Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Unified Web And E Mail Interaction Manager MEDIUM 6.8
CVE-2015-0753

SQL injection vulnerability in Cisco Unified Email Interaction Manager (EIM) and Unified Web Interaction Manager (WIM) 9.0(2) allows remote attackers…

Mitigation only
Fix from $1,600 2015-05-29
Unified Communications Manager HIGH 7.8
CVE-2015-0751

Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service vi…

Mitigation only
Fix from $1,950 2015-05-29
Steam Client MEDIUM 5.0
CVE-2015-4016

The client detection protocol in Valve Steam allows remote attackers to cause a denial of service (process crash) via a crafted response to a broadca…

Fix: 2015-05-13+
Fix from $1,600 2015-05-20
Debian Linux MEDIUM 5.0
CVE-2015-1261

android/java/src/org/chromium/chrome/browser/WebsiteSettingsPopup.java in Google Chrome before 43.0.2357.65 on Android does not properly restrict use…

Fix: after 42.0.2311.107
Fix from $1,600 2015-05-20
Wide Area Application Services MEDIUM 5.0
CVE-2015-0730

The SMB module in Cisco Wide Area Application Services (WAAS) 6.0(1) allows remote attackers to cause a denial of service (module reload) via an inva…

Mitigation only
Fix from $1,600 2015-05-16
Wireless Lan Controller Software MEDIUM 6.8
CVE-2015-0726

The web administration interface on Cisco Wireless LAN Controller (WLC) devices before 7.0.241, 7.1.x through 7.4.x before 7.4.122, and 7.5.x and 7.6…

Mitigation only
Fix from $1,600 2015-05-16
Unified Communications Manager MEDIUM 6.9
CVE-2015-0717

Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug…

Mitigation only
Fix from $1,600 2015-05-16
Yceb03 Firmware MEDIUM 6.8
CVE-2014-1901

Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 …

Mitigation only
Fix from $1,600 2015-05-14
Sharepoint Foundation MEDIUM 6.0
CVE-2015-1700EPSS 12%

Microsoft SharePoint Server 2007 SP3, SharePoint Foundation 2010 SP2, SharePoint Server 2010 SP2, and SharePoint Foundation 2013 SP1 allow remote aut…

Mitigation only
Fix from $1,600 2015-05-13
Unified Computing System Central Software HIGH 10.0
CVE-2015-0701

Cisco UCS Central Software before 1.3(1a) allows remote attackers to execute arbitrary commands via a crafted HTTP request, aka Bug ID CSCut46961.

Mitigation only
Fix from $1,950 2015-05-07
Unified Meetingplace HIGH 9.0
CVE-2015-0702

Unrestricted file upload vulnerability in the Custom Prompts upload implementation in Cisco Unified MeetingPlace 8.6(1.9) allows remote authenticated…

Mitigation only
Fix from $1,950 2015-04-21
Thinkserver System Manager Baseboard Management Controller Firmware MEDIUM 5.0
CVE-2015-3323

The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350…

Fix: after 118.71532.
Fix from $1,600 2015-04-16
Web Security Appliance HIGH 7.2
CVE-2015-0693

Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel…

Mitigation only
Fix from $1,950 2015-04-15
Adaptive Security Appliance Software HIGH 7.8
CVE-2015-0677

The XML parser in Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.28), 8.6 before 8.6(1.17), 9.0 before 9.0(4.33), 9.1 before 9.1(6…

Mitigation only
Fix from $1,950 2015-04-13
Adaptive Security Appliance Software HIGH 7.1
CVE-2015-0676

The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 befo…

Mitigation only
Fix from $1,950 2015-04-13
Asa With Firepower Services HIGH 7.8
CVE-2015-0678

The virtualization layer in Cisco ASA FirePOWER Software before 5.3.1.2 and 5.4.x before 5.4.0.1 and ASA Context-Aware (CX) Software before 9.3.2.1-9…

Mitigation only
Fix from $1,950 2015-04-11
Mac Os X MEDIUM 6.8
CVE-2015-1139

ImageIO in Apple OS X before 10.10.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted…

Fix: 10.10.3+
Fix from $1,600 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1135

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1134

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1133

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 10.0
CVE-2015-1132

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.2
CVE-2015-1131

fontd in Apple Type Services (ATS) in Apple OS X before 10.10.3 allows local users to gain privileges via unspecified vectors, a different vulnerabil…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1104EPSS 7%

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly determine whether an IPv6 packet had a local…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1105EPSS 9%

The TCP implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly implement the Urge…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Iphone Os HIGH 7.5
CVE-2015-1103

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 makes routing changes in response to ICMP_REDIRECT messages, w…

Fix: after 10.10.2
Fix from $1,950 2015-04-10
Mac Os X HIGH 7.1
CVE-2015-1102

The kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 does not properly handle TCP headers, which allows man-in-the-…

Fix: after 10.10.2
Fix from $1,950 2015-04-10
Iphone Os MEDIUM 6.8
CVE-2015-1088

CFURL in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly validate URLs, which allows remote attackers to execute arbitrary code …

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Tvos MEDIUM 6.9
CVE-2015-1086

The Audio Drivers subsystem in Apple iOS before 8.3 and Apple TV before 7.2 does not properly validate IOKit object metadata, which allows attackers …

Fix: after 8.2
Fix from $1,600 2015-04-10
Ios Xe HIGH 7.8
CVE-2015-0685

Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service…

Fix: after 3.7s.4
Fix from $1,950 2015-04-03
Sql Anywhere MEDIUM 5.0
CVE-2015-2819

SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.

No fix yet
Fix from $1,600 2015-04-01