Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Wireshark MEDIUM 5.9
CVE-2016-4083

epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation…

Mitigation only
Fix from $1,600 2016-04-25
Wireshark MEDIUM 5.9
CVE-2016-4078

The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote att…

Mitigation only
Fix from $1,600 2016-04-25
Foxit Reader HIGH 7.5
CVE-2016-4061

Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content str…

Fix: after 7.3.0.118
Fix from $1,950 2016-04-22
Wireless Lan Controller Software HIGH 7.5
CVE-2016-1364

Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a d…

Mitigation only
Fix from $1,950 2016-04-21
Squid MEDIUM 5.9
CVE-2016-2390EPSS 26%

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when …

Fix: after 3.5.13
Fix from $1,600 2016-04-19
Ar3200 Firmware MEDIUM 6.5
CVE-2016-3950

Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted pack…

Mitigation only
Fix from $1,600 2016-04-18
Fedora HIGH 7.5
CVE-2016-3071

Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.

Mitigation only
Fix from $1,950 2016-04-18
Debian Linux MEDIUM 6.5
CVE-2016-1654

The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a …

Fix: after 49.0.2623.112
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-2424

server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 6.2
CVE-2016-2414

The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in f…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 6.5
CVE-2016-2411

A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverag…

Mitigation only
Fix from $1,600 2016-04-18
Android HIGH 8.4
CVE-2016-0834

An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of ser…

Mitigation only
Fix from $1,950 2016-04-18
Ubuntu Linux MEDIUM 5.5
CVE-2016-3961

Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a d…

Fix: after 4.5.3
Fix from $1,600 2016-04-15
Fedora HIGH 7.5
CVE-2016-2145

The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows rem…

Fix: after 0.11.0
Fix from $1,950 2016-04-15
Junos HIGH 7.8
CVE-2016-1271

Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.…

Fix: after 12.1x46
Fix from $1,950 2016-04-15
Screenos HIGH 7.5
CVE-2016-1268

The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra…

Mitigation only
Fix from $1,950 2016-04-15
Emc Unisphere CRITICAL 9.8
CVE-2016-0889

An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a cr…

Fix: after 8.1
Fix from $2,300 2016-04-15
Debian Linux HIGH 8.8
CVE-2016-3069

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.

Patch available
Fix from $1,950 2016-04-13
Debian Linux HIGH 8.8
CVE-2016-3068EPSS 5%

Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.

Patch available
Fix from $1,950 2016-04-13
Git CRITICAL 9.8
CVE-2015-7545EPSS 19%

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x befo…

Fix: after 2.3.9
Fix from $2,300 2016-04-13
Mate S Firmware MEDIUM 6.1
CVE-2015-8682

The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C0…

Mitigation only
Fix from $1,600 2016-04-13
Ios Xr MEDIUM 5.3
CVE-2016-1376

Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and inte…

Mitigation only
Fix from $1,600 2016-04-12
Xml Core Services HIGH 8.8
CVE-2016-0147EPSS 16%

Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulner…

Mitigation only
Fix from $1,950 2016-04-12
Pan Os CRITICAL 9.8
CVE-2016-3655

The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remo…

Fix: 5.0.18 / 5.1.11+
Fix from $2,300 2016-04-12
Pan Os HIGH 7.2
CVE-2016-3654

The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before…

Fix: 5.0.18 / 5.1.11+
Fix from $1,950 2016-04-12
Struts HIGH 8.8
CVE-2016-0785EPSS 9%

Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva…

Fix: 2.3.20.3+
Fix from $1,950 2016-04-12
Ofbiz CRITICAL 9.8
CVE-2016-2170EPSS 13%

Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o…

Fix: 12.04.06 / 13.07.03+
Fix from $2,300 2016-04-12
Debian Linux HIGH 8.6
CVE-2015-8702

The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid cha…

Fix: after 2.0.18
Fix from $1,950 2016-04-12
S5300 Firmware HIGH 7.5
CVE-2016-3678

Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service…

Mitigation only
Fix from $1,950 2016-04-11
Perl HIGH 7.5
CVE-2016-2381EPSS 9%

Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp.

Fix: 5.23.9 / 12.1.2.0.4+
Fix from $1,950 2016-04-08