

Mitigation only
Fix from $1,600 2017-04-02
Mate 8 Firmware MEDIUM 5.5
CVE-2016-8756

ION memory management module in Huawei Mate 8 phones with software NXT-AL10C00B197 and earlier versions, NXT-DL10C00B197 and earlier versions, NXT-TL…

Mitigation only
Fix from $1,600 2017-04-02
Mate 8 Firmware MEDIUM 5.5
CVE-2016-8758

ION memory management module in Huawei Mate8 phones with software NXT-AL10C00B561 and earlier versions, NXT-CL10C00B561 and earlier versions, NXT-DL1…

Mitigation only
Fix from $1,600 2017-04-02
P9 Firmware MEDIUM 5.0
CVE-2016-8762

The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier ve…

Mitigation only
Fix from $1,600 2017-04-02
P9 Firmware MEDIUM 6.4
CVE-2016-8764

The TrustZone driver in Huawei P9 phones with software Versions earlier than EVA-AL10C00B352 and P9 Lite with software VNS-L21C185B130 and earlier ve…

Mitigation only
Fix from $1,600 2017-04-02
S12700 Firmware HIGH 7.5
CVE-2016-8773

Huawei S5300 with software V200R003C00, V200R007C00, V200R008C00, V200R009C00; S5700 with software V200R001C00, V200R002C00, V200R003C00, V200R005C00…

Mitigation only
Fix from $1,950 2017-04-02
Usg9520 Firmware HIGH 7.5
CVE-2016-8796

Huawei USG9520 V300R001C01, USG9560 V300R001C01, and USG9580 V300R001C01 allow unauthenticated attackers to send abnormal DHCP request packets to the…

Mitigation only
Fix from $1,950 2017-04-02
Ac6605 Firmware HIGH 7.5
CVE-2014-8572

Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300…

Mitigation only
Fix from $1,950 2017-04-02
Fusionaccess HIGH 7.5
CVE-2015-7844

Huawei FusionAccess with software V100R005C10,V100R005C20 could allow attackers to craft and send a malformed HDP protocol packet to cause the virtua…

Mitigation only
Fix from $1,950 2017-04-02
E3272s Firmware MEDIUM 5.5
CVE-2015-7847

Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 has a Denial of Service (DoS) …

Mitigation only
Fix from $1,600 2017-04-02
Logcenter MEDIUM 6.5
CVE-2015-8670

Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collection module, causing denial of…

Mitigation only
Fix from $1,600 2017-04-02
Hisuite HIGH 7.8
CVE-2016-8273

Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the soft…

Mitigation only
Fix from $1,950 2017-04-02
Mac Os X MEDIUM 5.5
CVE-2017-6974

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the system-installation subsystem of the "Sys…

Mitigation only
Fix from $1,600 2017-04-02
Safari MEDIUM 6.5
CVE-2017-2479EPSS 6%

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affec…

Fix: 6.2 / 10.1+
Fix from $1,600 2017-04-02
Iphone Os CRITICAL 9.8
CVE-2017-2434

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "HomeKit" component. It allows attackers to ha…

Fix: after 10.2.1
Fix from $2,300 2017-04-02
Safari MEDIUM 6.5
CVE-2017-2442EPSS 6%

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "WebKit JavaSc…

Fix: after 10.2.1
Fix from $1,600 2017-04-02