Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.0 CVE-2017-0613 An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t… Linux Kernel Patch available Fix from $1,9502017-05-12 HIGH 7.0 CVE-2017-0620 An elevation of privilege vulnerability in the Qualcomm Secure Channel Manager driver could enable a local malicious application to execute arbitrary… Linux Kernel after 7.1.2 Fix from $1,9502017-05-12 MEDIUM 5.9 CVE-2017-0280EPSS 8% The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows… Windows 10 Patch available Fix from $1,6002017-05-12 MEDIUM 5.9 CVE-2017-0269EPSS 7% The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows… Windows 10 Patch available Fix from $1,6002017-05-12 MEDIUM 5.9 CVE-2017-0273EPSS 7% The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows… Windows 10 Patch available Fix from $1,6002017-05-12 HIGH 7.3 CVE-2017-0249EPSS 8% An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Asp.net Model View Controller No fix yet Fix from $1,9502017-05-12 MEDIUM 5.3 CVE-2017-0256EPSS 5% A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests. Asp.net Model View Controller Mitigation only Fix from $1,6002017-05-12 HIGH 7.5 CVE-2017-0247EPSS 17% A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-pa… Asp.net Model View Controller Patch available Fix from $1,9502017-05-12 MEDIUM 5.9 CVE-2017-0171 Windows DNS Server allows a denial of service vulnerability when Microsoft Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 Gold and R2, and W… Windows Server 2008 Patch available Fix from $1,6002017-05-12 HIGH 7.6 CVE-2017-0212 Windows Hyper-V allows an elevation of privilege vulnerability when Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 fail to … Windows 10 Patch available Fix from $1,9502017-05-12 MEDIUM 5.9 CVE-2017-5948 An issue was discovered on OnePlus One, X, 2, 3, and 3T devices. OxygenOS and HydrogenOS are vulnerable to downgrade attacks. This is due to a lenien… Oxygenos No fix yet Fix from $1,6002017-05-11 HIGH 7.5 CVE-2016-7476 The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, APM, ASM, GTM, Link Controller, PEM, PSM, and WebSafe 11.6.0 before 11.6.0 HF6, … Big Ip Websafe Mitigation only Fix from $1,9502017-05-11 MEDIUM 6.5 CVE-2017-6865 A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET… Pcs 7 Mitigation only Fix from $1,6002017-05-11 MEDIUM 5.5 CVE-2016-10371 The TIFFWriteDirectoryTagCheckedRational function in tif_dirwrite.c in LibTIFF 4.0.6 allows remote attackers to cause a denial of service (assertion … Libtiff Mitigation only Fix from $1,6002017-05-10 HIGH 7.8 CVE-2017-0346 All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where… Gpu Driver Mitigation only Fix from $1,9502017-05-09 HIGH 7.8 CVE-2017-0350 All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where a value passed from a user to the driver… Gpu Driver Mitigation only Fix from $1,9502017-05-09 MEDIUM 5.5 CVE-2017-0353 All versions of the NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgDdiEscape where due to improper locking… Gpu Driver Mitigation only Fix from $1,6002017-05-09 MEDIUM 5.5 CVE-2017-0355 All versions of the NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer handler for DxgkDdiEscape where it may access … Gpu Driver Mitigation only Fix from $1,6002017-05-09 HIGH 7.5 CVE-2016-9253 In F5 BIG-IP 12.1.0 through 12.1.2, specific websocket traffic patterns may cause a disruption of service for virtual servers configured to use the w… Big Ip Local Traffic Manager Mitigation only Fix from $1,9502017-05-09 MEDIUM 5.3 CVE-2016-6877 Citrix XenMobile Server before 10.5.0.24 allows man-in-the-middle attackers to trigger HTTP 302 redirections via vectors involving the HTTP Host head… Xenmobile Server after 10.3.6.310 Fix from $1,6002017-05-05 HIGH 8.6 CVE-2016-9692 IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-suppli… Websphere Cast Iron Solution Patch available Fix from $1,9502017-05-05 HIGH 7.5 CVE-2017-3733EPSS 7% During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this… OpenSSL Patch available Fix from $1,9502017-05-04 MEDIUM 5.8 CVE-2017-6620 A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated,… Small Business Rv Series Router Firmware Mitigation only Fix from $1,6002017-05-03 MEDIUM 5.3 CVE-2017-7428 NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat. Imanager No fix yet Fix from $1,6002017-05-03 CRITICAL 9.8 CVE-2016-10243EPSS 6% TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file. Debian Linux Patch available Fix from $2,3002017-05-02 CRITICAL 9.8 CVE-2017-6551 Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Co… Pexip Infinity after 14.1 Fix from $2,3002017-05-02 HIGH 7.5 CVE-2017-8396 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the ex… Binutils Patch available Fix from $1,9502017-05-01 HIGH 7.8 CVE-2017-7721 IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file. Irfanview after 4.44 Fix from $1,9502017-04-30 HIGH 7.5 CVE-2017-7957 XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during… Fuse after 1.4.9 Fix from $1,9502017-04-29 HIGH 7.5 CVE-2017-2153 SEIL/x86 Fuji 1.70 to 5.62, SEIL/BPV4 5.00 to 5.62, SEIL/X1 1.30 to 5.62, SEIL/X2 1.30 to 5.62, SEIL/B1 1.00 to 5.62 allows remote attackers to cause… X86 Fuji Firmware Mitigation only Fix from $1,9502017-04-28