Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Wireshark MEDIUM 5.5
CVE-2015-8717

The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative me…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8716

The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conver…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8715

epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote a…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8714

The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certa…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8713

epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings,…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8712

The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not vali…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-8711

epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, whi…

Mitigation only
Fix from $1,600 2016-01-04
Wireshark MEDIUM 5.5
CVE-2015-3182

epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, whic…

Mitigation only
Fix from $1,600 2016-01-04
Rational Quality Manager MEDIUM 6.8
CVE-2015-1928

Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and…

Mitigation only
Fix from $1,600 2016-01-02
Wrt300n Dd Firmware MEDIUM 5.8
CVE-2015-7282

ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to s…

Mitigation only
Fix from $1,600 2015-12-31
Orientdb MEDIUM 6.1
CVE-2015-2918

The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, whic…

Mitigation only
Fix from $1,600 2015-12-31
Cg Wlncm4g Firmware MEDIUM 5.8
CVE-2015-7794

Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafte…

Mitigation only
Fix from $1,600 2015-12-30
Debian Linux MEDIUM 5.4
CVE-2015-5296EPSS 7%

Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
A840 Telemetry Gateway Base Station Firmware HIGH 8.7
CVE-2015-7931

The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attac…

Mitigation only
Fix from $1,950 2015-12-24
Kea MEDIUM 6.8
CVE-2015-8373

The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-12-22
Vcenter Orchestrator HIGH 7.3
CVE-2015-6934EPSS 5%

Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCen…

Mitigation only
Fix from $1,950 2015-12-21
Prime Network Services Controller HIGH 7.2
CVE-2015-6426

Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional p…

Mitigation only
Fix from $1,950 2015-12-18
Cool Video Gallery HIGH 7.5
CVE-2015-7527EPSS 5%

lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Wi…

No fix yet
Fix from $1,950 2015-12-17
Joomla\! HIGH 7.5
CVE-2015-8565

Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow…

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8564

Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences …

Mitigation only
Fix from $1,950 2015-12-16
Joomla\! HIGH 7.5
CVE-2015-8562EPSS 98%

Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U…

No fix yet
Fix from $1,950 2015-12-16
Debian Linux MEDIUM 5.0
CVE-2015-8476

Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) ema…

Fix: after 5.2.13
Fix from $1,600 2015-12-16
Linux MEDIUM 5.0
CVE-2015-8000EPSS 55%

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion fai…

Patch available
Fix from $1,600 2015-12-16
Fedora MEDIUM 6.8
CVE-2015-7216

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote atta…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7211

Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified…

Fix: after 42.0
Fix from $1,600 2015-12-16
Spa500 Firmware HIGH 7.2
CVE-2015-6403

The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows …

Mitigation only
Fix from $1,950 2015-12-15
Dpc3939 Wireless Residential Voice Gateway Firmware MEDIUM 6.5
CVE-2015-6361

The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary com…

Mitigation only
Fix from $1,600 2015-12-13
Tvos HIGH 9.3
CVE-2015-7079

dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged cont…

Fix: after 9.1
Fix from $1,950 2015-12-11
Iphone Os HIGH 9.3
CVE-2015-7072

dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code…

Fix: after 9.1
Fix from $1,950 2015-12-11
Watchos HIGH 7.2
CVE-2015-7047

The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted …

Fix: after 10.11.1
Fix from $1,950 2015-12-11