Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Ne5000e Firmware CRITICAL 9.8
CVE-2016-6178

Huawei NE40E and CX600 devices with software before V800R007SPH017; PTN 6900-2-M8 devices with software before V800R007SPH019; NE5000E devices with s…

Mitigation only
Fix from $2,300 2016-08-02
Pan Os HIGH 7.8
CVE-2016-1712

Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12, 6.0.x before 6.0.14, 6.1.x before 6.1.12, and 7.0.x before 7.0.8 might allow local user…

Fix: 5.0.19 / 5.1.12+
Fix from $1,950 2016-08-02
Jboss Operations Network CRITICAL 9.8
CVE-2016-3737EPSS 7%

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, relat…

Fix: after 3.3.5
Fix from $2,300 2016-08-02
Crosswalk HIGH 8.1
CVE-2016-5672

Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of …

Fix: after 19.49.514.4
Fix from $1,950 2016-08-01
Asyncos HIGH 7.5
CVE-2016-1461

Cisco AsyncOS on Email Security Appliance (ESA) devices through 9.7.0-125 allows remote attackers to bypass malware detection via a crafted attachmen…

Fix: after 9.7.0-125
Fix from $1,950 2016-08-01
Firesight System Software HIGH 7.5
CVE-2016-1463

Cisco FireSIGHT System Software 5.3.0, 5.3.1, 5.4.0, 6.0, and 6.0.1 allows remote attackers to bypass Snort rules via crafted parameters in the heade…

Mitigation only
Fix from $1,950 2016-07-28
Unified Computing System Performance Manager HIGH 8.8
CVE-2016-1374

The web framework in Cisco Unified Computing System (UCS) Performance Manager 2.0.0 and earlier allows remote authenticated users to execute arbitrar…

Mitigation only
Fix from $1,950 2016-07-28
Chrome MEDIUM 6.5
CVE-2016-5135

WebKit/Source/core/html/parser/HTMLPreloadScanner.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not consider referrer-policy infor…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Chrome MEDIUM 6.5
CVE-2016-1707

ios/web/web_state/ui/crw_web_controller.mm in Google Chrome before 52.0.2743.82 on iOS does not ensure that an invalid URL is replaced with the about…

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Chrome CRITICAL 9.6
CVE-2016-1706

The PPAPI implementation in Google Chrome before 52.0.2743.82 does not validate the origin of IPC messages to the plugin broker process that should h…

Fix: after 51.0.2704.106
Fix from $2,300 2016-07-23
Simatic Net Pc Software HIGH 7.5
CVE-2016-5874

Siemens SIMATIC NET PC-Software before 13 SP2 allows remote attackers to cause a denial of service (OPC UA service outage) via crafted TCP packets.

Fix: after 13
Fix from $1,950 2016-07-22
Simatic Batch CRITICAL 9.8
CVE-2016-5743EPSS 10%

Siemens SIMATIC WinCC before 7.3 Update 10 and 7.4 before Update 1, SIMATIC BATCH before 8.1 SP1 Update 9 as distributed in SIMATIC PCS 7 through 8.1…

Fix: after 8.2
Fix from $2,300 2016-07-22
Mac Os X HIGH 7.3
CVE-2016-4641

Login Window in Apple OS X before 10.11.6 allows attackers to execute arbitrary code in a privileged context or obtain sensitive user information via…

Fix: after 10.11.5
Fix from $1,950 2016-07-22
Iphone Os HIGH 7.8
CVE-2016-4594

The Sandbox Profiles component in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows attackers to access…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Safari MEDIUM 5.4
CVE-2016-4590

WebKit in Apple iOS before 9.3.3 and Safari before 9.1.2 mishandles about: URLs, which allows remote attackers to bypass the Same Origin Policy via a…

Fix: after 9.1.1
Fix from $1,600 2016-07-22
Fedora MEDIUM 5.9
CVE-2016-2775EPSS 63%

ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote at…

Patch available
Fix from $1,600 2016-07-19
Intelligent Management Center Application Performance Manager CRITICAL 9.8
CVE-2016-4372EPSS 19%

HPE iMC PLAT before 7.2 E0403P04, iMC EAD before 7.2 E0405P05, iMC APM before 7.2 E0401P04, iMC NTA before 7.2 E0401P01, iMC BIMS before 7.2 E0402P02…

Fix: after 7.2
Fix from $2,300 2016-07-15
Webex Meetings Server HIGH 7.5
CVE-2016-1450

Cisco WebEx Meetings Server 2.6 allows remote authenticated users to conduct command-injection attacks via vectors related to an upload's file type, …

Mitigation only
Fix from $1,950 2016-07-15
Amqp 0 X Jms Client HIGH 7.5
CVE-2016-4974EPSS 6%

Apache Qpid AMQP 0-x JMS client before 6.0.4 and JMS (AMQP 1.0) before 0.10.0 does not restrict the use of classes available on the classpath, which …

Fix: after 6.0.3
Fix from $1,950 2016-07-13
Ceph Storage Mon MEDIUM 6.5
CVE-2016-5009

The handle_command function in mon/Monitor.cc in Ceph allows remote authenticated users to cause a denial of service (segmentation fault and ceph mon…

Fix: after 0.94.6
Fix from $1,600 2016-07-12
Android HIGH 7.5
CVE-2016-3766

MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 do…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3760

Bluetooth in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows local users to gain privileges by establishing a pairin…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.0
CVE-2016-3757

The print_maps function in toolbox/lsof.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows user-…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3756

Tremolo/res012.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 does not validate the …

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3755

decoder/ih264d_parse_pslice.c in mediaserver in Android 6.x before 2016-07-01 does not properly select concealment frames, which allows remote attack…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.8
CVE-2016-3750

libs/binder/Parcel.cpp in the Parcels Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 d…

Mitigation only
Fix from $1,950 2016-07-11
Android CRITICAL 9.8
CVE-2016-3743

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-07-01 does not initialize certain data structures, which allows remote attackers to ex…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3742

decoder/ih264d_process_intra_mb.c in mediaserver in Android 6.x before 2016-07-01 mishandles intra mode, which allows remote attackers to execute arb…

Mitigation only
Fix from $2,300 2016-07-11
Android CRITICAL 9.8
CVE-2016-3741

The H.264 decoder in mediaserver in Android 6.x before 2016-07-01 does not initialize certain slice data, which allows remote attackers to execute ar…

Mitigation only
Fix from $2,300 2016-07-11
Debian Linux HIGH 7.8
CVE-2016-4324

Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesh…

Fix: after 5.1.3
Fix from $1,950 2016-07-08