Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Brackets CRITICAL 9.8
CVE-2016-4165

The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input.

Fix: after 1.6
Fix from $2,300 2016-06-16
Windows 10 MEDIUM 5.0
CVE-2016-3230

The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10…

Mitigation only
Fix from $1,600 2016-06-16
Jscript HIGH 7.5
CVE-2016-3207EPSS 17%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Jscript HIGH 7.5
CVE-2016-3206EPSS 15%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Jscript HIGH 7.5
CVE-2016-3205EPSS 15%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Mitigation only
Fix from $1,950 2016-06-16
Edge HIGH 7.8
CVE-2016-3203EPSS 33%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2016-06-16
Chakra Javascript HIGH 7.5
CVE-2016-3202EPSS 17%

The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allo…

Mitigation only
Fix from $1,950 2016-06-16
Office HIGH 7.3
CVE-2016-0025EPSS 15%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Ma…

Mitigation only
Fix from $1,950 2016-06-16
Ubuntu Linux HIGH 7.5
CVE-2016-4579

Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "ret…

Fix: after 1.3.3
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 7.5
CVE-2016-4353

ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (a…

Fix: after 1.3.2
Fix from $1,950 2016-06-13
Bladelogic Server Automation Console HIGH 7.5
CVE-2016-1542EPSS 75%

The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers t…

Patch available
Fix from $1,950 2016-06-13
Android MEDIUM 5.5
CVE-2016-2495

SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow…

Mitigation only
Fix from $1,600 2016-06-13
Android HIGH 7.8
CVE-2016-2487

libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2486

mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 do…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2480

The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does n…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2478

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2477

mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2…

Mitigation only
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2475

The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allo…

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2464

libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attacke…

Mitigation only
Fix from $1,950 2016-06-13
Opensuse HIGH 7.5
CVE-2016-3706EPSS 6%

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attack…

Fix: 2.23+
Fix from $1,950 2016-06-10
Puppet Agent CRITICAL 9.8
CVE-2016-2786

The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…

Mitigation only
Fix from $2,300 2016-06-10
Aironet Access Point Software HIGH 8.1
CVE-2016-1419

Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka…

Mitigation only
Fix from $1,950 2016-06-10
Debian Linux HIGH 7.1
CVE-2016-4449

XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, …

Fix: after 2.9.3
Fix from $1,950 2016-06-09
Universal Cmbd Foundation CRITICAL 9.8
CVE-2016-4368

HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remo…

Mitigation only
Fix from $2,300 2016-06-08
Aironet Access Point Software HIGH 7.8
CVE-2016-1418

Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root ac…

Mitigation only
Fix from $1,950 2016-06-08
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2016-4545

Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Tra…

Mitigation only
Fix from $1,950 2016-06-07
Struts MEDIUM 5.3
CVE-2016-3093EPSS 8%

Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca…

Fix: after 3.0.11
Fix from $1,600 2016-06-07
Struts CRITICAL 9.8
CVE-2016-3087EPSS 82%

Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec…

No fix yet
Fix from $2,300 2016-06-07
Debian Linux CRITICAL 9.8
CVE-2014-9746

The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t…

Fix: after 2.5.3
Fix from $2,300 2016-06-07
Ip Phone 8800 Series Firmware HIGH 7.8
CVE-2016-1403

CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug…

Mitigation only
Fix from $1,950 2016-06-04