Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Artifactory CRITICAL 9.8
CVE-2016-6501

JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP…

Fix: after 4.10
Fix from $2,300 2016-12-09
Crowd CRITICAL 9.8
CVE-2016-6496

The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att…

Fix: after 2.8.4
Fix from $2,300 2016-12-09
Linux Kernel HIGH 7.5
CVE-2016-9919EPSS 6%

The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote at…

Fix: 4.9+
Fix from $1,950 2016-12-08
Libtiff HIGH 7.4
CVE-2015-8870

Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or p…

Fix: after 4.0.3
Fix from $1,950 2016-12-06
HTTP Server HIGH 7.5
CVE-2016-8740EPSS 79%

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-…

Patch available
Fix from $1,950 2016-12-05
Sicam Pas\/pqs CRITICAL 9.8
CVE-2016-9157

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially…

Fix: 8.09+
Fix from $2,300 2016-12-05
Sicam Pas\/pqs HIGH 7.3
CVE-2016-9156

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts …

Fix: 8.09+
Fix from $1,950 2016-12-05
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Boa HIGH 7.5
CVE-2016-9564

Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' …

No fix yet
Fix from $1,950 2016-11-30
Maximo Asset Management MEDIUM 5.3
CVE-2016-5987

IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5 before 7.5.0.10 IF4, and 7.6 before 7.6.0.5 IF3 allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2937

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST reques…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2935

The broker application in IBM BigFix Remote Control before 9.1.3 allows remote attackers to cause a denial of service via an invalid HTTP request.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Linux Kernel MEDIUM 5.5
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial …

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows lo…

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Drupal MEDIUM 6.5
CVE-2016-9452

The transliterate mechanism in Drupal 8.x before 8.2.3 allows remote attackers to cause a denial of service via a crafted URL.

Patch available
Fix from $1,600 2016-11-25
Security Privileged Identity Manager MEDIUM 6.5
CVE-2016-2996

IBM Security Privileged Identity Manager 2.0 before 2.0.2 FP8, when Virtual Appliance is used, allows remote authenticated users to append to arbitra…

Mitigation only
Fix from $1,600 2016-11-24
Debian Linux HIGH 7.8
CVE-2016-1248EPSS 25%

vim before patch 8.0.0056 does not properly validate values for the 'filetype', 'syntax' and 'keymap' options, which may result in the execution of a…

Fix: after 8.0.0055
Fix from $1,950 2016-11-23
Email Security Appliance Firmware MEDIUM 5.3
CVE-2016-6463

A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, re…

Mitigation only
Fix from $1,600 2016-11-19
Email Security Appliance Firmware MEDIUM 5.3
CVE-2016-6462

A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, re…

Mitigation only
Fix from $1,600 2016-11-19
Adaptive Security Appliance Software MEDIUM 5.9
CVE-2016-6461

A vulnerability in the HTTP web-based management interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,600 2016-11-19
Email Security Appliance Firmware HIGH 7.5
CVE-2016-6458

A vulnerability in the content filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, …

Mitigation only
Fix from $1,950 2016-11-19
Hdf5 HIGH 8.6
CVE-2016-4332

The library's failure to check if certain message types support a particular flag, the HDF5 1.8.16 library will cast the structure to an alternative …

No fix yet
Fix from $1,950 2016-11-18
Wireshark MEDIUM 5.9
CVE-2016-9375

In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. Thi…

Mitigation only
Fix from $1,600 2016-11-17
Wireshark MEDIUM 5.9
CVE-2016-9372

In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in…

No fix yet
Fix from $1,600 2016-11-17
Avamar Data Store HIGH 8.4
CVE-2016-0909

EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) versions 7.3 and older contain a vulnerability that may expose the Avamar servers to pot…

Fix: after 7.3
Fix from $1,950 2016-11-15
Edge MEDIUM 5.3
CVE-2016-7209EPSS 9%

Microsoft Edge allows remote attackers to spoof web content via a crafted web site, aka "Microsoft Edge Spoofing Vulnerability."

No fix yet
Fix from $1,600 2016-11-10
Gpu Driver HIGH 7.8
CVE-2016-8809

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerabilit…

Fix: 342.00 / 375.63+
Fix from $1,950 2016-11-08
Gpu Driver MEDIUM 6.6
CVE-2016-5025

For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVAPI support layer causes a denial of service vulnerabi…

Fix: 341.96 / 354.99+
Fix from $1,600 2016-11-08
Geforce Experience MEDIUM 5.5
CVE-2016-4961

For the NVIDIA Quadro, NVS, and GeForce products, improper sanitization of parameters in the NVStreamKMS.sys API layer caused a denial of service vul…

Patch available
Fix from $1,600 2016-11-08
Geforce Experience HIGH 7.3
CVE-2016-4960

For the NVIDIA Quadro, NVS, and GeForce products, the NVIDIA NVStreamKMS.sys service component is improperly validating user-supplied data through it…

Patch available
Fix from $1,950 2016-11-08