Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Libplist MEDIUM 5.0
CVE-2017-6440

The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) …

No fix yet
Fix from $1,600 2017-03-15
Libplist MEDIUM 5.0
CVE-2017-6436

The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error…

Patch available
Fix from $1,600 2017-03-15
Sysinfo MEDIUM 6.7
CVE-2017-6516EPSS 5%

A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow a local attacker to gain ele…

Fix: after 10-h62
Fix from $1,600 2017-03-14
Ftp Server HIGH 7.5
CVE-2017-6367EPSS 7%

In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and a…

No fix yet
Fix from $1,950 2017-03-14
Busybox MEDIUM 5.5
CVE-2014-9645

The add_probe function in modutils/modprobe.c in BusyBox before 1.23.0 allows local users to bypass intended restrictions on loading kernel modules v…

Fix: after 1.22.1
Fix from $1,600 2017-03-12
WordPress MEDIUM 6.1
CVE-2017-6815

In WordPress before 4.7.3 (wp-includes/pluggable.php), control characters can trick redirect URL validation.

Fix: after 4.7.2
Fix from $1,600 2017-03-12
Software Updater HIGH 8.1
CVE-2017-6466

F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform fil…

Mitigation only
Fix from $1,950 2017-03-11
Clearpath Mcp HIGH 7.5
CVE-2017-5872

The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when runni…

Mitigation only
Fix from $1,950 2017-03-10
Android MEDIUM 5.5
CVE-2017-0499

A denial of service vulnerability in Audioserver could enable a local malicious application to cause a device hang or reboot. This issue is rated as …

Mitigation only
Fix from $1,600 2017-03-08
Android HIGH 7.8
CVE-2017-0475

An elevation of privilege vulnerability in the recovery verifier could enable a local malicious application to execute arbitrary code within the cont…

Mitigation only
Fix from $1,950 2017-03-08
Android MEDIUM 5.5
CVE-2017-0483

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu…

Mitigation only
Fix from $1,600 2017-03-08
Android MEDIUM 5.5
CVE-2017-0484

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu…

Mitigation only
Fix from $1,600 2017-03-08
Android MEDIUM 5.5
CVE-2017-0488

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu…

Mitigation only
Fix from $1,600 2017-03-08
Linux Kernel HIGH 7.0
CVE-2017-0458

An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the…

Patch available
Fix from $1,950 2017-03-08
Linux Kernel HIGH 7.0
CVE-2017-0463

An elevation of privilege vulnerability in the Qualcomm networking driver could enable a local malicious application to execute arbitrary code within…

Patch available
Fix from $1,950 2017-03-08
Business Process Manager MEDIUM 6.1
CVE-2016-9693

IBM Business Process Manager 7.5, 8.0, and 8.5 has a file download capability that is vulnerable to a set of attacks. Ultimately, an attacker can cau…

Patch available
Fix from $1,600 2017-03-07
Qradar Incident Forensics HIGH 8.8
CVE-2016-9726

IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-cra…

Patch available
Fix from $1,950 2017-03-07
Qradar Incident Forensics HIGH 8.5
CVE-2016-9727

IBM QRadar 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an at…

Patch available
Fix from $1,950 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6239

The mmap extension __MAP_NOFAULT in OpenBSD 5.8 and 5.9 allows attackers to cause a denial of service (kernel panic and crash) via a large size value.

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6243

thrsleep in kern/kern_synch.c in OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (kernel panic) via a crafted value in the tsp pa…

No fix yet
Fix from $1,600 2017-03-07
OpenBSD MEDIUM 5.5
CVE-2016-6247

OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_v…

No fix yet
Fix from $1,600 2017-03-07
OpenBSD HIGH 7.5
CVE-2016-6244

The sys_thrsigdivert function in kern/kern_sig.c in the OpenBSD kernel 5.9 allows remote attackers to cause a denial of service (panic) via a negativ…

No fix yet
Fix from $1,950 2017-03-07
Debian Linux MEDIUM 5.5
CVE-2017-6498

An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.

Patch available
Fix from $1,600 2017-03-06
Qbittorrent MEDIUM 6.1
CVE-2017-6504

WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.

Fix: after 3.3.10
Fix from $1,600 2017-03-06
Wireshark HIGH 7.5
CVE-2017-6468

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a NetScaler file parser crash, triggered by a malformed capture file. This was addressed in…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Wireshark HIGH 7.5
CVE-2017-6469

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is an LDSS dissector crash, triggered by packet injection or a malformed capture file. This wa…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Wireshark HIGH 7.5
CVE-2017-6471

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a WSP infinite loop, triggered by packet injection or a malformed capture file. This was ad…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Wireshark HIGH 7.5
CVE-2017-6473

In Wireshark 2.2.0 to 2.2.4 and 2.0.0 to 2.0.10, there is a K12 file parser crash, triggered by a malformed capture file. This was addressed in wiret…

Fix: after 2.2.4
Fix from $1,950 2017-03-04
Dropbear Ssh CRITICAL 9.8
CVE-2016-7406EPSS 10%

Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) …

Fix: after 2016.73
Fix from $2,300 2017-03-03
Dropbear Ssh CRITICAL 9.8
CVE-2016-7407

The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.

Fix: after 2016.73
Fix from $2,300 2017-03-03