Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS HIGH 7.5
CVE-2016-6379

Cisco IOS 12.2 and IOS XE 3.14 through 3.16 and 16.1 allow remote attackers to cause a denial of service (device reload) via crafted IP Detail Record…

Mitigation only
Fix from $1,950 2016-10-05
iOS HIGH 7.5
CVE-2016-6384

Cisco IOS 12.2 through 12.4 and 15.0 through 15.6 and IOS XE 3.1 through 3.17 and 16.2 allow remote attackers to cause a denial of service (device re…

Fix: after 15.6
Fix from $1,950 2016-10-05
Emc Unisphere CRITICAL 9.8
CVE-2016-6646

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…

Mitigation only
Fix from $2,300 2016-10-05
Emc Unisphere HIGH 8.8
CVE-2016-6645

The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3…

Mitigation only
Fix from $1,950 2016-10-05
Networker Module For Microsoft Applications CRITICAL 9.8
CVE-2016-0913

The client in EMC Replication Manager (RM) before 5.5.3.0_01-PatchHotfix, EMC Network Module for Microsoft 3.x, and EMC Networker Module for Microsof…

Fix: after 8.2.3.6
Fix from $2,300 2016-10-05
Usg9520 HIGH 7.5
CVE-2016-8278

Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,950 2016-10-03
Usg9520 MEDIUM 6.5
CVE-2016-8277

Huawei USG9520, USG9560, and USG9580 unified security gateways with software before V300R001C01SPCa00 allow remote authenticated users to cause a den…

Mitigation only
Fix from $1,600 2016-10-03
Debian Linux HIGH 8.8
CVE-2016-1244EPSS 5%

The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file.

Patch available
Fix from $1,950 2016-10-03
Tomcat HIGH 7.8
CVE-2016-1240EPSS 10%

The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and …

No fix yet
Fix from $1,950 2016-10-03
Linux HIGH 7.5
CVE-2016-2776EPSS 89%

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which al…

Fix: after 9.9.9
Fix from $1,950 2016-09-28
Ar Firmware MEDIUM 6.5
CVE-2016-6901

Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software befo…

Mitigation only
Fix from $1,600 2016-09-26
SQLite MEDIUM 5.9
CVE-2016-6153

os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive i…

Fix: after 3.12.2
Fix from $1,600 2016-09-26
Mitaka Murano CRITICAL 9.8
CVE-2016-4972

OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and pyt…

Fix: after 2.0.0
Fix from $2,300 2016-09-26
Ubuntu Linux HIGH 7.5
CVE-2016-7162

The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a sym…

Patch available
Fix from $1,950 2016-09-26
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-3110

mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP mes…

Mitigation only
Fix from $1,950 2016-09-26
Tivoli Storage Productivity Center MEDIUM 5.7
CVE-2016-5947

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to conduct clickjacking atta…

Patch available
Fix from $1,600 2016-09-26
Chrome MEDIUM 6.5
CVE-2016-5174

browser/ui/cocoa/browser_window_controller_private.mm in Google Chrome before 53.0.2785.113 does not process fullscreen toggle requests during a full…

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.8
CVE-2016-4753

Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 mishandle signed disk images, which allows attackers to execute arbitrar…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Safari HIGH 8.8
CVE-2016-4728

WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 mishandles error prototypes, which allows remote…

Fix: 10.0 / 12.5.1+
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 5.9
CVE-2016-4722

The IDS - Connectivity component in Apple iOS before 10 and OS X before 10.12 allows man-in-the-middle attackers to conduct Call Relay spoofing attac…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.5
CVE-2016-4711

CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4706

cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 6.2
CVE-2016-4701

Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environme…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.8
CVE-2016-4698

AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
iOS MEDIUM 6.5
CVE-2016-6412

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows man-in-the-mid…

Mitigation only
Fix from $1,600 2016-09-24
Firesight System Software HIGH 7.5
CVE-2016-6411

Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote …

Mitigation only
Fix from $1,950 2016-09-24
iOS MEDIUM 6.5
CVE-2016-6410

The Cisco Application-hosting Framework (CAF) component in Cisco IOS 15.6(1)T1 and IOS XE, when the IOx feature set is enabled, allows remote authent…

Mitigation only
Fix from $1,600 2016-09-24
Cloud Services Platform 2100 CRITICAL 9.8
CVE-2016-6374

Cisco Cloud Services Platform (CSP) 2100 2.0 allows remote attackers to execute arbitrary code via a crafted dnslookup command in an HTTP request, ak…

Mitigation only
Fix from $2,300 2016-09-22
Firefox HIGH 7.4
CVE-2016-5284

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinnin…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5272

The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast …

Fix: after 48.0.2
Fix from $1,950 2016-09-22