Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Leap MEDIUM 6.5
CVE-2016-9435

The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the a…

Fix: after 0.5.3
Fix from $1,600 2017-01-20
Leap MEDIUM 6.5
CVE-2016-9436

parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted…

Fix: after 0.5.3
Fix from $1,600 2017-01-20
Moodle MEDIUM 5.3
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

Fix: after 2.7.17
Fix from $1,600 2017-01-20
Netbsd CRITICAL 9.8
CVE-2015-8212

CGI handling flaw in bozohttpd in NetBSD 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows remote attackers to execute arbitrary code via crafted …

Mitigation only
Fix from $2,300 2017-01-19
Fedora HIGH 8.4
CVE-2016-7543

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

Fix: after 4.3
Fix from $1,950 2017-01-19
Chrome HIGH 8.8
CVE-2016-5197

The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who …

Fix: after 54.0.2840.68
Fix from $1,950 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5218

The extensions API in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation wit…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Chrome MEDIUM 6.5
CVE-2016-5222

Incorrect handling of invalid URLs in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android allowed a remote a…

Fix: after 54.0.2840.99
Fix from $1,600 2017-01-19
Spip HIGH 8.8
CVE-2016-7998EPSS 11%

The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML fi…

Fix: after 3.1.2
Fix from $1,950 2017-01-18
Exynos Fimg2d Driver MEDIUM 5.5
CVE-2016-9278

The Samsung Exynos fimg2d driver for Android with Exynos 5433, 54xx, or 7420 chipsets allows local users to cause a denial of service (kernel panic) …

Mitigation only
Fix from $1,600 2017-01-18
Ntp MEDIUM 5.3
CVE-2016-7431EPSS 10%

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp of zero. NOTE: this vulnerabi…

No fix yet
Fix from $1,600 2017-01-13
Ntp HIGH 7.5
CVE-2016-7434EPSS 53%

The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a crafted mrulist query.

Fix: 4.3.94+
Fix from $1,950 2017-01-13
Exponent Cms CRITICAL 9.8
CVE-2016-7790

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through…

Patch available
Fix from $2,300 2017-01-12
Exponent Cms CRITICAL 9.8
CVE-2016-7791

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to …

Patch available
Fix from $2,300 2017-01-12
Android HIGH 7.5
CVE-2017-0389

A denial of service vulnerability in core networking could enable a remote attacker to use specially crafted network packet to cause a device hang or…

Mitigation only
Fix from $1,950 2017-01-12
Linux Kernel CRITICAL 9.8
CVE-2016-8437

Improper input validation in Access Control APIs. Access control API may return memory range checking incorrectly. Product: Android. Versions: Kernel…

Mitigation only
Fix from $2,300 2017-01-12
Linux Kernel HIGH 7.8
CVE-2016-8442

Possible unauthorized memory access in the hypervisor. Lack of input validation could allow hypervisor memory to be accessed by the HLOS. Product: An…

Mitigation only
Fix from $1,950 2017-01-12
Debian Linux HIGH 7.5
CVE-2016-9131EPSS 41%

named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (ass…

Fix: after 9.10.3
Fix from $1,950 2017-01-12
Bind HIGH 7.5
CVE-2016-9147EPSS 10%

named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exi…

Patch available
Fix from $1,950 2017-01-12
Bind HIGH 7.5
CVE-2016-9444EPSS 7%

named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (ass…

Patch available
Fix from $1,950 2017-01-12
Acrobat MEDIUM 5.5
CVE-2017-2947EPSS 7%

Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have a security bypass vulnerability when manip…

Fix: after 15.020.20042
Fix from $1,600 2017-01-11
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-9247

Under certain conditions for BIG-IP systems using a virtual server with an associated FastL4 profile and TCP analytics profile, a specific sequence o…

Mitigation only
Fix from $1,600 2017-01-10
Ethernet Controller X710 Firmware MEDIUM 5.9
CVE-2016-8106

A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop th…

Fix: after 5.04
Fix from $1,600 2017-01-09
Samsung Mobile MEDIUM 5.5
CVE-2017-5217

Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually cra…

Mitigation only
Fix from $1,600 2017-01-09
Anti Virus MEDIUM 5.5
CVE-2016-4329

A local denial of service vulnerability exists in window broadcast message handling functionality of Kaspersky Anti-Virus software. Sending certain u…

No fix yet
Fix from $1,600 2017-01-06
Ntp MEDIUM 5.3
CVE-2016-1547EPSS 5%

An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec a5fb34b9cc89b92a8fef2f4590048…

Fix: after 4.2.8
Fix from $1,600 2017-01-06
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-5024

Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow …

Mitigation only
Fix from $1,600 2017-01-03
Borg MEDIUM 5.3
CVE-2016-10100

Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an att…

Fix: after 1.0.8
Fix from $1,600 2017-01-02
Debian Linux MEDIUM 5.5
CVE-2015-8744

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a L…

Fix: after 2.4.1
Fix from $1,600 2016-12-29
Jabber Guest MEDIUM 6.5
CVE-2016-9224

A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Inf…

Mitigation only
Fix from $1,600 2016-12-26