Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Application Server Java HIGH 7.5
CVE-2016-3980EPSS 7%

The Java Startup Framework (aka jstart) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (process crash) via a cra…

Fix: after 7.4
Fix from $1,950 2016-04-08
Java As HIGH 7.5
CVE-2016-3979EPSS 6%

Internet Communication Manager (aka ICMAN or ICM) in SAP JAVA AS 7.2 through 7.4 allows remote attackers to cause a denial of service (heap memory co…

No fix yet
Fix from $1,950 2016-04-08
Debian Linux HIGH 7.3
CVE-2016-2098EPSS 81%

Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to execute arbitrary Ruby code by…

Fix: after 3.2.22.1
Fix from $1,950 2016-04-07
Jenkins HIGH 8.8
CVE-2016-0792EPSS 83%

Multiple unspecified API endpoints in Jenkins before 1.650 and LTS before 1.642.2 allow remote authenticated users to execute arbitrary code via seri…

Fix: after 1.649
Fix from $1,950 2016-04-07
Jenkins MEDIUM 6.1
CVE-2016-0789

CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitr…

Fix: after 1.649
Fix from $1,600 2016-04-07
P7 Firmware MEDIUM 5.5
CVE-2015-8305

Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted applicati…

Mitigation only
Fix from $1,600 2016-04-07
Clustered Data Ontap MEDIUM 6.8
CVE-2016-1563

NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…

Mitigation only
Fix from $1,600 2016-04-07
Evolved Programmable Network Manager CRITICAL 9.8
CVE-2016-1291EPSS 7%

Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allow remote attackers to execute arbitrary…

Mitigation only
Fix from $2,300 2016-04-06
Asa With Firepower Services HIGH 7.5
CVE-2016-1345

Cisco FireSIGHT System Software 5.4.0 through 6.0.1 and ASA with FirePOWER Services 5.4.0 through 6.0.0.1 allow remote attackers to bypass malware pr…

Mitigation only
Fix from $1,950 2016-04-01
iOS HIGH 7.5
CVE-2016-1351

The Locator/ID Separation Protocol (LISP) implementation in Cisco IOS 15.1 and 15.2 and NX-OS 4.1 through 6.2 allows remote attackers to cause a deni…

Mitigation only
Fix from $1,950 2016-03-26
Iphone Os MEDIUM 5.5
CVE-2016-1752

The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to cause a denial of service via a …

Fix: 2.2 / 9.2+
Fix from $1,600 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1747

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1746

IOGraphics in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corru…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Mac Os X HIGH 7.8
CVE-2016-1733

AppleRAID in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrup…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Ruby HIGH 8.4
CVE-2015-7551

The Fiddle::Handle implementation in ext/fiddle/handle.c in Ruby before 2.0.0-p648, 2.1 before 2.1.8, and 2.2 before 2.2.4, as distributed in Apple O…

Fix: after 10.11.3
Fix from $1,950 2016-03-24
Service Manager CRITICAL 9.8
CVE-2016-1998EPSS 7%

HPE Service Manager (SM) 9.3x before 9.35 P4 and 9.4x before 9.41.P2 allows remote attackers to execute arbitrary commands via a crafted serialized J…

Patch available
Fix from $2,300 2016-03-22
Operations Orchestration CRITICAL 9.8
CVE-2016-1997EPSS 7%

HPE Operations Orchestration 10.x before 10.51 and Operations Orchestration content before 1.7.0 allow remote attackers to execute arbitrary commands…

Fix: after 1.5.3
Fix from $2,300 2016-03-22
Android CRITICAL 9.8
CVE-2016-0815

The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H,…

Mitigation only
Fix from $2,300 2016-03-12
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2016-1338

Cisco TelePresence Video Communication Server (VCS) X8.5.1 and X8.5.2 allows remote authenticated users to cause a denial of service (VoIP outage) vi…

Mitigation only
Fix from $1,600 2016-03-12
Bind MEDIUM 6.8
CVE-2016-2088EPSS 23%

resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST a…

Mitigation only
Fix from $1,600 2016-03-09
Debian Linux MEDIUM 5.9
CVE-2016-2774EPSS 74%

ISC DHCP 4.1.x before 4.1-ESV-R13 and 4.2.x and 4.3.x before 4.3.4 does not restrict the number of concurrent TCP sessions, which allows remote attac…

Mitigation only
Fix from $1,600 2016-03-09
Acrobat HIGH 8.4
CVE-2016-1008

Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acroba…

Fix: after 15.010.20059
Fix from $1,950 2016-03-09
.net Framework CRITICAL 9.8
CVE-2016-0132EPSS 22%

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 mishandles signature validation for unspecified elements of XML document…

Mitigation only
Fix from $2,300 2016-03-09
Windows 10 HIGH 8.8
CVE-2016-0121EPSS 41%

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Go…

No fix yet
Fix from $1,950 2016-03-09
Windows 10 MEDIUM 6.5
CVE-2016-0120EPSS 39%

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Go…

No fix yet
Fix from $1,600 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0118EPSS 34%

The PDF library in Microsoft Windows 10 Gold and 1511 allows remote attackers to execute arbitrary code via a crafted PDF document, aka "Windows Remo…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0117EPSS 73%

The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 8.8
CVE-2016-0101EPSS 20%

Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 8.8
CVE-2016-0098EPSS 20%

Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 allow remote attack…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0092EPSS 58%

OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

Mitigation only
Fix from $1,950 2016-03-09