Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS MEDIUM 6.5
CVE-2014-2146

The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking…

Fix: after 15.4
Fix from $1,600 2016-09-22
Ac6003 Firmware MEDIUM 6.5
CVE-2016-6824

Huawei AC6003, AC6005, AC6605, and ACU2 access controllers with software before V200R006C10SPC200 allows remote authenticated users to cause a denial…

Mitigation only
Fix from $1,600 2016-09-22
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5418

The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to …

Patch available
Fix from $1,950 2016-09-21
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4809

The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a…

Patch available
Fix from $1,950 2016-09-21
Ubuntu Linux MEDIUM 5.5
CVE-2015-8932

The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of s…

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Ubuntu Linux HIGH 7.5
CVE-2015-8930

bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member o…

Fix: after 3.1.901a
Fix from $1,950 2016-09-20
Ubuntu Linux MEDIUM 6.5
CVE-2015-8923

The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a …

Fix: after 3.1.901a
Fix from $1,600 2016-09-20
Webex Meetings Server HIGH 7.5
CVE-2016-1483

Cisco WebEx Meetings Server 2.6 allows remote attackers to cause a denial of service (CPU consumption) by repeatedly accessing the account-validation…

Mitigation only
Fix from $1,950 2016-09-19
Fog Director MEDIUM 6.5
CVE-2016-6405

Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartr…

Mitigation only
Fix from $1,600 2016-09-18
PHP CRITICAL 9.8
CVE-2016-7417EPSS 7%

ext/spl/spl_array.c in PHP before 5.6.26 and 7.x before 7.0.11 proceeds with SplArray unserialization without validating a return value and data type…

Fix: after 5.6.25
Fix from $2,300 2016-09-17
OpenSSL HIGH 7.5
CVE-2016-6302EPSS 26%

The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which…

Patch available
Fix from $1,950 2016-09-16
Exchange Server HIGH 7.4
CVE-2016-3378EPSS 15%

Open redirect vulnerability in Microsoft Exchange Server 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, an…

Mitigation only
Fix from $1,950 2016-09-14
Ace Application Control Engine Module A1 HIGH 7.5
CVE-2016-6399

Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers…

Mitigation only
Fix from $1,950 2016-09-12
Firesight System Software MEDIUM 5.3
CVE-2016-6396

Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remot…

Mitigation only
Fix from $1,600 2016-09-12
Yorufukurou MEDIUM 6.5
CVE-2016-4852

YoruFukurou (NightOwl) before 2.85 relies on support for emoji skin-tone modifiers even though this support is missing from the CoreText CTFramesette…

Fix: after 2.84
Fix from $1,600 2016-09-12
PHP CRITICAL 9.8
CVE-2016-7129EPSS 7%

The php_wddx_process_data function in ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service…

Fix: after 5.6.24
Fix from $2,300 2016-09-12
Junos MEDIUM 5.9
CVE-2016-1277

Juniper Junos OS before 12.1X46-D50, 12.1X47 before 12.1X47-D40, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9, 14.1 before 14.1R8, 14.1X53 before 1…

Fix: after 12.1x46
Fix from $1,600 2016-09-09
Junos HIGH 7.5
CVE-2016-1263

Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3X48 before 12.3X48-D30, 13.3 before 13.3R9-S1, 14.1 before 14.1R7, …

Fix: after 12.1x46
Fix from $1,950 2016-09-09
Webex Wrf Player T29 HIGH 7.8
CVE-2016-1464EPSS 10%

Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug I…

No fix yet
Fix from $1,950 2016-09-03
Mq Appliance Firmware HIGH 8.8
CVE-2016-5879

MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) H…

Mitigation only
Fix from $1,950 2016-09-02
Small Business 220 Series Smart Plus Switches HIGH 7.5
CVE-2016-1472

The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,950 2016-09-02
Readynas Surveillance CRITICAL 9.8
CVE-2016-5675EPSS 71%

handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR Read…

No fix yet
Fix from $2,300 2016-08-31
Readynas Surveillance CRITICAL 9.8
CVE-2016-5674EPSS 95%

__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 thro…

No fix yet
Fix from $2,300 2016-08-31
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Aironet Access Point Software MEDIUM 6.5
CVE-2016-6361

The Aggregated MAC Protocol Data Unit (AMPDU) implementation on Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.121.0 and 8.3.x b…

Mitigation only
Fix from $1,600 2016-08-22
Ip Phone 8800 Series Firmware HIGH 7.5
CVE-2016-1479

Cisco IP Phone 8800 devices with software 11.0(1) allow remote attackers to cause a denial of service (memory corruption) via a crafted HTTP request,…

Mitigation only
Fix from $1,950 2016-08-22
Application Policy Infrastructure Controller Enterprise Module HIGH 8.8
CVE-2016-1365

The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0 allows remote authenticated users …

Mitigation only
Fix from $1,950 2016-08-18
Live Meeting HIGH 7.8
CVE-2016-3304EPSS 51%

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vi…

No fix yet
Fix from $1,950 2016-08-09
Live Meeting HIGH 7.8
CVE-2016-3303EPSS 51%

The Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office 2007 SP3, Office 2010 SP2, Word Vi…

No fix yet
Fix from $1,950 2016-08-09
Live Meeting HIGH 7.8
CVE-2016-3301EPSS 44%

The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and…

No fix yet
Fix from $1,950 2016-08-09