Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 8.8 CVE-2016-1391 Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(2) and Prime Virtual Network Analysis Module (vNAM) be… Prime Network Analysis Module Software Mitigation only Fix from $1,9502016-06-04 HIGH 7.8 CVE-2016-1390 Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) be… Prime Network Analysis Module Software Mitigation only Fix from $1,9502016-06-04 HIGH 7.5 CVE-2016-3944 UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi… Accelerator Application Mitigation only Fix from $1,9502016-06-03 HIGH 8.1 CVE-2016-0363 The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 be… Satellite Mitigation only Fix from $1,9502016-06-03 MEDIUM 5.3 CVE-2016-1370 Cisco Prime Network Analysis Module (NAM) before 6.2(1-b) miscalculates IPv6 payload lengths, which allows remote attackers to cause a denial of serv… Network Analysis Module Software Mitigation only Fix from $1,6002016-06-03 MEDIUM 5.9 CVE-2016-3094EPSS 8% PlainSaslServer.java in Apache Qpid Java before 6.0.3, when the broker is configured to allow plaintext passwords, allows remote attackers to cause a… Qpid Broker J after 6.0.2 Fix from $1,6002016-06-01 HIGH 7.5 CVE-2016-1409 The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS XE 2.1 through 3.17S, IOS XR 2.0.0 through 5.3.2, and NX-OS allows… iOS Mitigation only Fix from $1,9502016-05-29 HIGH 7.5 CVE-2015-8853 The (1) S_reghop3, (2) S_reghop4, and (3) S_reghopmaybe3 functions in regexec.c in Perl before 5.24.0 allow context-dependent attackers to cause a de… Fedora after 5.23.9 Fix from $1,9502016-05-25 HIGH 7.5 CVE-2016-1407 Cisco IOS XR through 5.3.2 mishandles Local Packet Transport Services (LPTS) flow-base entries, which allows remote attackers to cause a denial of se… Ios Xr Mitigation only Fix from $1,9502016-05-25 HIGH 7.5 CVE-2016-1400 Cisco TelePresence Video Communications Server (VCS) X8.x before X8.7.2 allows remote attackers to cause a denial of service (service disruption) via… Telepresence Video Communication Server Mitigation only Fix from $1,9502016-05-25 HIGH 7.5 CVE-2016-1382 Cisco AsyncOS before 8.5.3-069 and 8.6 through 8.8 on Web Security Appliance (WSA) devices mishandles memory allocation for HTTP requests, which allo… Web Security Appliance \(wsa\) Mitigation only Fix from $1,9502016-05-25 HIGH 7.5 CVE-2016-1380 Cisco AsyncOS 8.0 before 8.0.6-119 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (proxy-process hang) … Web Security Appliance Mitigation only Fix from $1,9502016-05-25 HIGH 8.8 CVE-2016-4782 Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent sc… Shareit Mitigation only Fix from $1,9502016-05-23 HIGH 8.1 CVE-2016-4087 Huawei S12700 switches with software before V200R008C00SPC500 and S5700 switches with software before V200R005SPH010, when the debug switch is enable… S12700 Firmware Mitigation only Fix from $1,9502016-05-23 HIGH 7.5 CVE-2016-4049 The bgp_dump_routes_func function in bgpd/bgp_dump.c in Quagga does not perform size checks when dumping data, which might allow remote attackers to … Quagga Mitigation only Fix from $1,9502016-05-23 HIGH 7.5 CVE-2016-3959 The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer libra… Go after 1.5 Fix from $1,9502016-05-23 HIGH 7.5 CVE-2016-4348 The _rsvg_css_normalize_font_size function in librsvg 2.40.2 allows context-dependent attackers to cause a denial of service (stack consumption and a… Debian Linux after 2.40.1 Fix from $1,9502016-05-20 MEDIUM 5.3 CVE-2016-3739EPSS 7% The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7… Curl Patch available Fix from $1,6002016-05-20 HIGH 7.5 CVE-2015-7558 librsvg before 2.40.12 allows context-dependent attackers to cause a denial of service (infinite loop, stack consumption, and application crash) via … Debian Linux after 2.40.11 Fix from $1,9502016-05-20 HIGH 7.5 CVE-2015-7557 The _rsvg_node_poly_build_path function in rsvg-shapes.c in librsvg before 2.40.7 allows context-dependent attackers to cause a denial of service (ou… Librsvg after 2.40.6 Fix from $1,9502016-05-20 CRITICAL 9.8 CVE-2016-4072EPSS 6% The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted fi… PHP after 10.11.4 Fix from $2,3002016-05-20 CRITICAL 9.8 CVE-2016-4071EPSS 19% Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows … PHP after 10.11.4 Fix from $2,3002016-05-20 HIGH 7.5 CVE-2016-1843 The Messages component in Apple OS X before 10.11.5 mishandles filename encoding, which allows remote attackers to obtain sensitive information via u… Mac Os X after 10.11.4 Fix from $1,9502016-05-20 HIGH 8.8 CVE-2016-1800 Captive Network Assistant in Apple OS X before 10.11.5 mishandles a custom URL scheme, which allows user-assisted remote attackers to execute arbitra… Mac Os X after 10.11.4 Fix from $1,9502016-05-20 MEDIUM 6.5 CVE-2016-4425 Jansson 2.7 and earlier allows context-dependent attackers to cause a denial of service (deep recursion, stack consumption, and crash) via crafted JS… Jansson after 2.7 Fix from $1,6002016-05-17 HIGH 7.5 CVE-2016-3705EPSS 5% The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth… Ubuntu Linux Mitigation only Fix from $1,9502016-05-17 HIGH 7.5 CVE-2015-4605EPSS 7% The mcopy function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, d… PHP after 5.4.39 Fix from $1,9502016-05-16 HIGH 7.5 CVE-2015-4604EPSS 7% The mget function in softmagic.c in file 5.x, as used in the Fileinfo component in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, do… PHP after 5.4.39 Fix from $1,9502016-05-16 MEDIUM 6.5 CVE-2015-4598 PHP before 5.4.42, 5.5.x before 5.5.26, and 5.6.x before 5.6.10 does not ensure that pathnames lack %00 sequences, which might allow remote attackers… Enterprise Linux Desktop after 5.4.41 Fix from $1,6002016-05-16 MEDIUM 6.5 CVE-2015-3411 PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers … Enterprise Linux after 5.4.39 Fix from $1,6002016-05-16