Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-5024

Virtual servers in F5 BIG-IP systems 11.6.1 before 11.6.1 HF1 and 12.1.x before 12.1.2, when configured to parse RADIUS messages via an iRule, allow …

Mitigation only
Fix from $1,600 2017-01-03
Borg MEDIUM 5.3
CVE-2016-10100

Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery, potentially allowing an att…

Fix: after 1.0.8
Fix from $1,600 2017-01-02
Debian Linux MEDIUM 5.5
CVE-2015-8744

QEMU (aka Quick Emulator) built with a VMWARE VMXNET3 paravirtual NIC emulator support is vulnerable to crash issue. It occurs when a guest sends a L…

Fix: after 2.4.1
Fix from $1,600 2016-12-29
Jabber Guest MEDIUM 6.5
CVE-2016-9224

A vulnerability in the Cisco Jabber Guest Server could allow an unauthenticated, remote attacker to initiate connections to arbitrary hosts. More Inf…

Mitigation only
Fix from $1,600 2016-12-26
Ffmpeg MEDIUM 5.5
CVE-2016-7785

The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a c…

Fix: after 3.1.3
Fix from $1,600 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-8595

The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a cr…

Fix: after 3.1.4
Fix from $1,600 2016-12-23
Lynx HIGH 7.5
CVE-2016-9179

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be t…

Mitigation only
Fix from $1,950 2016-12-22
Excel HIGH 7.8
CVE-2016-7266EPSS 22%

Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 …

Mitigation only
Fix from $1,950 2016-12-20
Excel MEDIUM 5.5
CVE-2016-7267EPSS 19%

Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary cod…

Mitigation only
Fix from $1,600 2016-12-20
Chrome MEDIUM 6.5
CVE-2016-5187

Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacke…

Fix: after 53.0.2785.143
Fix from $1,600 2016-12-18
Simatic S7 300 Cpu Firmware HIGH 7.5
CVE-2016-9158

A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS varia…

Mitigation only
Fix from $1,950 2016-12-17
Gpu Driver HIGH 7.8
CVE-2016-8818

All versions of NVIDIA Windows GPU Display contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a pointer p…

Patch available
Fix from $1,950 2016-12-16
Gpu Driver MEDIUM 6.1
CVE-2016-8820

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a ch…

Patch available
Fix from $1,600 2016-12-16
Gpu Driver HIGH 7.8
CVE-2016-8822

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x60000…

Patch available
Fix from $1,950 2016-12-16
Web Security Appliance HIGH 7.5
CVE-2016-9212

A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could al…

Mitigation only
Fix from $1,950 2016-12-14
Ons 15454 Sdh Multiservice Platform Software HIGH 7.5
CVE-2016-9211

A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker …

Mitigation only
Fix from $1,950 2016-12-14
Expressway MEDIUM 6.5
CVE-2016-9207

A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections …

Mitigation only
Fix from $1,600 2016-12-14
iOS HIGH 7.5
CVE-2016-9201

A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass tra…

Mitigation only
Fix from $1,950 2016-12-14
Firesight System Software HIGH 7.5
CVE-2016-9193

A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could …

Mitigation only
Fix from $1,950 2016-12-14
Fedora HIGH 7.5
CVE-2016-7952

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecor…

Fix: after 1.2.2
Fix from $1,950 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7949

Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to t…

Fix: after 0.9.9
Fix from $2,300 2016-12-13
Android MEDIUM 5.5
CVE-2016-6712

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before…

Patch available
Fix from $1,600 2016-12-13
Android MEDIUM 5.5
CVE-2016-6711

A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before…

Patch available
Fix from $1,600 2016-12-13
Solaris CRITICAL 9.8
CVE-2016-5691EPSS 5%

The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validati…

Fix: after 6.9.4-4
Fix from $2,300 2016-12-13
phpMyAdmin HIGH 7.5
CVE-2016-9863

An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) a…

Patch available
Fix from $1,950 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-9860

An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbi…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9859

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9858

An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6630

An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the cha…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6623

An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. A…

Patch available
Fix from $1,600 2016-12-11