Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
iOS HIGH 7.5
CVE-2016-1478

Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2016-08-08
Rv180 Vpn Router Firmware HIGH 8.8
CVE-2016-1430

Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz485…

Mitigation only
Fix from $1,950 2016-08-08
Fedora HIGH 7.5
CVE-2016-6515EPSS 59%

The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows r…

Fix: after 7.2
Fix from $1,950 2016-08-07
Linux Kernel HIGH 7.8
CVE-2016-5340

The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x…

Fix: after 7.0
Fix from $1,950 2016-08-07
Linux Kernel CRITICAL 9.8
CVE-2014-9410

The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Inno…

Fix: after 3.19.8
Fix from $2,300 2016-08-07
Chrome HIGH 7.5
CVE-2016-5141

Blink, as used in Google Chrome before 52.0.2743.116, allows remote attackers to spoof the address bar via vectors involving a provisional URL for an…

Fix: after 52.0.2743.82
Fix from $1,950 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5358

epan/dissectors/packet-pktap.c in the Ethernet dissector in Wireshark 2.x before 2.0.4 mishandles the packet-header data type, which allows remote at…

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5357

wiretap/netscreen.c in the NetScreen file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processin…

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5355

wiretap/toshiba.c in the Toshiba file parser in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles sscanf unsigned-integer processing, w…

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5353

epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the reserved C/T value, …

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5351

epan/crypt/airpdcap.c in the IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles the lack of an EAPOL_RSN_KEY, w…

Patch available
Fix from $1,600 2016-08-07
Debian Linux HIGH 7.5
CVE-2016-6128EPSS 7%

The gdImageCropThreshold function in gd_crop.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 7.0.9, allows remote attack…

Fix: after 2.2.2
Fix from $1,950 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-6512EPSS 8%

epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, which allows remote attackers to…

No fix yet
Fix from $1,600 2016-08-06
Wireshark MEDIUM 5.9
CVE-2016-6509

epan/dissectors/packet-ldss.c in the LDSS dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 mishandles conversations, which allows re…

Patch available
Fix from $1,600 2016-08-06
Wireshark MEDIUM 5.9
CVE-2016-6503EPSS 6%

The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual C++ compiler options, which a…

No fix yet
Fix from $1,600 2016-08-06
Linux MEDIUM 5.5
CVE-2016-6197

fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceed…

Fix: after 4.5.7
Fix from $1,600 2016-08-06
Linux Kernel HIGH 7.8
CVE-2016-6162

net/core/skbuff.c in the Linux kernel 4.7-rc6 allows local users to cause a denial of service (panic) or possibly have unspecified other impact via c…

Mitigation only
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9889

drivers/media/platform/msm/camera_v2/pproc/cpp/msm_cpp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9886

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9884

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate certain pointers, wh…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9872

The diag driver in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not ensure unique identifiers in a DCI client table, …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9866

drivers/media/platform/msm/camera_v2/sensor/csid/msm_csid.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices d…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.8
CVE-2014-9864

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not validate ioctl calls, which a…

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android HIGH 7.5
CVE-2016-3831

The telephony component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows remote attackers to cau…

Patch available
Fix from $1,950 2016-08-05
Android MEDIUM 5.5
CVE-2016-3830

codecs/aacdec/SoftAAC2.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-…

Patch available
Fix from $1,600 2016-08-05
Android HIGH 7.8
CVE-2016-3826

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 does …

Patch available
Fix from $1,950 2016-08-05
Hana HIGH 7.5
CVE-2016-6148

SAP HANA DB 1.00.73.00.389160 allows remote attackers to cause a denial of service (process termination) or execute arbitrary code via vectors relate…

No fix yet
Fix from $1,950 2016-08-05
Firefox MEDIUM 5.3
CVE-2016-5267

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-l…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-2839

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with …

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Xenserver MEDIUM 6.2
CVE-2016-6259

Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows l…

Patch available
Fix from $1,600 2016-08-02