Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2018-6084 Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrar… Chrome 66.0.3359.117+ Fix from $1,9502019-01-09 MEDIUM 6.5 CVE-2018-16080 A missing check for popup window handling in Fullscreen in Google Chrome on macOS prior to 69.0.3497.81 allowed a remote attacker to spoof the conten… Chrome 69.0.3497.81+ Fix from $1,6002019-01-09 MEDIUM 6.5 CVE-2018-16088 A missing check for JS-simulated input events in Blink in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to download arbitrary files w… Chrome 69.0.3497.81+ Fix from $1,6002019-01-09 CRITICAL 9.6 CVE-2018-16068 Missing validation in Mojo in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTM… Chrome 69.0.3497.81+ Fix from $2,3002019-01-09 CRITICAL 9.6 CVE-2017-15402 Using an ID that can be controlled by a compromised renderer which allows any frame to overwrite the page_state of any other frame in the same proces… Chrome 62.0.3202.74+ Fix from $2,3002019-01-09 HIGH 7.5 CVE-2019-3581 Improper input validation in the proxy component of McAfee Web Gateway 7.8.2.0 and later allows remote attackers to cause a denial of service via a c… Mcafee Web Gateway 7.8.2.5 / 8.0.2.0+ Fix from $1,9502019-01-09 MEDIUM 5.5 CVE-2019-5716 In Wireshark 2.6.0 to 2.6.5, the 6LoWPAN dissector could crash. This was addressed in epan/dissectors/packet-6lowpan.c by avoiding use of a TVB befor… Wireshark after 2.6.5 Fix from $1,6002019-01-08 MEDIUM 5.5 CVE-2019-5717 In Wireshark 2.6.0 to 2.6.5 and 2.4.0 to 2.4.11, the P_MUL dissector could crash. This was addressed in epan/dissectors/packet-p_mul.c by rejecting t… Wireshark after 2.6.5 Fix from $1,6002019-01-08 HIGH 8.4 CVE-2019-0550 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g… Windows 10 Patch available Fix from $1,9502019-01-08 HIGH 8.4 CVE-2019-0551 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a g… Windows 10 Patch available Fix from $1,9502019-01-08 HIGH 7.8 CVE-2017-18320 QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions … Msm8996au Firmware Mitigation only Fix from $1,9502019-01-03 MEDIUM 6.5 CVE-2018-20662 In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of… Debian Linux Patch available Fix from $1,6002019-01-03 MEDIUM 5.5 CVE-2018-19478 In Artifex Ghostscript before 9.26, a carefully crafted PDF file can trigger an extremely long running computation when parsing the file. Debian Linux 9.26+ Fix from $1,6002019-01-02 HIGH 7.5 CVE-2018-20658EPSS 8% The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD comma… Core Ftp No fix yet Fix from $1,9502019-01-02 HIGH 7.8 CVE-2018-5197 A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command i… Xplatform Mitigation only Fix from $1,9502019-01-02 MEDIUM 6.5 CVE-2018-20650 A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data… Ubuntu Linux Patch available Fix from $1,6002019-01-01 CRITICAL 9.8 CVE-2018-6333 The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL c… Nuclide 0.290.0+ Fix from $2,3002018-12-31 HIGH 7.5 CVE-2018-6343 Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Cert… Proxygen 2018.11.19.00+ Fix from $1,9502018-12-31 HIGH 7.5 CVE-2018-6347 An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.1… Proxygen 2018.12.31.00+ Fix from $1,9502018-12-31 CRITICAL 9.8 CVE-2018-6334 Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before be… Hhvm after 3.25.1 Fix from $2,3002018-12-31 HIGH 7.5 CVE-2018-6335 A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affec… Hhvm after 3.21.10 Fix from $1,9502018-12-31 HIGH 7.5 CVE-2018-20614 public\install\install.php in CIM 0.9.3 allows remote attackers to reload the product via the public/install/#/step3 URI. Cim No fix yet Fix from $1,9502018-12-30 HIGH 7.5 CVE-2018-14988 The MXQ TV Box 4.4.2 Android device with a build fingerprint of MBX/m201_N/m201_N:4.4.2/KOT49H/20160106:user/test-keys contains the Android framework… Mxq Tv Box Firmware Mitigation only Fix from $1,9502018-12-28 HIGH 7.5 CVE-2018-20575 Orange Livebox 00.96.320S devices have an undocumented /system_firmwarel.stm URI for manual firmware update. This is related to Firmware 01.11.2017-1… Arv7519rw22 Livebox 2.1 Firmware No fix yet Fix from $1,9502018-12-28 MEDIUM 6.5 CVE-2018-20551 A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media ann… Ubuntu Linux Patch available Fix from $1,6002018-12-28 CRITICAL 9.8 CVE-2018-5203 DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary f… Dextuploadx5 after 2.2.0.0 Fix from $2,3002018-12-28 MEDIUM 6.5 CVE-2018-20539 There is a Segmentation fault triggered by illegal address access at liblas::SpatialReference::GetGTIF() (spatialreference.cpp) in libLAS 1.8.1 that … Liblas No fix yet Fix from $1,6002018-12-28 HIGH 8.1 CVE-2018-20519 An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intentio… 74cms No fix yet Fix from $1,9502018-12-27 MEDIUM 6.5 CVE-2018-19869 An issue was discovered in Qt before 5.11.3. A malformed SVG image causes a segmentation fault in qsvghandler.cpp. Qt 5.11.3+ Fix from $1,6002018-12-26 HIGH 7.5 CVE-2018-20404 ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which ca… Epia E900 Firmware No fix yet Fix from $1,9502018-12-26