Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Enterprise Linux Desktop Supplementary MEDIUM 6.5
CVE-2016-1665

The JSGenericLowering class in compiler/js-generic-lowering.cc in Google V8, as used in Google Chrome before 50.0.2661.94, mishandles comparison oper…

Fix: after 50.0.2661.87
Fix from $1,600 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.0
CVE-2016-1661

Blink, as used in Google Chrome before 50.0.2661.94, does not ensure that frames satisfy a check for the same renderer process in addition to a Same …

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Enterprise Linux Desktop Supplementary HIGH 8.8
CVE-2016-1660

Blink, as used in Google Chrome before 50.0.2661.94, mishandles assertions in the WTF::BitArray and WTF::double_conversion::Vector classes, which all…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Ninja Forms CRITICAL 9.8
CVE-2016-1209EPSS 62%

The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via crafted serialized values in…

Fix: after 2.9.42
Fix from $2,300 2016-05-14
Big Ip Access Policy Manager MEDIUM 5.9
CVE-2015-8099

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and …

Mitigation only
Fix from $1,600 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9764

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a crafted GIF file.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2014-9762

imlib2 before 1.4.7 allows remote attackers to cause a denial of service (segmentation fault) via a GIF image without a colormap.

Fix: after 1.4.6
Fix from $1,950 2016-05-13
Fedora HIGH 7.5
CVE-2016-2850

Botan 1.11.x before 1.11.29 does not enforce TLS policy for (1) signature algorithms and (2) ECC curves, which allows remote attackers to conduct dow…

Mitigation only
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2016-2194

The ressol function in Botan before 1.10.11 and 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (infinite loop) via unspec…

Fix: after 1.10.10
Fix from $1,950 2016-05-13
Debian Linux HIGH 7.5
CVE-2015-5726

The BER decoder in Botan 0.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (application crash) via…

Mitigation only
Fix from $1,950 2016-05-13
Fpwin Pro MEDIUM 5.5
CVE-2016-4498

Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows local users to cause a denial of service or possibly…

Mitigation only
Fix from $1,600 2016-05-12
Coldfusion MEDIUM 5.9
CVE-2016-1115

Adobe ColdFusion 10 before Update 19, 11 before Update 8, and 2016 before Update 1 mishandles wildcards in name fields of X.509 certificates, which m…

Mitigation only
Fix from $1,600 2016-05-11
Ubuntu Linux HIGH 7.5
CVE-2016-4555EPSS 54%

client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge S…

Patch available
Fix from $1,950 2016-05-10
Ubuntu Linux HIGH 7.5
CVE-2016-4476

hostapd 0.6.7 through 2.5 and wpa_supplicant 0.6.7 through 2.5 do not reject \n and \r characters in passphrase parameters, which allows remote attac…

Fix: after 2.5
Fix from $1,950 2016-05-09
Android MEDIUM 5.5
CVE-2016-2454

The Qualcomm hardware video codec in Android before 2016-05-01 on Nexus 5 devices allows remote attackers to cause a denial of service (reboot) via a…

Fix: after 6.0.1
Fix from $1,600 2016-05-09
Libarchive HIGH 8.8
CVE-2016-1541EPSS 10%

Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attack…

Fix: after 3.1.901a
Fix from $1,950 2016-05-07
Livesafe HIGH 7.5
CVE-2016-4535EPSS 10%

Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (mem…

No fix yet
Fix from $1,950 2016-05-05
Ubuntu Linux HIGH 8.4
CVE-2016-3714 KEVEPSS 97%

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1…

Fix: after 6.9.3-9
Fix from $1,950 2016-05-05
Linux Kernel HIGH 7.8
CVE-2015-8019

The skb_copy_and_csum_datagram_iovec function in net/core/datagram.c in the Linux kernel 3.14.54 and 3.18.22 does not accept a length argument, which…

Mitigation only
Fix from $1,950 2016-05-02
Linux Kernel MEDIUM 5.5
CVE-2015-2672

The xsave/xrstor implementation in arch/x86/include/asm/xsave.h in the Linux kernel before 3.19.2 creates certain .altinstr_replacement pointers and …

Fix: after 3.19.1
Fix from $1,600 2016-05-02
Linux Kernel MEDIUM 5.5
CVE-2008-7316

mm/filemap.c in the Linux kernel before 2.6.25 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers…

Fix: after 2.6.24
Fix from $1,600 2016-05-02
Wireshark MEDIUM 5.9
CVE-2016-4421

epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.12.x before 1.12.10 and 2.x before 2.0.2 allows remote attackers to cause a de…

Mitigation only
Fix from $1,600 2016-05-01
Wireshark MEDIUM 5.9
CVE-2016-4420

The NFS dissector in Wireshark 2.x before 2.0.2 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

Mitigation only
Fix from $1,600 2016-05-01
Linux Kernel MEDIUM 6.2
CVE-2016-2548

sound/core/timer.c in the Linux kernel before 4.4.1 retains certain linked lists after a close or stop action, which allows local users to cause a de…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 6.2
CVE-2016-2549

sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of servi…

Fix: after 4.4
Fix from $1,600 2016-04-27
Linux Kernel HIGH 7.8
CVE-2016-2143

The fork implementation in the Linux kernel before 4.5 on s390 platforms mishandles the case of four page-table levels, which allows local users to c…

Fix: 3.2.79 / 3.12.58+
Fix from $1,950 2016-04-27
Linux Kernel MEDIUM 6.8
CVE-2016-0774

The (1) pipe_read and (2) pipe_write implementations in fs/pipe.c in a certain Linux kernel backport in the linux package before 3.2.73-2+deb7u3 on D…

Fix: after 6.0.1
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.5
CVE-2015-8844

The signal implementation in the Linux kernel before 4.3.5 on powerpc platforms does not check for an MSR with both the S and T bits set, which allow…

Fix: after 4.3.4
Fix from $1,600 2016-04-27
Struts CRITICAL 9.8
CVE-2016-3082EPSS 19%

XSLTResult in Apache Struts 2.x before 2.3.20.2, 2.3.24.x before 2.3.24.2, and 2.3.28.x before 2.3.28.1 allows remote attackers to execute arbitrary …

Patch available
Fix from $2,300 2016-04-26
Debian Linux MEDIUM 5.9
CVE-2016-4085

Stack-based buffer overflow in epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 1.12.x before 1.12.11 allows remote attackers to …

Mitigation only
Fix from $1,600 2016-04-25