Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Prime Network Analysis Module Software HIGH 8.8
CVE-2016-1391

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) be…

Mitigation only
Fix from $1,950 2016-06-04
Prime Network Analysis Module Software HIGH 7.8
CVE-2016-1390

Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) be…

Mitigation only
Fix from $1,950 2016-06-04
Accelerator Application HIGH 7.5
CVE-2016-3944

UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi…

Mitigation only
Fix from $1,950 2016-06-03
Satellite HIGH 8.1
CVE-2016-0363

The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be…

Mitigation only
Fix from $1,950 2016-06-03
Network Analysis Module Software MEDIUM 5.3
CVE-2016-1370

Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of serv…

Mitigation only
Fix from $1,600 2016-06-03
Qpid Broker J MEDIUM 5.9
CVE-2016-3094EPSS 8%

PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a…

Fix: after 6.0.2
Fix from $1,600 2016-06-01
iOS HIGH 7.5
CVE-2016-1409

The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows…

Mitigation only
Fix from $1,950 2016-05-29
Fedora HIGH 7.5
CVE-2015-8853

The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a de…

Fix: after 5.23.9
Fix from $1,950 2016-05-25
Ios Xr HIGH 7.5
CVE-2016-1407

Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2016-05-25
Telepresence Video Communication Server HIGH 7.5
CVE-2016-1400

Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via…

Mitigation only
Fix from $1,950 2016-05-25
Web Security Appliance \(wsa\) HIGH 7.5
CVE-2016-1382

Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allo…

Mitigation only
Fix from $1,950 2016-05-25
Web Security Appliance HIGH 7.5
CVE-2016-1380

Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) …

Mitigation only
Fix from $1,950 2016-05-25
Shareit HIGH 8.8
CVE-2016-4782

Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent sc…

Mitigation only
Fix from $1,950 2016-05-23
S12700 Firmware HIGH 8.1
CVE-2016-4087

Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enable…

Mitigation only
Fix from $1,950 2016-05-23
Quagga HIGH 7.5
CVE-2016-4049

The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to …

Mitigation only
Fix from $1,950 2016-05-23
Go HIGH 7.5
CVE-2016-3959

The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer libra…

Fix: after 1.5
Fix from $1,950 2016-05-23
Debian Linux HIGH 7.5
CVE-2016-4348

The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and a…

Fix: after 2.40.1
Fix from $1,950 2016-05-20
Curl MEDIUM 5.3
CVE-2016-3739EPSS 7%

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7…

Patch available
Fix from $1,600 2016-05-20
Debian Linux HIGH 7.5
CVE-2015-7558

librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via …

Fix: after 2.40.11
Fix from $1,950 2016-05-20
Librsvg HIGH 7.5
CVE-2015-7557

The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (ou…

Fix: after 2.40.6
Fix from $1,950 2016-05-20
PHP CRITICAL 9.8
CVE-2016-4072EPSS 6%

The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fi…

Fix: after 10.11.4
Fix from $2,300 2016-05-20
PHP CRITICAL 9.8
CVE-2016-4071EPSS 19%

Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows …

Fix: after 10.11.4
Fix from $2,300 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1843

The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via u…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 8.8
CVE-2016-1800

Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitra…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Jansson MEDIUM 6.5
CVE-2016-4425

Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JS…

Fix: after 2.7
Fix from $1,600 2016-05-17
Ubuntu Linux HIGH 7.5
CVE-2016-3705EPSS 5%

The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth…

Mitigation only
Fix from $1,950 2016-05-17
PHP HIGH 7.5
CVE-2015-4605EPSS 7%

The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, d…

Fix: after 5.4.39
Fix from $1,950 2016-05-16
PHP HIGH 7.5
CVE-2015-4604EPSS 7%

The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, do…

Fix: after 5.4.39
Fix from $1,950 2016-05-16
Enterprise Linux Desktop MEDIUM 6.5
CVE-2015-4598

PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers…

Fix: after 5.4.41
Fix from $1,600 2016-05-16
Enterprise Linux MEDIUM 6.5
CVE-2015-3411

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …

Fix: after 5.4.39
Fix from $1,600 2016-05-16