Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Telepresence Mcu Software CRITICAL 9.8
CVE-2017-3792EPSS 6%

A vulnerability in a proprietary device driver in the kernel of Cisco TelePresence Multipoint Control Unit (MCU) Software could allow an unauthentica…

Mitigation only
Fix from $2,300 2017-02-01
Samsung Mobile HIGH 7.8
CVE-2016-4038

Array index error in the msm_sensor_config function in kernel/SM-G9008V_CHN_KK_Opensource/Kernel/drivers/media/platform/msm/camera_v2/sensor/msm_sens…

Mitigation only
Fix from $1,950 2017-02-01
Merge System CRITICAL 9.8
CVE-2016-9420

MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 allow remote attackers to have unspecified impact via vectors related to "…

Fix: after 1.8.7
Fix from $2,300 2017-01-31
Big Ip Local Traffic Manager HIGH 7.5
CVE-2016-9249

An undisclosed traffic pattern received by a BIG-IP Virtual Server with TCP Fast Open enabled may cause the Traffic Management Microkernel (TMM) to r…

Mitigation only
Fix from $1,950 2017-01-31
Smart Protection Server HIGH 8.8
CVE-2016-6266EPSS 8%

ccca_ajaxhandler.php in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote aut…

Patch available
Fix from $1,950 2017-01-30
Smart Protection Server HIGH 8.8
CVE-2016-6267EPSS 55%

SnmpUtils in Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows remote authenticated …

Patch available
Fix from $1,950 2017-01-30
Ntp MEDIUM 5.3
CVE-2016-2516EPSS 11%

NTP before 4.2.8p7 and 4.3.x before 4.3.92, when mode7 is enabled, allows remote attackers to cause a denial of service (ntpd abort) by using the sam…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Ntp MEDIUM 5.3
CVE-2016-2517EPSS 8%

NTP before 4.2.8p7 and 4.3.x before 4.3.92 allows remote attackers to cause a denial of service (prevent subsequent authentication) by leveraging kno…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Debian Linux HIGH 7.5
CVE-2016-9939

Crypto++ (aka cryptopp and libcrypto++) 5.6.4 contained a bug in its ASN.1 BER decoding routine. The library will allocate a memory block based on th…

Patch available
Fix from $1,950 2017-01-30
Ntp MEDIUM 5.3
CVE-2015-8138EPSS 7%

NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to bypass the origin timestamp validation via a packet with an origin timestamp se…

Fix: after 4.2.8
Fix from $1,600 2017-01-30
Wnr2000v5 Firmware CRITICAL 9.8
CVE-2016-10176EPSS 72%

The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the web server of the device. This…

Fix: after 1.0.0.34
Fix from $2,300 2017-01-30
Vm Virtualbox HIGH 8.4
CVE-2017-3316EPSS 6%

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: GUI). Supported versions that are affected are VirtualBox…

Patch available
Fix from $1,950 2017-01-27
MySQL MEDIUM 6.5
CVE-2017-3273

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.34 and earlier …

Fix: after 5.7.16
Fix from $1,600 2017-01-27
Ca Workload Automation Ae HIGH 7.8
CVE-2016-9795

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance f…

Mitigation only
Fix from $1,950 2017-01-27
Vm Server MEDIUM 5.9
CVE-2017-3242

Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that …

Patch available
Fix from $1,600 2017-01-27
MySQL MEDIUM 6.5
CVE-2017-3256

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.16 and …

Fix: after 5.7.16
Fix from $1,600 2017-01-27
MySQL MEDIUM 6.5
CVE-2017-3258

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier,…

Fix: 5.5.54 / 10.0.29+
Fix from $1,600 2017-01-27
Xenserver MEDIUM 6.0
CVE-2016-10024

Xen through 4.8.x allows local x86 PV guest OS kernel administrators to cause a denial of service (host hang or crash) by modifying the instruction s…

Fix: after 4.8.0
Fix from $1,600 2017-01-26
Libgd MEDIUM 5.5
CVE-2016-9317EPSS 6%

The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via…

Fix: after 2.2.3
Fix from $1,600 2017-01-26
Email Security Appliance MEDIUM 5.8
CVE-2017-3800

A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, re…

Mitigation only
Fix from $1,600 2017-01-26
Adaptive Server Enterprise HIGH 7.5
CVE-2017-5371

Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted …

No fix yet
Fix from $1,950 2017-01-23
Webnms Framework CRITICAL 9.8
CVE-2016-6603EPSS 49%

ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.

No fix yet
Fix from $2,300 2017-01-23
Xenserver HIGH 7.9
CVE-2016-9379

The pygrub boot loader emulator in Xen, when S-expression output format is requested, allows local pygrub-using guest OS administrators to read or de…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.5
CVE-2016-9380

The pygrub boot loader emulator in Xen, when nul-delimited output format is requested, allows local pygrub-using guest OS administrators to read or d…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 8.8
CVE-2016-9383

Xen, when running on a 64-bit hypervisor, allows local x86 guest OS users to modify arbitrary memory and consequently obtain sensitive information, c…

Patch available
Fix from $1,950 2017-01-23
Xenserver MEDIUM 6.0
CVE-2016-9385

The x86 segment base write emulation functionality in Xen 4.4.x through 4.7.x allows local x86 PV guest OS administrators to cause a denial of servic…

Patch available
Fix from $1,600 2017-01-23
Cakephp HIGH 7.5
CVE-2016-4793

The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP header.

Fix: after 3.2.4
Fix from $1,950 2017-01-23
Keepass HIGH 7.5
CVE-2016-5119

The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check r…

Fix: after 2.33
Fix from $1,950 2017-01-23
Multichannel Vpn Router 300 Firmware MEDIUM 5.9
CVE-2014-9754

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (thro…

No fix yet
Fix from $1,600 2017-01-20
Multichannel Vpn Router 300 Firmware HIGH 7.5
CVE-2014-9755

The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (thro…

No fix yet
Fix from $1,950 2017-01-20