Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2018-0020 Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a re… Junos Mitigation only Fix from $1,9502018-04-11 MEDIUM 5.3 CVE-2017-17308 SCCPX module in Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, … Dp300 Firmware Mitigation only Fix from $1,6002018-04-11 CRITICAL 9.8 CVE-2018-8954EPSS 7% CA Workload Control Center before r11.4 SP6 allows remote attackers to execute arbitrary code via a crafted HTTP request. Workload Control Center Mitigation only Fix from $2,3002018-04-11 CRITICAL 9.8 CVE-2017-18074 In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM… Mdm9607 Firmware Mitigation only Fix from $2,3002018-04-11 HIGH 7.5 CVE-2017-1081 In FreeBSD before 11.0-STABLE, 11.0-RELEASE-p10, 10.3-STABLE, and 10.3-RELEASE-p19, ipfilter using "keep state" or "keep frags" options can cause a k… FreeBSD after 11.0 Fix from $1,9502018-04-10 HIGH 8.1 CVE-2018-9327 Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document… Etherpad 1.6.4+ Fix from $1,9502018-04-07 HIGH 8.8 CVE-2018-9846 In Roundcube from versions 1.2.0 to 1.3.5, with the archive plugin enabled and configured, it's possible to exploit the unsanitized, user-controlled … Debian Linux after 1.3.5 Fix from $1,9502018-04-07 HIGH 7.8 CVE-2018-1000156EPSS 5% GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed)… Ubuntu Linux No fix yet Fix from $1,9502018-04-06 HIGH 7.5 CVE-2017-12088 An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below.… Micrologix 1400 B Firmware after 21.2 Fix from $1,9502018-04-05 MEDIUM 5.3 CVE-2018-9115EPSS 6% Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can f… Sitaware No fix yet Fix from $1,6002018-04-04 HIGH 7.5 CVE-2016-10235 A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#… Android Mitigation only Fix from $1,9502018-04-04 HIGH 7.8 CVE-2017-13287 In createFromParcel of VerifyCredentialResponse.java, there is a possible invalid parcel read due to improper input validation. This could lead to lo… Android Mitigation only Fix from $1,9502018-04-04 MEDIUM 5.3 CVE-2017-13295 A denial of service vulnerability in the Android framework (package installer). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. … Android Mitigation only Fix from $1,6002018-04-04 HIGH 7.5 CVE-2017-13300 A denial of service vulnerability in the Android media framework (libhevc). Product: Android. Versions: 6.0, 6.0.1. Android ID: A-71567394. Android Mitigation only Fix from $1,9502018-04-04 HIGH 7.5 CVE-2017-13301 A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-66498711. Android No fix yet Fix from $1,9502018-04-04 HIGH 7.5 CVE-2017-13302 A denial of service vulnerability in the Android system (system ui). Product: Android. Versions: 8.0. Android ID: A-69969749. Android Mitigation only Fix from $1,9502018-04-04 CRITICAL 9.8 CVE-2017-13284 In config_set_string of config.cc, it is possible to pair a second BT keyboard without user approval due to improper input validation. This could lea… Android Mitigation only Fix from $2,3002018-04-04 HIGH 7.5 CVE-2018-9256 In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting th… Wireshark after 2.4.5 Fix from $1,9502018-04-04 HIGH 7.5 CVE-2018-9258 In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources. Wireshark after 2.4.5 Fix from $1,9502018-04-04 HIGH 7.5 CVE-2018-9259 In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the b… Wireshark after 2.4.5 Fix from $1,9502018-04-04 HIGH 7.5 CVE-2018-9260 In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c b… Wireshark after 2.4.5 Fix from $1,9502018-04-04 HIGH 7.5 CVE-2018-9262 In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the VLAN dissector could crash. This was addressed in epan/dissectors/packet-vlan.c by limiting VLAN… Wireshark after 2.4.5 Fix from $1,9502018-04-04 HIGH 7.5 CVE-2016-10718EPSS 12% Brave Browser before 0.13.0 allows a tab to close itself even if the tab was not opened by a script, resulting in denial of service. Brave Browser 0.13.0+ Fix from $1,9502018-04-04 HIGH 7.5 CVE-2018-8049 The Stealth endpoint in Unisys Stealth SVG 2.8.x, 3.0.x before 3.0.1999, 3.1.x, 3.2.x before 3.2.030, and 3.3.x before 3.3.016, when running on Linux… Stealth Svg 3.0.1999 / 3.2.030+ Fix from $1,9502018-04-03 HIGH 7.5 CVE-2018-8779EPSS 7% In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1, the UNIXServer.open and UNIXSocket.open method… Ruby 2.2.10 / 2.3.7+ Fix from $1,9502018-04-03 CRITICAL 9.8 CVE-2017-18147 In Qualcomm Android for MSM, Firefox OS for MSM, and QRD Android with all Android releases from CAF using the Linux kernel before security patch leve… Android No fix yet Fix from $2,3002018-04-03 MEDIUM 5.5 CVE-2018-1099 DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser in… Etcd after 3.3.1 Fix from $1,6002018-04-03 HIGH 7.5 CVE-2016-7472 F5 BIG-IP ASM version 12.1.0 - 12.1.1 may allow remote attackers to cause a denial of service (DoS) via a crafted HTTP request. Big Ip Application Security Manager Mitigation only Fix from $1,9502018-04-03 HIGH 7.8 CVE-2018-4175 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "LaunchServices" component. It allows att… Mac Os X 10.13.4+ Fix from $1,9502018-04-03 MEDIUM 5.5 CVE-2018-4176 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "Disk Images" component. It allows attack… Mac Os X 10.13.4+ Fix from $1,6002018-04-03