Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Samsung Mobile HIGH 7.5
CVE-2016-4547

Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to …

Mitigation only
Fix from $1,950 2017-02-13
Op Tee HIGH 7.5
CVE-2016-6129

The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equ…

Fix: 2.2.0+
Fix from $1,950 2017-02-13
Mcafee Agent MEDIUM 5.9
CVE-2017-3896

Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remo…

Mitigation only
Fix from $1,600 2017-02-13
Bruno MEDIUM 5.9
CVE-2017-5589

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Chatsecure MEDIUM 5.9
CVE-2017-5590

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Fix: after 1.0.11
Fix from $1,600 2017-02-09
Sleekxmpp MEDIUM 5.9
CVE-2017-5591

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Fix: after 1.3.1
Fix from $1,600 2017-02-09
Profanity MEDIUM 5.9
CVE-2017-5592

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Psi\+ MEDIUM 5.9
CVE-2017-5593

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Jappix MEDIUM 5.9
CVE-2017-5602

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Jitsi MEDIUM 5.9
CVE-2017-5603

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Mcabber MEDIUM 5.9
CVE-2017-5604

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Movim MEDIUM 5.9
CVE-2017-5605

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Xabber MEDIUM 5.9
CVE-2017-5606

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Fix: after 1.0.30
Fix from $1,600 2017-02-09
Converse.js MEDIUM 5.9
CVE-2017-5858

An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta…

Patch available
Fix from $1,600 2017-02-09
Puppet Enterprise MEDIUM 5.3
CVE-2016-9686

The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preve…

Fix: 2016.4.3+
Fix from $1,600 2017-02-08
Android HIGH 7.5
CVE-2017-0422

A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or re…

Mitigation only
Fix from $1,950 2017-02-08
Libiberty HIGH 7.5
CVE-2016-6131

The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the ref…

Patch available
Fix from $1,950 2017-02-07
Libtorrent HIGH 7.5
CVE-2016-7164

The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via…

Patch available
Fix from $1,950 2017-02-07
Libtiff MEDIUM 5.5
CVE-2016-5102

Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service…

Fix: after 4.0.6
Fix from $1,600 2017-02-06
Linux Kernel MEDIUM 5.5
CVE-2010-5328

include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper proces…

Fix: after 2.6.34.7
Fix from $1,600 2017-02-06
Splunk MEDIUM 6.5
CVE-2017-5880

Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x …

Patch available
Fix from $1,600 2017-02-04
Racf Connector HIGH 8.1
CVE-2016-6500

Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor wi…

Fix: after 1.1.0.0
Fix from $1,950 2017-02-03
Secure Firewall Management Center MEDIUM 5.8
CVE-2017-3809

A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to pre…

Mitigation only
Fix from $1,600 2017-02-03
Secure Firewall Management Center MEDIUM 5.8
CVE-2017-3814

A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to b…

Mitigation only
Fix from $1,600 2017-02-03
Email Security Appliance Firmware MEDIUM 5.8
CVE-2017-3818

A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could…

Mitigation only
Fix from $1,600 2017-02-03
Secure Firewall Threat Defense MEDIUM 5.3
CVE-2017-3822

A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, r…

Mitigation only
Fix from $1,600 2017-02-03
Lepton MEDIUM 5.5
CVE-2016-6234

The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg…

Patch available
Fix from $1,600 2017-02-02
Bigfix Platform MEDIUM 6.5
CVE-2016-6084

IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request.

Patch available
Fix from $1,600 2017-02-01
Saplpd HIGH 7.5
CVE-2016-10079EPSS 5%

SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515.

Fix: after 7400.3.11.33
Fix from $1,950 2017-02-01
Expressway HIGH 8.6
CVE-2017-3790

A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow…

Mitigation only
Fix from $1,950 2017-02-01