Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Simatic S7 1500 Cpu Firmware HIGH 7.5
CVE-2016-2200EPSS 6%

Siemens SIMATIC S7-1500 CPU devices before 1.8.3 allow remote attackers to cause a denial of service (STOP mode transition) via crafted packets on TC…

Fix: after 1.8.2
Fix from $1,950 2016-02-08
Android HIGH 8.8
CVE-2016-0802

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to ex…

Fix: after 10.11.3
Fix from $1,950 2016-02-07
Iphone Os CRITICAL 9.8
CVE-2016-0801EPSS 33%

The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to ex…

Fix: after 10.11.3
Fix from $2,300 2016-02-07
Bind MEDIUM 5.9
CVE-2016-1284

rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a den…

Mitigation only
Fix from $1,600 2016-02-04
Radicale CRITICAL 10.0
CVE-2015-8747

The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.

Fix: after 1.0.1
Fix from $2,300 2016-02-03
E5151 Firmware HIGH 7.5
CVE-2015-8265

Huawei Mobile WiFi E5151 routers with software before E5151s-2TCPU-V200R001B146D27SP00C00 and E5186 routers with software before V200R001B310D01SP00C…

Mitigation only
Fix from $1,950 2016-02-01
Firefox HIGH 7.4
CVE-2016-1942

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a …

Fix: after 43.0.4
Fix from $1,950 2016-01-31
500 Series Switch Firmware HIGH 7.5
CVE-2016-1303

The web GUI on Cisco Small Business 500 devices 1.2.0.92 allows remote attackers to cause a denial of service via a crafted HTTP request, aka Bug ID …

Mitigation only
Fix from $1,950 2016-01-30
Prosody MEDIUM 5.3
CVE-2016-0756

The generate_dialback function in the mod_dialback module in Prosody before 0.9.10 does not properly separate fields when generating dialback keys, w…

Fix: after 0.9.9
Fix from $1,600 2016-01-29
Curl MEDIUM 5.3
CVE-2016-0754

cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a rem…

Fix: after 7.46.0
Fix from $1,600 2016-01-29
Privoxy HIGH 7.5
CVE-2016-1983

The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an e…

Fix: after 3.0.23
Fix from $1,950 2016-01-27
Privoxy HIGH 7.5
CVE-2016-1982

The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read …

Fix: after 3.0.23
Fix from $1,950 2016-01-27
Chrome HIGH 7.6
CVE-2016-1612

The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility befo…

Fix: after 47.0.2526.106
Fix from $1,950 2016-01-25
Xen HIGH 8.5
CVE-2016-1570

The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, …

Mitigation only
Fix from $1,950 2016-01-22
Hana CRITICAL 9.3
CVE-2016-1929

The XS engine in SAP HANA allows remote attackers to spoof log entries in trace files and consequently cause a denial of service (disk consumption an…

Mitigation only
Fix from $2,300 2016-01-20
Bind HIGH 7.0
CVE-2015-8705EPSS 8%

buffer.c in named in ISC BIND 9.10.x before 9.10.3-P3, when debug logging is enabled, allows remote attackers to cause a denial of service (REQUIRE a…

Mitigation only
Fix from $1,950 2016-01-20
Bind MEDIUM 6.5
CVE-2015-8704EPSS 20%

apl_42.c in ISC BIND 9.x before 9.9.8-P3, 9.9.x, and 9.10.x before 9.10.3-P3 allows remote authenticated users to cause a denial of service (INSIST a…

Mitigation only
Fix from $1,600 2016-01-20
Tivoli Storage Manager MEDIUM 5.3
CVE-2015-4951

Client Acceptor Daemon (CAD) in the client in IBM Spectrum Protect (formerly Tivoli Storage Manager) 5.5 and 6.x before 6.3.2.5, 6.4 before 6.4.3.1, …

Patch available
Fix from $1,600 2016-01-20
Arcsight Logger MEDIUM 6.3
CVE-2015-6864

HPE ArcSight Logger before 6.1P1 allows remote authenticated users to execute arbitrary code via unspecified input to the (1) Intellicus or (2) clien…

Fix: after 6.1
Fix from $1,600 2016-01-16
Arcsight Logger HIGH 7.3
CVE-2015-6863

HPE ArcSight Logger before 6.1P1 allows remote attackers to execute arbitrary code via unspecified input to the (1) Intellicus or (2) client-certific…

Fix: after 6.1
Fix from $1,950 2016-01-16
Junos MEDIUM 5.9
CVE-2016-1262

Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.1X48 before 12.3X48-D20, and 15.1X49 before 15.1X49-D30 on SRX series devices, wh…

Fix: after 12.1x46
Fix from $1,600 2016-01-15
Junos MEDIUM 5.3
CVE-2016-1258

Embedthis Appweb, as used in J-Web in Juniper Junos OS before 12.1X44-D60, 12.1X46 before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R1…

Mitigation only
Fix from $1,600 2016-01-15
Junos MEDIUM 5.9
CVE-2016-1257

The Routing Engine in Juniper Junos OS 13.2R5 through 13.2R8, 13.3R1 before 13.3R8, 13.3R7 before 13.3R7-S3, 14.1R1 before 14.1R6, 14.1R3 before 14.1…

Mitigation only
Fix from $1,600 2016-01-15
Gajim MEDIUM 5.4
CVE-2015-8688

Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.

Fix: after 0.16.4
Fix from $1,600 2016-01-15
Debian Linux MEDIUM 6.5
CVE-2015-8605EPSS 76%

ISC DHCP 4.x before 4.1-ESV-R12-P1, 4.2.x, and 4.3.x before 4.3.3-P1 allows remote attackers to cause a denial of service (application crash) via an …

Fix: after 9.353
Fix from $1,600 2016-01-14
Firebird MEDIUM 6.5
CVE-2016-1569

FireBird 2.5.5 allows remote authenticated users to cause a denial of service (daemon crash) by using service manager to invoke the gbak utility with…

No fix yet
Fix from $1,600 2016-01-13
Rsa MEDIUM 5.3
CVE-2016-1494EPSS 7%

The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via craft…

Fix: 3.3+
Fix from $1,600 2016-01-13
Ubuntu Linux HIGH 7.3
CVE-2015-8607

The canonpath function in the File::Spec module in PathTools before 3.62, as used in Perl, does not properly preserve the taint attribute of data, wh…

Fix: after 3.61
Fix from $1,950 2016-01-13
Fedora HIGH 7.4
CVE-2015-8466

Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header.

Fix: after 1.8
Fix from $1,950 2016-01-13
Vcn500 HIGH 7.4
CVE-2015-8331

The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 does not properly invalidate the session ID when an …

Mitigation only
Fix from $1,950 2016-01-11