Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Windows 10 HIGH 7.8
CVE-2016-0091EPSS 24%

OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

Mitigation only
Fix from $1,950 2016-03-09
Chrome HIGH 8.8
CVE-2016-2844

WebKit/Source/core/layout/LayoutBlock.cpp in Blink, as used in Google Chrome before 49.0.2623.75, does not properly determine when anonymous block wr…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Prime Infrastructure HIGH 8.8
CVE-2016-1359

Cisco Prime Infrastructure 3.0 allows remote authenticated users to execute arbitrary code via a crafted HTTP request that is mishandled during viewi…

Mitigation only
Fix from $1,950 2016-03-03
Web Security Appliance MEDIUM 5.3
CVE-2016-1288

The HTTPS Proxy feature in Cisco AsyncOS before 8.5.3-051 and 9.x before 9.0.0-485 on Web Security Appliance (WSA) devices allows remote attackers to…

Mitigation only
Fix from $1,600 2016-03-03
Gs1900 10hp Firmware HIGH 7.5
CVE-2015-6260

Cisco NX-OS 7.1(1)N1(1) on Nexus 5500, 5600, and 6000 devices does not properly validate PDUs in SNMP packets, which allows remote attackers to cause…

Fix: 2.50+
Fix from $1,950 2016-03-03
phpMyAdmin MEDIUM 6.8
CVE-2016-2562

The checkHTTP function in libraries/Config.class.php in phpMyAdmin 4.5.x before 4.5.5.1 does not verify X.509 certificates from api.github.com SSL se…

Patch available
Fix from $1,600 2016-03-01
Wireshark MEDIUM 5.5
CVE-2016-2527

wiretap/nettrace_3gpp_32_423.c in the 3GPP TS 32.423 Trace file parser in Wireshark 2.0.x before 2.0.2 does not ensure that a '\0' character is prese…

Mitigation only
Fix from $1,600 2016-02-28
Wireshark MEDIUM 5.9
CVE-2016-2528

The dissect_nhdr_extopt function in epan/dissectors/packet-lbmc.c in the LBMC dissector in Wireshark 2.0.x before 2.0.2 does not validate length valu…

Mitigation only
Fix from $1,600 2016-02-28
Wireshark MEDIUM 5.9
CVE-2016-2526

epan/dissectors/packet-hiqnet.c in the HiQnet dissector in Wireshark 2.0.x before 2.0.2 does not validate the data type, which allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-28
Wireshark MEDIUM 5.9
CVE-2016-2525

epan/dissectors/packet-http2.c in the HTTP/2 dissector in Wireshark 2.0.x before 2.0.2 does not limit the amount of header data, which allows remote …

Mitigation only
Fix from $1,600 2016-02-28
Wireshark MEDIUM 5.9
CVE-2016-2524

epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers t…

Mitigation only
Fix from $1,600 2016-02-28
Squid HIGH 7.5
CVE-2016-2572EPSS 10%

http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2571EPSS 9%

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remo…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2570EPSS 9%

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows rem…

Patch available
Fix from $1,950 2016-02-27
Squid HIGH 7.5
CVE-2016-2569EPSS 31%

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of servic…

Patch available
Fix from $1,950 2016-02-27
Is My Json Valid HIGH 7.5
CVE-2016-2537

The is-my-json-valid package before 2.12.4 for Node.js has an incorrect exports['utc-millisec'] regular expression, which allows remote attackers to …

Fix: after 2.12.3
Fix from $1,950 2016-02-23
Line MEDIUM 5.7
CVE-2016-1156

LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash…

Fix: after 4.3.1
Fix from $1,600 2016-02-19
Debian Linux MEDIUM 6.8
CVE-2016-2270

Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO p…

Fix: after 4.6.1
Fix from $1,600 2016-02-19
Hp Ux Ipfilter MEDIUM 5.9
CVE-2016-1987

HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via uns…

Mitigation only
Fix from $1,600 2016-02-18
Small Business Wireless Access Points Firmware MEDIUM 5.3
CVE-2016-1334

Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 6.5
CVE-2016-1153

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service via unspecified vectors, a different v…

No fix yet
Fix from $1,600 2016-02-17
Office MEDIUM 6.5
CVE-2015-8489

customapp in Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to cause a denial of service (excessive database locking) via a cra…

Mitigation only
Fix from $1,600 2016-02-17
Emptoris Contract Management HIGH 7.5
CVE-2015-5042

IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0…

Mitigation only
Fix from $1,950 2016-02-15
Connect MEDIUM 5.3
CVE-2016-0950

Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.

Fix: after 9.5.2
Fix from $1,600 2016-02-10
Windows 10 HIGH 7.8
CVE-2016-0046EPSS 26%

Windows Reader in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remote attackers to execute arbitrary code via a craf…

Patch available
Fix from $1,950 2016-02-10
Windows 8.1 HIGH 7.5
CVE-2016-0044EPSS 14%

Sync Framework in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows RT 8.1 allows remote attackers to cause a denial of service (SyncShareSv…

Patch available
Fix from $1,950 2016-02-10
Jasper MEDIUM 6.5
CVE-2016-2089

The jas_matrix_clip function in jas_seq.c in JasPer 1.900.1 allows remote attackers to cause a denial of service (invalid read and application crash)…

Mitigation only
Fix from $1,600 2016-02-08
Bamboo CRITICAL 9.8
CVE-2015-8360

An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serializ…

Patch available
Fix from $2,300 2016-02-08
Bamboo CRITICAL 9.8
CVE-2014-9757

The Ignite Realtime Smack XMPP API, as used in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0, allows remote configured XMPP servers to execu…

Patch available
Fix from $2,300 2016-02-08
Simatic S7 1500 Cpu Firmware MEDIUM 5.3
CVE-2016-2201

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to bypass a replay protection mechanism via packets on TCP port 102.

Mitigation only
Fix from $1,600 2016-02-08