Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Office HIGH 9.3
CVE-2015-6172EPSS 54%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2016, Word 2013 RT SP1, and Office Compatibility Pack SP3 allow remote a…

Mitigation only
Fix from $1,950 2015-12-09
Unified Security Gateway Firmware HIGH 7.1
CVE-2015-8084

Huawei USG5500, USG2100, USG2200, and USG5100 unified security gateways with software before V300R001C10SPC600, when "DHCP Snooping" is enabled and e…

Mitigation only
Fix from $1,950 2015-12-07
Networker HIGH 7.8
CVE-2015-6849

EMC NetWorker before 8.0.4.5, 8.1.x before 8.1.3.6, 8.2.x before 8.2.2.2, and 9.0 before build 407 allows remote attackers to cause a denial of servi…

Mitigation only
Fix from $1,950 2015-12-05
iOS HIGH 7.2
CVE-2015-6385

The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbit…

Mitigation only
Fix from $1,950 2015-12-01
Vp 9660 Firmware HIGH 8.5
CVE-2015-8227

The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote administrators to obtain sensi…

Mitigation only
Fix from $1,950 2015-11-24
Vbulletin HIGH 7.5
CVE-2015-7808EPSS 81%

The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks an…

No fix yet
Fix from $1,950 2015-11-24
Mac Os X HIGH 7.5
CVE-2015-7036EPSS 39%

The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or …

Fix: after 10.10.3
Fix from $1,950 2015-11-22
Espace Firmware MEDIUM 5.0
CVE-2015-7845

The exception handling mechanism in the CLI Module in Huawei eSpace U1910, U1911, U1930, U1960, U1980, and U1981 unified gateways with software befor…

Mitigation only
Fix from $1,600 2015-11-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-8023

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly val…

Mitigation only
Fix from $1,600 2015-11-18
Firesight System Software MEDIUM 6.8
CVE-2015-6357

The rule-update feature in Cisco FireSIGHT Management Center (MC) 5.2 through 5.4.0.1 does not verify the X.509 certificate of the support.sourcefire…

No fix yet
Fix from $1,600 2015-11-18
Authoritative MEDIUM 5.0
CVE-2015-5311EPSS 67%

PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash)…

Patch available
Fix from $1,600 2015-11-17
Ffmpeg HIGH 7.5
CVE-2015-8219

The init_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.8.2 does not enforce minimum-value and maximum-value constraints on tile coordi…

Fix: after 2.8.1
Fix from $1,950 2015-11-17
Ffmpeg MEDIUM 6.8
CVE-2015-8218

The decode_uncompressed function in libavcodec/faxcompr.c in FFmpeg before 2.8.2 does not validate uncompressed runs, which allows remote attackers t…

Fix: after 2.8.1
Fix from $1,600 2015-11-17
Ffmpeg HIGH 7.5
CVE-2015-8217

The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote atta…

Fix: after 2.8.1
Fix from $1,950 2015-11-17
Linux Kernel MEDIUM 5.0
CVE-2015-8215

net/ipv6/addrconf.c in the IPv6 stack in the Linux kernel before 4.0 does not validate attempted changes to the MTU value, which allows context-depen…

Fix: after 3.19
Fix from $1,600 2015-11-16
Windows 7 MEDIUM 5.8
CVE-2015-6112

SChannel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2015-11-11
Windows 10 HIGH 9.3
CVE-2015-6104EPSS 35%

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Ser…

Patch available
Fix from $1,950 2015-11-11
Windows 10 HIGH 9.3
CVE-2015-6103EPSS 35%

The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Ser…

Patch available
Fix from $1,950 2015-11-11
Chrome HIGH 7.5
CVE-2015-1302

The PDF viewer in Google Chrome before 46.0.2490.86 does not properly restrict scripting messages and API exposure, which allows remote attackers to …

Fix: after 46.0.2490.80
Fix from $1,950 2015-11-11
Hana HIGH 7.5
CVE-2015-7994

The SQL interface in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary code via unspecified vectors related t…

No fix yet
Fix from $1,950 2015-11-10
Hana HIGH 7.5
CVE-2015-7993

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to execute arbitrary …

No fix yet
Fix from $1,950 2015-11-10
Hana HIGH 10.0
CVE-2015-7828EPSS 7%

SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified o…

Fix: after 1.00
Fix from $1,950 2015-11-10
Openjdk HIGH 10.0
CVE-2014-8873

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, …

Mitigation only
Fix from $1,950 2015-11-09
Big Ip Application Acceleration Manager MEDIUM 6.1
CVE-2015-6546

The vCMP host in F5 BIG-IP Analytics, APM, ASM, GTM, Link Controller, and LTM 11.0.0 before 11.6.0, BIG-IP AAM 11.4.0 before 11.6.0, BIG-IP AFM and P…

Mitigation only
Fix from $1,600 2015-11-06
Sonicwall Totalsecure Tz 100 Firmware MEDIUM 5.0
CVE-2015-7770

Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.

Fix: after 5.9.1.0
Fix from $1,600 2015-11-06
Email Security Appliance HIGH 7.8
CVE-2015-6291

Cisco AsyncOS before 8.5.7-043, 9.x before 9.1.1-023, and 9.5.x and 9.6.x before 9.6.0-046 on Email Security Appliance (ESA) devices mishandles malfo…

Mitigation only
Fix from $1,950 2015-11-06
Smartviewer MEDIUM 6.8
CVE-2015-8040

The rtsp_getdlsendtime method in the CNC_Ctrl control in Samsung SmartViewer allows remote attackers to execute arbitrary code via an index value.

Mitigation only
Fix from $1,600 2015-11-02
Xen HIGH 7.2
CVE-2015-7835

The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV gues…

Mitigation only
Fix from $1,950 2015-10-30
Asr 5000 Software MEDIUM 5.0
CVE-2015-6351

Cisco ASR 5500 System Architecture Evolution (SAE) Gateway devices with software 19.1.0.61559 and 19.2.0 allow remote attackers to cause a denial of …

Mitigation only
Fix from $1,600 2015-10-30
Owncloud Server HIGH 9.0
CVE-2015-7699

The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate a…

Patch available
Fix from $1,950 2015-10-26