Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Big Ip Advanced Firewall Manager MEDIUM 5.0
CVE-2015-4638

The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.…

Mitigation only
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5879

XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-n…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Commerce Commonwealth MEDIUM 5.0
CVE-2015-7231

The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a…

Patch available
Fix from $1,600 2015-09-17
Security Audit MEDIUM 6.8
CVE-2015-6828

The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress does not use an HTTPS session…

Fix: after 1.0.5
Fix from $1,600 2015-09-16
Bugzilla HIGH 7.5
CVE-2015-4499

Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco…

Patch available
Fix from $1,950 2015-09-14
Openldap MEDIUM 5.0
CVE-2015-6908EPSS 20%

The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable as…

Fix: after 10.11.1
Fix from $1,600 2015-09-11
Windows 10 HIGH 9.3
CVE-2015-2530EPSS 16%

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…

Patch available
Fix from $1,950 2015-09-09
Windows 10 HIGH 9.3
CVE-2015-2514EPSS 15%

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…

Patch available
Fix from $1,950 2015-09-09
Windows 10 HIGH 9.3
CVE-2015-2513EPSS 19%

Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a…

Patch available
Fix from $1,950 2015-09-09
Windows 10 HIGH 9.3
CVE-2015-2506EPSS 16%

atmfd.dll in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1…

Patch available
Fix from $1,950 2015-09-09
Ubuntu Linux HIGH 7.5
CVE-2015-6826

The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows …

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ffmpeg HIGH 7.5
CVE-2015-6825

The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows re…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ubuntu Linux HIGH 7.5
CVE-2015-6824

The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote at…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Ffmpeg HIGH 7.5
CVE-2015-6821

The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote…

Fix: after 2.7.1
Fix from $1,950 2015-09-06
Bind HIGH 7.1
CVE-2015-5986EPSS 26%

openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE …

Fix: after 9.10.2
Fix from $1,950 2015-09-05
Bind HIGH 7.8
CVE-2015-5722EPSS 34%

buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure…

Fix: after 9.10.2
Fix from $1,950 2015-09-05
Integrated Management Controller Supervisor HIGH 9.4
CVE-2015-6259

The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Uni…

Fix: after 5.2.0.0
Fix from $1,950 2015-09-04
Check Mk MEDIUM 5.5
CVE-2014-2332

Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, r…

Fix: after 1.2.3
Fix from $1,600 2015-08-31
Systems Insight Manager MEDIUM 6.5
CVE-2015-2140

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticate…

Fix: after 7.4
Fix from $1,600 2015-08-27
Openssh MEDIUM 6.4
CVE-2015-6563

The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, w…

Fix: after 10.11.0
Fix from $1,600 2015-08-24
Wireless Lan Controller Software MEDIUM 5.0
CVE-2015-6258

The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to …

Mitigation only
Fix from $1,600 2015-08-22
Asr 5000 Series Software MEDIUM 5.0
CVE-2015-6256

Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fiel…

Mitigation only
Fix from $1,600 2015-08-22
Documentum Content Server HIGH 9.0
CVE-2015-4534

Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 al…

Mitigation only
Fix from $1,950 2015-08-20
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2015-4329

The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary …

Mitigation only
Fix from $1,600 2015-08-20
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2015-4321

The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(…

Mitigation only
Fix from $1,600 2015-08-20
Telepresence Video Communication Server Software MEDIUM 5.5
CVE-2015-4316

The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly va…

Mitigation only
Fix from $1,600 2015-08-20
Telepresence Video Communication Server Software HIGH 7.2
CVE-2015-4327

The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script argum…

Mitigation only
Fix from $1,950 2015-08-20
Telepresence Video Communication Server Software MEDIUM 5.5
CVE-2015-4315

The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which…

Mitigation only
Fix from $1,600 2015-08-20
Iphone Os HIGH 7.2
CVE-2015-3805

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Iphone Os HIGH 7.2
CVE-2015-3803

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture execu…

Fix: after 10.10.4
Fix from $1,950 2015-08-17