Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
CRITICAL 9.8 CVE-2016-4165 The extension manager in Adobe Brackets before 1.7 allows attackers to have an unspecified impact via invalid input. Brackets after 1.6 Fix from $2,3002016-06-16 MEDIUM 5.0 CVE-2016-3230 The Search component in Microsoft Windows 7, Windows Server 2008 R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10… Windows 10 Mitigation only Fix from $1,6002016-06-16 HIGH 7.5 CVE-2016-3207EPSS 17% The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack… Jscript Mitigation only Fix from $1,9502016-06-16 HIGH 7.5 CVE-2016-3206EPSS 15% The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack… Jscript Mitigation only Fix from $1,9502016-06-16 HIGH 7.5 CVE-2016-3205EPSS 15% The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack… Jscript Mitigation only Fix from $1,9502016-06-16 HIGH 7.8 CVE-2016-3203EPSS 33% Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to execute arbitrary code… Edge Mitigation only Fix from $1,9502016-06-16 HIGH 7.5 CVE-2016-3202EPSS 17% The Microsoft (1) Chakra JavaScript, (2) JScript, and (3) VBScript engines, as used in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, allo… Chakra Javascript Mitigation only Fix from $1,9502016-06-16 HIGH 7.3 CVE-2016-0025EPSS 15% Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Office 2016, Word 2016, Word for Mac 2011, Word 2016 for Ma… Office Mitigation only Fix from $1,9502016-06-16 HIGH 7.5 CVE-2016-4579 Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "ret… Ubuntu Linux after 1.3.3 Fix from $1,9502016-06-13 HIGH 7.5 CVE-2016-4353 ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (a… Ubuntu Linux after 1.3.2 Fix from $1,9502016-06-13 HIGH 7.5 CVE-2016-1542EPSS 75% The RPC API in RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attackers t… Bladelogic Server Automation Console Patch available Fix from $1,9502016-06-13 MEDIUM 5.5 CVE-2016-2495 SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allow… Android Mitigation only Fix from $1,6002016-06-13 HIGH 7.8 CVE-2016-2487 libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers to gain… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2486 mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 do… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2480 The mm-video-v4l2 vidc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does n… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2478 mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2477 mm-video-v4l2/vidc/vdec/src/omx_vdec_msm8974.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2475 The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, and Pixel C devices allo… Android after 6.0.1 Fix from $1,9502016-06-13 HIGH 7.8 CVE-2016-2464 libvpx in libwebm in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attacke… Android Mitigation only Fix from $1,9502016-06-13 HIGH 7.5 CVE-2016-3706EPSS 6% Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attack… Opensuse 2.23+ Fix from $1,9502016-06-10 CRITICAL 9.8 CVE-2016-2786 The pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica… Puppet Agent Mitigation only Fix from $2,3002016-06-10 HIGH 8.1 CVE-2016-1419 Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka… Aironet Access Point Software Mitigation only Fix from $1,9502016-06-10 HIGH 7.1 CVE-2016-4449 XML external entity (XXE) vulnerability in the xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.4, when not in validating mode, … Debian Linux after 2.9.3 Fix from $1,9502016-06-09 CRITICAL 9.8 CVE-2016-4368 HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remo… Universal Cmbd Foundation Mitigation only Fix from $2,3002016-06-08 HIGH 7.8 CVE-2016-1418 Cisco Aironet Access Point Software 8.2(100.0) on 1830e, 1830i, 1850e, 1850i, 2800, and 3800 access points allows local users to obtain Linux root ac… Aironet Access Point Software Mitigation only Fix from $1,9502016-06-08 HIGH 7.5 CVE-2016-4545 Virtual servers in F5 BIG-IP 11.5.4, when SSL profiles are enabled, allow remote attackers to cause a denial of service (resource consumption and Tra… Big Ip Application Acceleration Manager Mitigation only Fix from $1,9502016-06-07 MEDIUM 5.3 CVE-2016-3093EPSS 8% Apache Struts 2.0.0 through 2.3.24.1 does not properly cache method references when used with OGNL before 3.0.12, which allows remote attackers to ca… Struts after 3.0.11 Fix from $1,6002016-06-07 CRITICAL 9.8 CVE-2016-3087EPSS 82% Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to exec… Struts No fix yet Fix from $2,3002016-06-07 CRITICAL 9.8 CVE-2014-9746 The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in t… Debian Linux after 2.5.3 Fix from $2,3002016-06-07 HIGH 7.8 CVE-2016-1403 CISCO IP 8800 phones with software 11.0.1 and earlier allow local users to gain privileges for OS command execution via crafted CLI commands, aka Bug… Ip Phone 8800 Series Firmware Mitigation only Fix from $1,9502016-06-04