Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Safari MEDIUM 6.5
CVE-2017-2453

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves the "Safari" compo…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Iphone Os HIGH 7.5
CVE-2017-2461

An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS before 10.2 is affected. watch…

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Mac Os X HIGH 7.8
CVE-2017-2410

An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.12.3
Fix from $1,950 2017-04-02
Iphone Os MEDIUM 5.3
CVE-2017-2414

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "DataAccess" component. It allows remote attac…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Safari HIGH 8.8
CVE-2017-2378

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. The issue involves bookmark creation …

Fix: after 10.2.1
Fix from $1,950 2017-04-02
Tigervnc HIGH 7.5
CVE-2017-7394

In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.

Patch available
Fix from $1,950 2017-04-01
Illumos HIGH 8.6
CVE-2016-6560

illumos osnet-incorporation bcopy() and bzero() implementations make signed instead of unsigned comparisons allowing a system crash.

Patch available
Fix from $1,950 2017-03-31
Linux Kernel MEDIUM 5.5
CVE-2017-7346

The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain leve…

Fix: after 4.10.7
Fix from $1,600 2017-03-30
Sentinel HIGH 7.5
CVE-2017-5185

A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.

Fix: 8.0.1+
Fix from $1,950 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9805

ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9806

ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9808

ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9809

ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9810

The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed d…

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9811

The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed x…

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9813

ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Imagemagick MEDIUM 5.5
CVE-2014-9815

ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted wpg file.

Fix: 6.9.4-0+
Fix from $1,600 2017-03-30
Bubblewrap CRITICAL 10.0
CVE-2017-5226

When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characte…

Fix: after 0.1.5
Fix from $2,300 2017-03-29
Binutils HIGH 7.5
CVE-2017-7301

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that…

Patch available
Fix from $1,950 2017-03-29
Ruby HIGH 7.3
CVE-2009-5147EPSS 10%

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

Patch available
Fix from $1,950 2017-03-29
Chicken HIGH 7.5
CVE-2015-4556

The string-translate* procedure in the data-structures unit in CHICKEN before 4.10.0 allows remote attackers to cause a denial of service (crash).

Fix: after 4.9.0
Fix from $1,950 2017-03-29
Ntp MEDIUM 6.5
CVE-2017-6463

NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote authenticated users to cause a denial of service (daemon crash) via an invalid setting in a…

Mitigation only
Fix from $1,600 2017-03-27
Ntp MEDIUM 6.5
CVE-2017-6464

NTP before 4.2.8p10 and 4.3.x before 4.3.94 allows remote attackers to cause a denial of service (ntpd crash) via a malformed mode configuration dire…

Patch available
Fix from $1,600 2017-03-27
Extraputty HIGH 7.5
CVE-2017-7183

The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP pr…

Fix: after 0.29
Fix from $1,950 2017-03-27
Bash HIGH 7.8
CVE-2017-5932

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character a…

Patch available
Fix from $1,950 2017-03-27
Ryzen MEDIUM 5.5
CVE-2017-7262

The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that…

Fix: after 2017-01-27
Fix from $1,600 2017-03-25
Linux Kernel MEDIUM 5.5
CVE-2017-7261

The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5 does not check for a zero value o…

Fix: after 4.10.5
Fix from $1,600 2017-03-24
Ar3200 Firmware CRITICAL 9.8
CVE-2016-6206

Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a craf…

Mitigation only
Fix from $2,300 2017-03-24
Mate S Firmware MEDIUM 5.5
CVE-2015-8678

The ION driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92B2…

Mitigation only
Fix from $1,600 2017-03-24
Jasper MEDIUM 5.5
CVE-2016-9390

The jas_seq2d_create function in jas_seq.c in JasPer before 1.900.14 allows remote attackers to cause a denial of service (assertion failure) via a c…

Fix: after 1.900.13
Fix from $1,600 2017-03-23