Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2017-5944 The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remote authen… Request Tracker Mitigation only Fix from $1,9502017-07-03 MEDIUM 6.5 CVE-2017-2298 The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compro… Mcollective Sshkey Security after 0.5.0 Fix from $1,6002017-06-30 MEDIUM 5.5 CVE-2017-10674 Antiy Antivirus Engine 5.0.0.06281654 allows local users to cause a denial of service (BSOD) via a long third argument in a DeviceIoControl call. Antivirus Engine Mitigation only Fix from $1,6002017-06-30 HIGH 7.5 CVE-2017-10688EPSS 6% In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A crafted input will lead to a… Libtiff No fix yet Fix from $1,9502017-06-29 CRITICAL 9.8 CVE-2017-4997 EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exp… Emc Vasa Provider Virtual Appliance after 8.3.0 Fix from $2,3002017-06-29 HIGH 8.8 CVE-2014-8149 OpenDaylight defense4all 1.1.0 and earlier allows remote authenticated users to write report data to arbitrary files. Defense4all after 1.1.0 Fix from $1,9502017-06-27 HIGH 7.5 CVE-2015-2245 Huawei Ascend P7 allows remote attackers to cause a denial of service (phone process crash). P7 L09 Firmware No fix yet Fix from $1,9502017-06-27 HIGH 7.5 CVE-2017-9982 TeamSpeak Client 3.0.19 allows remote attackers to cause a denial of service (application crash) via the ᗪ Unicode character followed by the &#… Teamspeak Client No fix yet Fix from $1,9502017-06-27 MEDIUM 6.5 CVE-2017-7522EPSS 5% OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service by authenticated remote attacker via sending a certificate with a… Openvpn after 2.3.16 Fix from $1,6002017-06-27 HIGH 7.5 CVE-2015-3215 The NetKVM Windows Virtio driver allows remote attackers to cause a denial of service (guest crash) via a crafted length value in an IP packet, as de… Virtio Win Patch available Fix from $1,9502017-06-26 HIGH 8.0 CVE-2017-6662 A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an aut… Evolved Programmable Network Manager Mitigation only Fix from $1,9502017-06-26 MEDIUM 5.7 CVE-2017-9773 Denial of Service was found in Horde_Image 2.x before 2.5.0 via a crafted URL to the "Null" image driver. Horde Image No fix yet Fix from $1,6002017-06-21 MEDIUM 5.5 CVE-2017-9778 GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file ca… Gdb after 8.0 Fix from $1,6002017-06-21 CRITICAL 9.8 CVE-2017-3098EPSS 6% Adobe Captivate versions 9 and earlier have a remote code execution vulnerability in the quiz reporting feature that could be abused to read and writ… Captivate after 9.0 Fix from $2,3002017-06-20 CRITICAL 9.8 CVE-2017-9741 install/make-config.php in ProjectSend r754 allows remote attackers to execute arbitrary PHP code via the dbprefix parameter, related to replacing TA… Projectsend No fix yet Fix from $2,3002017-06-18 MEDIUM 6.5 CVE-2015-3254 The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vecto… Thrift after 0.9.2 Fix from $1,6002017-06-16 HIGH 7.5 CVE-2017-9675EPSS 9% On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot. Dir 605l Firmware No fix yet Fix from $1,9502017-06-15 MEDIUM 6.5 CVE-2017-8545 A spoofing vulnerability exists in when Microsoft Outlook for Mac does not sanitize html properly, aka "Microsoft Outlook for Mac Spoofing Vulnerabil… Outlook Patch available Fix from $1,6002017-06-15 CRITICAL 9.8 CVE-2017-7676 Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '*' wildcard character - like my*test, test*.txt. This can result in u… Ranger after 0.7.0 Fix from $2,3002017-06-14 MEDIUM 5.5 CVE-2016-10337 In all Android releases from CAF using the Linux kernel, some validation of secure applications was not being performed. Android No fix yet Fix from $1,6002017-06-13 HIGH 7.8 CVE-2016-10338 In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing. Android No fix yet Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2017-7366 In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters. Android Patch available Fix from $1,6002017-06-13 HIGH 7.8 CVE-2017-7369 In all Android releases from CAF using the Linux kernel, an array index in an ALSA routine is not properly validating potentially leading to kernel s… Android Patch available Fix from $1,9502017-06-13 HIGH 7.8 CVE-2014-9962 In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of a DRM provisioning command. Android No fix yet Fix from $1,9502017-06-13 HIGH 7.8 CVE-2014-9965 In all Android releases from CAF using the Linux kernel, a vulnerability exists in the parsing of an SCM call. Android No fix yet Fix from $1,9502017-06-13 HIGH 7.8 CVE-2015-9033 In all Android releases from CAF using the Linux kernel, a QTEE system call fails to validate a pointer. Android Mitigation only Fix from $1,9502017-06-13 CRITICAL 9.8 CVE-2017-6667 A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthentic… Context Service Development Kit Mitigation only Fix from $2,3002017-06-13 HIGH 7.5 CVE-2017-6671 A vulnerability in the email message scanning of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remo… Email Security Appliance Firmware Mitigation only Fix from $1,9502017-06-13 HIGH 7.5 CVE-2017-6674 A vulnerability in the feature-license management functionality of Cisco Firepower System Software could allow an unauthenticated, remote attacker to… Firesight System Mitigation only Fix from $1,9502017-06-13 HIGH 7.5 CVE-2017-6680 A vulnerability in the AutoVNF logging function of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to create arbitrary… Ultra Services Framework Mitigation only Fix from $1,9502017-06-13