Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Iphone Os HIGH 7.2
CVE-2015-3802

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Mac Os X HIGH 7.2
CVE-2015-3760

dyld in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unspecifie…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Office HIGH 9.3
CVE-2015-2466EPSS 17%

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted template, aka "Microso…

Mitigation only
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2464EPSS 36%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Fix: after 5.1.40416.0
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2463EPSS 34%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Fix: after 5.1.40416.0
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2462EPSS 36%

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win…

Patch available
Fix from $1,950 2015-08-15
Windows 10 HIGH 9.3
CVE-2015-2461EPSS 36%

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win…

Patch available
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2460EPSS 31%

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win…

Patch available
Fix from $1,950 2015-08-15
Windows 10 HIGH 9.3
CVE-2015-2459EPSS 32%

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win…

Patch available
Fix from $1,950 2015-08-15
Windows 10 HIGH 9.3
CVE-2015-2458EPSS 32%

ATMFD.DLL in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win…

Patch available
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2456EPSS 36%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Fix: after 5.1.40416.0
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2455EPSS 37%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Fix: after 5.1.40416.0
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2435EPSS 22%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Fix: after 5.1.40416.0
Fix from $1,950 2015-08-15
Live Meeting HIGH 9.3
CVE-2015-2431EPSS 30%

Microsoft Office 2007 SP3 and 2010 SP2, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee, Lync 2013 SP1, and Lync Basic 2013 SP1 allow remote…

No fix yet
Fix from $1,950 2015-08-15
Netvault Backup MEDIUM 5.0
CVE-2015-5696EPSS 8%

Dell Netvault Backup before 10.0.5 allows remote attackers to cause a denial of service (crash) via a crafted request.

Fix: after 10.0.1.24
Fix from $1,600 2015-08-14
Bootstrap Dht HIGH 7.5
CVE-2015-5685EPSS 6%

The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet,…

Patch available
Fix from $1,950 2015-08-13
Fortios MEDIUM 5.0
CVE-2015-5965

The SSL-VPN feature in Fortinet FortiOS before 4.3.13 only checks the first byte of the TLS MAC in finished messages, which makes it easier for remot…

Fix: after 4.3.12
Fix from $1,600 2015-08-11
Endpoint Protection Manager HIGH 8.5
CVE-2015-1492

Untrusted search path vulnerability in the client in Symantec Endpoint Protection 12.1 before 12.1-RU6-MP1 allows local users to gain privileges via …

Mitigation only
Fix from $1,950 2015-08-01
Endpoint Protection Manager MEDIUM 5.5
CVE-2015-1487EPSS 52%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to write to arbitrar…

No fix yet
Fix from $1,600 2015-08-01
Unified Computing System Central Software MEDIUM 5.0
CVE-2015-4286

The web framework in Cisco UCS Central Software 1.3(0.99) allows remote attackers to read arbitrary files via a crafted HTTP request, aka Bug ID CSCu…

Mitigation only
Fix from $1,600 2015-07-29
Yoyaku HIGH 7.5
CVE-2015-2977

Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.

No fix yet
Fix from $1,950 2015-07-29
Gazou Bbs Plus MEDIUM 5.0
CVE-2015-2974

LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving a crafted image file.

Fix: after 2.35
Fix from $1,600 2015-07-29
Chrome HIGH 7.5
CVE-2015-1284

The LocalFrame::isURLAllowed function in core/frame/LocalFrame.cpp in Blink, as used in Google Chrome before 44.0.2403.89, does not properly check fo…

Fix: after 43.0.2357.134
Fix from $1,950 2015-07-23
Ios Xr MEDIUM 5.0
CVE-2015-4284

The Concurrent Data Management Replication process in Cisco IOS XR 5.3.0 on ASR 9000 devices allows remote attackers to cause a denial of service (BG…

Mitigation only
Fix from $1,600 2015-07-22
HTTP Server MEDIUM 5.0
CVE-2015-3183EPSS 73%

The chunked transfer coding implementation in the Apache HTTP Server before 2.4.14 does not properly parse chunk headers, which allows remote attacke…

Fix: 2.2.31 / 2.4.16+
Fix from $1,600 2015-07-20
Blackberry Link MEDIUM 6.8
CVE-2015-4111

mc_demux_mp4_ds.ax in an unspecified third-party codec demux in BlackBerry Link before 1.2.3.53 with installer before 1.1.0.22 allows remote attacker…

Fix: after 1.2.3.52
Fix from $1,600 2015-07-20
Db2 MEDIUM 6.8
CVE-2015-0157

IBM DB2 9.7 through FP10, 9.8 through FP5, 10.1 before FP5, and 10.5 through FP5 on Linux, UNIX, and Windows allows remote authenticated users to cau…

Patch available
Fix from $1,600 2015-07-20
Videoscape Distribution Suite Service Broker HIGH 7.8
CVE-2015-0725

Cisco Videoscape Distribution Suite Service Broker (aka VDS-SB), when a VDSM configuration on UCS is used, and Videoscape Distribution Suite for Inte…

Patch available
Fix from $1,950 2015-07-16
Sicam Mic Firmware HIGH 9.3
CVE-2015-5386

Siemens SICAM MIC devices with firmware before 2404 allow remote attackers to bypass authentication and obtain administrative access via unspecified …

Fix: after 2403
Fix from $1,950 2015-07-16
Webex Meetings Server MEDIUM 6.5
CVE-2015-4276

Cisco WebEx Meetings Server 2.5MR1 allows remote authenticated users to execute arbitrary code via a crafted command parameter, aka Bug ID CSCus56138.

Mitigation only
Fix from $1,600 2015-07-16