Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2016-7785 The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a c… Ffmpeg after 3.1.3 Fix from $1,6002016-12-23 MEDIUM 5.5 CVE-2016-8595 The gsm_parse function in libavcodec/gsm_parser.c in FFmpeg before 3.1.5 allows remote attackers to cause a denial of service (assert fault) via a cr… Ffmpeg after 3.1.4 Fix from $1,6002016-12-23 HIGH 7.5 CVE-2016-9179 lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be t… Lynx Mitigation only Fix from $1,9502016-12-22 HIGH 7.8 CVE-2016-7266EPSS 17% Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Office Compatibility Pack SP3, Excel Viewer, and Excel 2016 … Excel Mitigation only Fix from $1,9502016-12-20 MEDIUM 5.5 CVE-2016-7267EPSS 16% Microsoft Excel 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 misparses file formats, which makes it easier for remote attackers to execute arbitrary cod… Excel Mitigation only Fix from $1,6002016-12-20 MEDIUM 6.5 CVE-2016-5187 Google Chrome prior to 54.0.2840.85 for Android incorrectly handled rapid transition into and out of full screen mode, which allowed a remote attacke… Chrome after 53.0.2785.143 Fix from $1,6002016-12-18 HIGH 7.5 CVE-2016-9158 A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS varia… Simatic S7 300 Cpu Firmware Mitigation only Fix from $1,9502016-12-17 HIGH 7.8 CVE-2016-8818 All versions of NVIDIA Windows GPU Display contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a pointer p… Gpu Driver Patch available Fix from $1,9502016-12-16 MEDIUM 6.1 CVE-2016-8820 All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a ch… Gpu Driver Patch available Fix from $1,6002016-12-16 HIGH 7.8 CVE-2016-8822 All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x60000… Gpu Driver Patch available Fix from $1,9502016-12-16 HIGH 7.5 CVE-2016-9212 A vulnerability in the Decrypt for End-User Notification configuration parameter of Cisco AsyncOS Software for Cisco Web Security Appliances could al… Web Security Appliance Mitigation only Fix from $1,9502016-12-14 HIGH 7.5 CVE-2016-9211 A vulnerability in TCP port management in Cisco ONS 15454 Series Multiservice Provisioning Platforms could allow an unauthenticated, remote attacker … Ons 15454 Sdh Multiservice Platform Software Mitigation only Fix from $1,9502016-12-14 MEDIUM 6.5 CVE-2016-9207 A vulnerability in the HTTP traffic server component of Cisco Expressway could allow an unauthenticated, remote attacker to initiate TCP connections … Expressway Mitigation only Fix from $1,6002016-12-14 HIGH 7.5 CVE-2016-9201 A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass tra… iOS Mitigation only Fix from $1,9502016-12-14 HIGH 7.5 CVE-2016-9193 A vulnerability in the malicious file detection and blocking features of Cisco Firepower Management Center and Cisco FireSIGHT System Software could … Firesight System Software Mitigation only Fix from $1,9502016-12-14 HIGH 7.5 CVE-2016-7952 X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecor… Fedora after 1.2.2 Fix from $1,9502016-12-13 CRITICAL 9.8 CVE-2016-7949 Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to t… Fedora after 0.9.9 Fix from $2,3002016-12-13 MEDIUM 5.5 CVE-2016-6712 A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before… Android Patch available Fix from $1,6002016-12-13 MEDIUM 5.5 CVE-2016-6711 A remote denial of service vulnerability in libvpx in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before… Android Patch available Fix from $1,6002016-12-13 CRITICAL 9.8 CVE-2016-5691 The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validati… Solaris after 6.9.4-4 Fix from $2,3002016-12-13 HIGH 7.5 CVE-2016-9863 An issue was discovered in phpMyAdmin. With a very large request to table partitioning function, it is possible to invoke a Denial of Service (DoS) a… phpMyAdmin Patch available Fix from $1,9502016-12-11 MEDIUM 5.9 CVE-2016-9860 An issue was discovered in phpMyAdmin. An unauthenticated user can execute a denial of service attack when phpMyAdmin is running with $cfg['AllowArbi… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9859 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in import feature… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 5.3 CVE-2016-9858 An issue was discovered in phpMyAdmin. With a crafted request parameter value it is possible to initiate a denial of service attack in saved searches… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.5 CVE-2016-6630 An issue was discovered in phpMyAdmin. An authenticated user can trigger a denial-of-service (DoS) attack by entering a very long password at the cha… phpMyAdmin Patch available Fix from $1,6002016-12-11 MEDIUM 6.5 CVE-2016-6623 An issue was discovered in phpMyAdmin. An authorized user can cause a denial-of-service (DoS) attack on a server by passing large values to a loop. A… phpMyAdmin Patch available Fix from $1,6002016-12-11 CRITICAL 9.8 CVE-2016-6501 JFrog Artifactory before 4.11 allows remote attackers to execute arbitrary code via an LDAP attribute with a crafted serialized Java object, aka LDAP… Artifactory after 4.10 Fix from $2,3002016-12-09 CRITICAL 9.8 CVE-2016-6496 The LDAP directory connector in Atlassian Crowd before 2.8.8 and 2.9.x before 2.9.5 allows remote attackers to execute arbitrary code via an LDAP att… Crowd after 2.8.4 Fix from $2,3002016-12-09 HIGH 7.5 CVE-2016-9919EPSS 6% The icmp6_send function in net/ipv6/icmp.c in the Linux kernel through 4.8.12 omits a certain check of the dst data structure, which allows remote at… Linux Kernel 4.9+ Fix from $1,9502016-12-08 HIGH 7.4 CVE-2015-8870 Integer overflow in tools/bmp2tiff.c in LibTIFF before 4.0.4 allows remote attackers to cause a denial of service (heap-based buffer over-read), or p… Libtiff after 4.0.3 Fix from $1,9502016-12-06