Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Imagemagick MEDIUM 5.5
CVE-2016-10068

The MSL interpreter in ImageMagick before 6.9.6-4 allows remote attackers to cause a denial of service (segmentation fault and application crash) via…

Fix: after 6.9.6-3
Fix from $1,600 2017-03-02
Imagemagick MEDIUM 5.5
CVE-2016-10069

coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid nu…

Fix: after 6.9.4-4
Fix from $1,600 2017-03-02
Glibc MEDIUM 5.9
CVE-2016-10228

The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSL…

Fix: after 2.25
Fix from $1,600 2017-03-02
Netflow Generation Appliance Software HIGH 7.5
CVE-2017-3826

A vulnerability in the Stream Control Transmission Protocol (SCTP) decoder of the Cisco NetFlow Generation Appliance (NGA) with software before 1.1(1…

Mitigation only
Fix from $1,950 2017-03-01
Debian Linux MEDIUM 5.5
CVE-2016-9830

The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in …

Patch available
Fix from $1,600 2017-03-01
Linux Kernel HIGH 7.8
CVE-2017-6345

The LLC subsystem in the Linux kernel before 4.9.13 does not ensure that a certain destructor exists in required circumstances, which allows local us…

Fix: after 4.9.12
Fix from $1,950 2017-03-01
Graphicsmagick MEDIUM 5.5
CVE-2016-5240

The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a…

Fix: after 1.3.23
Fix from $1,600 2017-02-27
Debian Linux MEDIUM 5.5
CVE-2017-6188

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting…

Fix: 2.0.30.1 / 2.999.9+
Fix from $1,600 2017-02-22
Documentum D2 CRITICAL 9.8
CVE-2017-5586EPSS 17%

OpenText Documentum D2 (formerly EMC Documentum D2) 4.x allows remote attackers to execute arbitrary commands via a crafted serialized Java object, r…

No fix yet
Fix from $2,300 2017-02-22
Web Security Appliance MEDIUM 5.8
CVE-2017-3827

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) and W…

Mitigation only
Fix from $1,600 2017-02-22
Meeting Server HIGH 7.5
CVE-2017-3830

A vulnerability in an internal API of the Cisco Meeting Server (CMS) could allow an unauthenticated, remote attacker to cause a denial of service (Do…

Mitigation only
Fix from $1,950 2017-02-22
Meeting Server HIGH 8.1
CVE-2017-3837

An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allo…

Mitigation only
Fix from $1,950 2017-02-22
Maxview MEDIUM 5.5
CVE-2017-6078

FastStone MaxView 3.0 and 3.1 allows user-assisted attackers to cause a denial of service (application crash) via a malformed BMP image with a crafte…

No fix yet
Fix from $1,600 2017-02-21
Iphone Os MEDIUM 5.5
CVE-2017-2368

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "Contacts" component. It allows remote attac…

Fix: after 10.2.0
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 6.5
CVE-2017-2371EPSS 6%

An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. The issue involves the "WebKit" component, which allows remote atta…

Fix: 10.2.1+
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 5.5
CVE-2016-7665

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remo…

Fix: after 10.1.1
Fix from $1,600 2017-02-20
Iphone Os HIGH 7.5
CVE-2016-7667

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The issue involves the "CoreText" c…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Mac Os X HIGH 7.8
CVE-2016-7742

An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "xar" component, which allows remote atta…

Fix: after 10.12.1
Fix from $1,950 2017-02-20
Iphone Os MEDIUM 5.9
CVE-2016-7636

An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchOS before 3.1.3 is affected. T…

Fix: after 10.12.1
Fix from $1,600 2017-02-20
Iphone Os MEDIUM 6.8
CVE-2016-4690

An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Image Capture" component, which allows attack…

Fix: after 10.1.1
Fix from $1,600 2017-02-20
Mac Os X MEDIUM 6.5
CVE-2016-7580

An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves the "Mail" component, which allows remote web s…

Fix: after 10.11.6
Fix from $1,600 2017-02-20
Mac Os X MEDIUM 5.5
CVE-2016-4661

An issue was discovered in certain Apple products. macOS before 10.12.1 is affected. The issue involves the "ntfs" component, which misparses disk im…

Fix: after 10.12.0
Fix from $1,600 2017-02-20
Iphone Os HIGH 7.8
CVE-2016-4669

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: 3.1 / 10.0.1+
Fix from $1,950 2017-02-20
Debian Linux MEDIUM 6.3
CVE-2016-9955

The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses o…

Fix: 1.14.11+
Fix from $1,600 2017-02-17
Dovecot MEDIUM 5.9
CVE-2016-8652EPSS 35%

The auth component in Dovecot before 2.2.27, when auth-policy is configured, allows a remote attackers to cause a denial of service (crash) by aborti…

Fix: after 2.2.27
Fix from $1,600 2017-02-17
Gpu Driver HIGH 7.8
CVE-2017-0312

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscapeID 0x10000…

No fix yet
Fix from $1,950 2017-02-15
Gpu Driver MEDIUM 5.5
CVE-2017-0318

All versions of NVIDIA Linux GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper validation of an input parame…

No fix yet
Fix from $1,600 2017-02-15
Aix MEDIUM 5.5
CVE-2016-8944

IBM AIX 7.1 and 7.2 allows a local user to open a file with a specially crafted argument that would crash the system. IBM APARs: IV91488, IV91487, IV…

Patch available
Fix from $1,600 2017-02-15
Lgate Firmware HIGH 8.6
CVE-2016-5782

An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP…

Mitigation only
Fix from $1,950 2017-02-13
Samsung Mobile MEDIUM 5.5
CVE-2016-4546

Samsung devices with Android KK(4.4) or L(5.0/5.1) allow local users to cause a denial of service (IAndroidShm service crash) via crafted data in a s…

Mitigation only
Fix from $1,600 2017-02-13