Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Cognos Disclosure Management HIGH 9.3
CVE-2015-5014

IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an execut…

Patch available
Fix from $1,950 2015-10-26
Mac Os X HIGH 7.2
CVE-2015-5945

The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Iphone Os HIGH 7.1
CVE-2015-7004

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

Fix: after 9.0.2
Fix from $1,950 2015-10-23
Screenos MEDIUM 5.0
CVE-2015-7750

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3…

Fix: after 6.3.0
Fix from $1,600 2015-10-19
Junos HIGH 7.8
CVE-2015-7749

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspeci…

Fix: after 15.1x49
Fix from $1,950 2015-10-19
Junos MEDIUM 5.0
CVE-2015-7748

Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R…

Mitigation only
Fix from $1,600 2015-10-19
Asr 5000 Software MEDIUM 5.0
CVE-2015-6334

Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process rest…

Mitigation only
Fix from $1,600 2015-10-16
Storage Manager HIGH 10.0
CVE-2015-7838

ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.

Fix: after 6.1
Fix from $1,950 2015-10-15
Telepresence Video Communication Server Software MEDIUM 6.9
CVE-2015-6318

Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified sy…

Mitigation only
Fix from $1,600 2015-10-12
Vcenter Server MEDIUM 5.0
CVE-2015-1047

vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartb…

Patch available
Fix from $1,600 2015-10-12
Chrome HIGH 7.5
CVE-2015-1303

bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information a…

Fix: after 45.0.2454.93
Fix from $1,950 2015-10-12
Enterprise Linux Desktop MEDIUM 6.8
CVE-2015-5234

IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app…

Fix: after 1.5.2
Fix from $1,600 2015-10-09
Ubuntu Linux MEDIUM 6.8
CVE-2015-1337

Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk imag…

No fix yet
Fix from $1,600 2015-10-09
Mac Os X MEDIUM 5.0
CVE-2015-5883

The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting ch…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Safari HIGH 10.0
CVE-2015-5780

The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has u…

Fix: after 8.0.8
Fix from $1,950 2015-10-09
Android HIGH 10.0
CVE-2015-6598

libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via …

Fix: after 5.1
Fix from $1,950 2015-10-06
Email Address HIGH 7.8
CVE-2015-7686

Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial o…

Fix: after 1.908
Fix from $1,950 2015-10-06
Enterprise Linux Desktop MEDIUM 6.8
CVE-2014-9751

The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr…

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Enterprise Linux Desktop MEDIUM 5.8
CVE-2014-9750EPSS 6%

ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from …

Fix: 4.2.8+
Fix from $1,600 2015-10-06
Android HIGH 9.3
CVE-2015-6602

libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demo…

Fix: after 5.1.1
Fix from $1,950 2015-10-02
Android HIGH 9.3
CVE-2015-3876

libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file.

Fix: after 5.1.1
Fix from $1,950 2015-10-02
Android HIGH 9.3
CVE-2015-3837

The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data…

Fix: after 5.1
Fix from $1,950 2015-10-01
Notebook MEDIUM 6.8
CVE-2015-7337

The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via …

Fix: after 3.2.1
Fix from $1,600 2015-09-29
X2crm HIGH 7.5
CVE-2015-5074EPSS 8%

Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.…

Fix: after 5.0.8
Fix from $1,950 2015-09-29
iOS HIGH 7.8
CVE-2015-6279

The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE…

Mitigation only
Fix from $1,950 2015-09-28
iOS HIGH 7.8
CVE-2015-6278

The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE…

Mitigation only
Fix from $1,950 2015-09-28
Ios Xe HIGH 7.8
CVE-2015-6282

Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers t…

Mitigation only
Fix from $1,950 2015-09-26
Web Studio HIGH 7.5
CVE-2015-7375

Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime e…

Fix: after 7.1.3.6
Fix from $1,950 2015-09-25
Web Studio HIGH 7.5
CVE-2015-7374

The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vec…

Fix: after 7.1.3.6
Fix from $1,950 2015-09-25
Flash Player HIGH 10.0
CVE-2015-5568EPSS 20%

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…

Fix: after 18.0.0.199
Fix from $1,950 2015-09-22