Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 7.5 CVE-2016-4547 Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to … Samsung Mobile Mitigation only Fix from $1,9502017-02-13 HIGH 7.5 CVE-2016-6129 The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equ… Op Tee 2.2.0+ Fix from $1,9502017-02-13 MEDIUM 5.9 CVE-2017-3896 Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remo… Mcafee Agent Mitigation only Fix from $1,6002017-02-13 MEDIUM 5.9 CVE-2017-5589 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Bruno Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5590 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Chatsecure after 1.0.11 Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5591 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Sleekxmpp after 1.3.1 Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5592 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Profanity Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5593 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Psi\+ Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5602 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Jappix Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5603 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Jitsi Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5604 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Mcabber Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5605 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Movim Patch available Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5606 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Xabber after 1.0.30 Fix from $1,6002017-02-09 MEDIUM 5.9 CVE-2017-5858 An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including conta… Converse.js Patch available Fix from $1,6002017-02-09 MEDIUM 5.3 CVE-2016-9686 The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preve… Puppet Enterprise 2016.4.3+ Fix from $1,6002017-02-08 HIGH 7.5 CVE-2017-0422 A denial of service vulnerability in Bionic DNS could enable a remote attacker to use a specially crafted network packet to cause a device hang or re… Android Mitigation only Fix from $1,9502017-02-08 HIGH 7.5 CVE-2016-6131 The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the ref… Libiberty Patch available Fix from $1,9502017-02-07 HIGH 7.5 CVE-2016-7164 The construct function in puff.cpp in Libtorrent 1.1.0 allows remote torrent trackers to cause a denial of service (segmentation fault and crash) via… Libtorrent Patch available Fix from $1,9502017-02-07 MEDIUM 5.5 CVE-2016-5102 Buffer overflow in the readgifimage function in gif2tiff.c in the gif2tiff tool in LibTIFF 4.0.6 allows remote attackers to cause a denial of service… Libtiff after 4.0.6 Fix from $1,6002017-02-06 MEDIUM 5.5 CVE-2010-5328 include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero from reaching the swapper proces… Linux Kernel after 2.6.34.7 Fix from $1,6002017-02-06 MEDIUM 6.5 CVE-2017-5880 Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x … Splunk Patch available Fix from $1,6002017-02-04 HIGH 8.1 CVE-2016-6500 Unspecified methods in the RACF Connector component before 1.1.1.0 in ForgeRock OpenIDM and OpenICF improperly call the SearchControls constructor wi… Racf Connector after 1.1.0.0 Fix from $1,9502017-02-03 MEDIUM 5.8 CVE-2017-3809 A vulnerability in the Policy deployment module of the Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to pre… Secure Firewall Management Center Mitigation only Fix from $1,6002017-02-03 MEDIUM 5.8 CVE-2017-3814 A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to b… Secure Firewall Management Center Mitigation only Fix from $1,6002017-02-03 MEDIUM 5.8 CVE-2017-3818 A vulnerability in the Multipurpose Internet Mail Extensions (MIME) scanner of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could… Email Security Appliance Firmware Mitigation only Fix from $1,6002017-02-03 MEDIUM 5.3 CVE-2017-3822 A vulnerability in the logging subsystem of the Cisco Firepower Threat Defense (FTD) Firepower Device Manager (FDM) could allow an unauthenticated, r… Secure Firewall Threat Defense Mitigation only Fix from $1,6002017-02-03 MEDIUM 5.5 CVE-2016-6234 The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg… Lepton Patch available Fix from $1,6002017-02-02 MEDIUM 6.5 CVE-2016-6084 IBM BigFix Platform could allow an attacker on the local network to crash the BES server using a specially crafted XMLSchema request. Bigfix Platform Patch available Fix from $1,6002017-02-01 HIGH 7.5 CVE-2016-10079EPSS 5% SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long string to TCP port 515. Saplpd after 7400.3.11.33 Fix from $1,9502017-02-01 HIGH 8.6 CVE-2017-3790 A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow… Expressway Mitigation only Fix from $1,9502017-02-01