Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.8 CVE-2016-5759 The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. Suse Linux Enterprise Desktop Mitigation only Fix from $1,9502017-09-08 MEDIUM 5.3 CVE-2017-12217 A vulnerability in the General Packet Radio Service (GPRS) Tunneling Protocol ingress packet handler of Cisco ASR 5500 System Architecture Evolution … Asr 5500 Firmware Mitigation only Fix from $1,6002017-09-07 MEDIUM 5.8 CVE-2017-12218 A vulnerability in the malware detection functionality within Advanced Malware Protection (AMP) of Cisco AsyncOS Software for Cisco Email Security Ap… Asyncos Mitigation only Fix from $1,6002017-09-07 MEDIUM 6.4 CVE-2017-12223 A vulnerability in the ROM Monitor (ROMMON) code of Cisco IR800 Integrated Services Router Software could allow an unauthenticated, local attacker to… Ir800 Integrated Services Router Firmware Mitigation only Fix from $1,6002017-09-07 MEDIUM 6.5 CVE-2017-6792 A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to ove… Prime Collaboration Provisioning Mitigation only Fix from $1,6002017-09-07 MEDIUM 6.7 CVE-2017-6794 A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and… Meeting Server Mitigation only Fix from $1,6002017-09-07 HIGH 8.8 CVE-2017-14169 In the mxf_read_primer_pack function in libavformat/mxfdec.c in FFmpeg 3.3.3 -> 2.4, an integer signedness error might occur when a crafted file, whi… Debian Linux Patch available Fix from $1,9502017-09-07 HIGH 8.8 CVE-2015-0853 svn-workbench 1.6.2 and earlier on a system with xeyes installed allows local users to execute arbitrary commands by using the "Command Shell" menu i… Svn Workbench after 1.6.2 Fix from $1,9502017-09-06 MEDIUM 5.3 CVE-2015-5186 Audit before 2.4.4 in Linux does not sanitize escape characters in filenames. Linux Audit after 2.4.3 Fix from $1,6002017-09-06 HIGH 7.5 CVE-2017-14098EPSS 47% In the pjsip channel driver (res_pjsip) in Asterisk 13.x before 13.17.1 and 14.x before 14.6.1, a carefully crafted tel URI in a From, To, or Contact… Asterisk Patch available Fix from $1,9502017-09-02 HIGH 7.5 CVE-2017-12874 The InfoCard module 1.0 for SimpleSAMLphp allows attackers to spoof XML messages by leveraging an incorrect check of return values in signature valid… Debian Linux Patch available Fix from $1,9502017-09-01 HIGH 7.8 CVE-2017-14105 HiveManager Classic through 8.1r1 allows arbitrary JSP code execution by modifying a backup archive before a restore, because the restore feature doe… Hivemanager Classic Patch available Fix from $1,9502017-09-01 HIGH 7.5 CVE-2017-12869 The multiauth module in SimpleSAMLphp 1.14.13 and earlier allows remote attackers to bypass authentication context restrictions and use an authentica… Debian Linux after 1.14.13 Fix from $1,9502017-09-01 MEDIUM 5.9 CVE-2017-3898 A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo… Livesafe after 16.0.2 Fix from $1,6002017-09-01 HIGH 7.5 CVE-2017-0900EPSS 8% RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clie… Debian Linux after 2.6.12 Fix from $1,9502017-08-31 HIGH 7.5 CVE-2017-0901EPSS 26% RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on th… Debian Linux Patch available Fix from $1,9502017-08-31 HIGH 7.5 CVE-2017-14063 Async Http Client (aka async-http-client) before 2.0.35 can be tricked into connecting to a host different from the one extracted by java.net.URI if … Async Http Client 2.0.35+ Fix from $1,9502017-08-31 MEDIUM 6.5 CVE-2017-9945 In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a speci… 7km Pac Switched Ethernet Profinet Expansion Module Firmware after 2.1.2 Fix from $1,6002017-08-30 HIGH 8.8 CVE-2016-4462 By manipulating the URL parameter externalLoginKey, a malicious, logged in user could pass valid Freemarker directives to the Template Engine that ar… Ofbiz Mitigation only Fix from $1,9502017-08-30 HIGH 7.5 CVE-2017-13767 In Wireshark 2.4.0, 2.2.0 to 2.2.8, and 2.0.0 to 2.0.14, the MSDP dissector could go into an infinite loop. This was addressed in epan/dissectors/pac… Wireshark Patch available Fix from $1,9502017-08-30 MEDIUM 6.1 CVE-2017-1428 IBM Cognos Analytics 11.0 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web … Cognos Analytics Patch available Fix from $1,6002017-08-29 HIGH 7.5 CVE-2015-5209EPSS 9% Apache Struts 2.x before 2.3.24.1 allows remote attackers to manipulate Struts internals, alter user sessions, or affect container settings via vecto… Struts Mitigation only Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-12775 qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts. Question2answer after 1.7.4 Fix from $1,9502017-08-29 HIGH 8.8 CVE-2017-10952EPSS 15% This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.2.0.2051. User interaction is requ… Foxit Reader No fix yet Fix from $1,9502017-08-29 MEDIUM 5.5 CVE-2017-13685 The dump_callback function in SQLite 3.20.0 allows remote attackers to cause a denial of service (EXC_BAD_ACCESS and application crash) via a crafted… SQLite Mitigation only Fix from $1,6002017-08-29 HIGH 7.5 CVE-2017-13735 There is a floating point exception in the kodak_radc_load_raw function in dcraw_common.cpp in LibRaw 0.18.2. It will lead to a remote denial of serv… Libraw Mitigation only Fix from $1,9502017-08-29 HIGH 7.5 CVE-2015-0234 Multiple temporary file creation vulnerabilities in pki-core 10.2.0. Pki Core Patch available Fix from $1,9502017-08-29 HIGH 7.5 CVE-2015-1554 kgb-bot 1.33-2 allows remote attackers to cause a denial of service (crash). Kgb Bot No fix yet Fix from $1,9502017-08-28 HIGH 8.8 CVE-2015-1443 The httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allows remote attackers to execute arbitrary code. Fli4l after 3.10.0 Fix from $1,9502017-08-28 HIGH 7.5 CVE-2017-13709 In FlightGear before version 2017.3.1, Main/logger.cxx in the FGLogger subsystem allows one to overwrite any file via a resource that affects the con… Flightgear No fix yet Fix from $1,9502017-08-27