Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2016-8218 An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validati… Cf Release after 203 Fix from $2,3002017-06-13 CRITICAL 9.8 CVE-2017-2773 An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23… Cloud Foundry Elastic Runtime Mitigation only Fix from $2,3002017-06-13 HIGH 7.5 CVE-2017-4994 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions pr… Cloud Foundry Uaa Bosh after 262 Fix from $1,9502017-06-13 MEDIUM 5.9 CVE-2017-6656 A vulnerability in Session Initiation Protocol (SIP) call handling of Cisco IP Phone 8800 Series devices could allow an unauthenticated, remote attac… Ip Phone 8800 Series Mitigation only Fix from $1,6002017-06-13 HIGH 8.8 CVE-2017-2179 Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a differe… Appgoat after 3.0.2 Fix from $1,9502017-06-09 MEDIUM 6.5 CVE-2016-7821 Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen v… Wnc01wh Firmware after 1.0.0.8 Fix from $1,6002017-06-09 HIGH 7.5 CVE-2015-1379 The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash). Socat after 1.7.2.4 Fix from $1,9502017-06-08 HIGH 7.5 CVE-2015-3913 The IP stack in multiple Huawei Campus series switch models allows remote attackers to cause a denial of service (reboot) via a crafted ICMP request … S2300 Firmware Mitigation only Fix from $1,9502017-06-08 HIGH 8.8 CVE-2014-3498 The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands. Ansible after 1.6.5 Fix from $1,9502017-06-08 HIGH 7.5 CVE-2017-9022 The gmp plugin in strongSwan before 5.5.3 does not properly validate RSA public keys before calling mpz_powm_sec, which allows remote peers to cause … Debian Linux after 5.5.2 Fix from $1,9502017-06-08 HIGH 7.8 CVE-2017-6638 A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to … Anyconnect Secure Mobility Client after 4.4.00243 Fix from $1,9502017-06-08 HIGH 7.5 CVE-2015-5175EPSS 9% Application plugins in Apache CXF Fediz before 1.1.3 and 1.2.x before 1.2.1 allow remote attackers to cause a denial of service. Cxf Fediz after 1.1.2 Fix from $1,9502017-06-07 MEDIUM 6.5 CVE-2015-8538 dwarf_leb.c in libdwarf allows attackers to cause a denial of service (SIGSEGV). Libdwarf after 2015-11-14 Fix from $1,6002017-06-07 CRITICAL 9.8 CVE-2016-6087 IBM Domino 8.5 and 9.0 could allow an attacker to steal credentials using multiple sessions and large amounts of data using Domino TLS Key Exchange v… Domino Patch available Fix from $2,3002017-06-07 HIGH 8.8 CVE-2016-9977 IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existi… Maximo Asset Management Patch available Fix from $1,9502017-06-07 HIGH 7.5 CVE-2017-7564 In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secu… Trusted Firmware A after 1.3 Fix from $1,9502017-06-07 MEDIUM 6.5 CVE-2015-3830 The stock Android browser address bar in all Android operating systems suffers from Address Bar Spoofing, which allows remote attackers to trick a vi… Android No fix yet Fix from $1,6002017-06-06 HIGH 8.2 CVE-2017-1000368 Todd Miller's sudo version 1.8.20p1 and earlier is vulnerable to an input validation (embedded newlines) in the get_process_ttyname() function result… Sudo after 1.8.20 Fix from $1,9502017-06-05 HIGH 7.5 CVE-2017-7669 In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. W… Hadoop Mitigation only Fix from $1,9502017-06-05 HIGH 7.5 CVE-2017-9350 In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors… Wireshark after 2.2.6 Fix from $1,9502017-06-02 HIGH 7.5 CVE-2017-9353EPSS 11% In Wireshark 2.2.0 to 2.2.6, the IPv6 dissector could crash. This was addressed in epan/dissectors/packet-ipv6.c by validating an IPv6 address. Wireshark after 2.2.6 Fix from $1,9502017-06-02 HIGH 7.5 CVE-2017-9354 In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the RGMP dissector could crash. This was addressed in epan/dissectors/packet-rgmp.c by validating an… Wireshark after 2.2.6 Fix from $1,9502017-06-02 HIGH 7.5 CVE-2017-9334 An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, wh… Chicken after 4.12.0 Fix from $1,9502017-06-01 MEDIUM 5.5 CVE-2017-4897 VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by t… Horizon Daas after 6.1.6 Fix from $1,6002017-05-31 MEDIUM 6.1 CVE-2017-9303 Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to condu… Laravel Mitigation only Fix from $1,6002017-05-29 MEDIUM 6.5 CVE-2017-9263 In Open vSwitch (OvS) 2.7.0, while parsing an OpenFlow role status message, there is a call to the abort() function for undefined role status reasons… Openvswitch Patch available Fix from $1,6002017-05-29 MEDIUM 5.5 CVE-2017-9242 The __ip6_append_data function in net/ipv6/ip6_output.c in the Linux kernel through 4.11.3 is too late in checking whether an overwrite of an skb dat… Linux Kernel after 4.11.3 Fix from $1,6002017-05-27 HIGH 7.2 CVE-2017-3134 An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'co… Fortiwlc Sd after 8.2.4 Fix from $1,9502017-05-27 CRITICAL 9.8 CVE-2017-9034EPSS 6% Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root… Serverprotect Patch available Fix from $2,3002017-05-26 MEDIUM 6.5 CVE-2016-2165 The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior … Cf Release after 231 Fix from $1,6002017-05-25