Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.9 CVE-2016-4083 epan/dissectors/packet-mswsp.c in the MS-WSP dissector in Wireshark 2.0.x before 2.0.3 does not ensure that data is available before array allocation… Wireshark Mitigation only Fix from $1,6002016-04-25 MEDIUM 5.9 CVE-2016-4078 The IEEE 802.11 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 does not properly restrict element lists, which allows remote att… Wireshark Mitigation only Fix from $1,6002016-04-25 HIGH 7.5 CVE-2016-4061 Foxit Reader and PhantomPDF before 7.3.4 on Windows allow remote attackers to cause a denial of service (application crash) via a crafted content str… Foxit Reader after 7.3.0.118 Fix from $1,9502016-04-22 HIGH 7.5 CVE-2016-1364 Cisco Wireless LAN Controller (WLC) Software 7.4 before 7.4.130.0(MD) and 7.5, 7.6, and 8.0 before 8.0.110.0(ED) allows remote attackers to cause a d… Wireless Lan Controller Software Mitigation only Fix from $1,9502016-04-21 MEDIUM 5.9 CVE-2016-2390EPSS 26% The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when … Squid after 3.5.13 Fix from $1,6002016-04-19 MEDIUM 6.5 CVE-2016-3950 Huawei AR3200 routers with software before V200R006C10SPC300 allow remote authenticated users to cause a denial of service (restart) via crafted pack… Ar3200 Firmware Mitigation only Fix from $1,6002016-04-18 HIGH 7.5 CVE-2016-3071 Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform. Fedora Mitigation only Fix from $1,9502016-04-18 MEDIUM 6.5 CVE-2016-1654 The media subsystem in Google Chrome before 50.0.2661.75 does not initialize an unspecified data structure, which allows remote attackers to cause a … Debian Linux after 49.0.2623.112 Fix from $1,6002016-04-18 MEDIUM 5.5 CVE-2016-2424 server/content/SyncStorageEngine.java in SyncStorageEngine in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-0… Android Mitigation only Fix from $1,6002016-04-18 MEDIUM 6.2 CVE-2016-2414 The Minikin library in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not properly consider negative size values in f… Android Mitigation only Fix from $1,6002016-04-18 MEDIUM 6.5 CVE-2016-2411 A Qualcomm Power Management kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverag… Android Mitigation only Fix from $1,6002016-04-18 HIGH 8.4 CVE-2016-0834 An unspecified media codec in mediaserver in Android 6.x before 2016-04-01 allows remote attackers to execute arbitrary code or cause a denial of ser… Android Mitigation only Fix from $1,9502016-04-18 MEDIUM 5.5 CVE-2016-3961 Xen and the Linux kernel through 4.5.x do not properly suppress hugetlbfs support in x86 PV guests, which allows local PV guest OS users to cause a d… Ubuntu Linux after 4.5.3 Fix from $1,6002016-04-15 HIGH 7.5 CVE-2016-2145 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows rem… Fedora after 0.11.0 Fix from $1,9502016-04-15 HIGH 7.8 CVE-2016-1271 Juniper Junos OS before 12.1X46-D45, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R11, 12.3X48 before 12.3X48-D25, 13.2 before 13.2R8, 13.3 before 13.… Junos after 12.1x46 Fix from $1,9502016-04-15 HIGH 7.5 CVE-2016-1268 The administrative web services interface in Juniper ScreenOS before 6.3.0r21 allows remote attackers to cause a denial of service (reboot) via a cra… Screenos Mitigation only Fix from $1,9502016-04-15 CRITICAL 9.8 CVE-2016-0889 An HTTP servlet in vApp Manager in EMC Unisphere for VMAX Virtual Appliance before 8.2.0 allows remote attackers to write to arbitrary files via a cr… Emc Unisphere after 8.1 Fix from $2,3002016-04-15 HIGH 8.8 CVE-2016-3069 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. Debian Linux Patch available Fix from $1,9502016-04-13 HIGH 8.8 CVE-2016-3068EPSS 5% Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. Debian Linux Patch available Fix from $1,9502016-04-13 CRITICAL 9.8 CVE-2015-7545EPSS 19% The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x befo… Git after 2.3.9 Fix from $2,3002016-04-13 MEDIUM 6.1 CVE-2015-8682 The Video0 driver in Huawei P8 smartphones with software GRA-UL00 before GRA-UL00C00B350, GRA-UL10 before GRA-UL10C00B350, GRA-TL00 before GRA-TL00C0… Mate S Firmware Mitigation only Fix from $1,6002016-04-13 MEDIUM 5.3 CVE-2016-1376 Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and inte… Ios Xr Mitigation only Fix from $1,6002016-04-12 HIGH 8.8 CVE-2016-0147EPSS 16% Microsoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulner… Xml Core Services Mitigation only Fix from $1,9502016-04-12 CRITICAL 9.8 CVE-2016-3655 The management web interface in Palo Alto Networks PAN-OS before 5.0.18, 6.0.x before 6.0.13, 6.1.x before 6.1.10, and 7.0.x before 7.0.5 allows remo… Pan Os 5.0.18 / 5.1.11+ Fix from $2,3002016-04-12 HIGH 7.2 CVE-2016-3654 The device management command line interface (CLI) in Palo Alto Networks PAN-OS before 5.0.18, 5.1.x before 5.1.11, 6.0.x before 6.0.13, 6.1.x before… Pan Os 5.0.18 / 5.1.11+ Fix from $1,9502016-04-12 HIGH 8.8 CVE-2016-0785EPSS 9% Apache Struts 2.x before 2.3.28 allows remote attackers to execute arbitrary code via a "%{}" sequence in a tag attribute, aka forced double OGNL eva… Struts 2.3.20.3+ Fix from $1,9502016-04-12 CRITICAL 9.8 CVE-2016-2170EPSS 13% Apache OFBiz 12.04.x before 12.04.06 and 13.07.x before 13.07.03 allow remote attackers to execute arbitrary commands via a crafted serialized Java o… Ofbiz 12.04.06 / 13.07.03+ Fix from $2,3002016-04-12 HIGH 8.6 CVE-2015-8702 The DNS::GetResult function in dns.cpp in InspIRCd before 2.0.19 allows remote DNS servers to cause a denial of service (netsplit) via an invalid cha… Debian Linux after 2.0.18 Fix from $1,9502016-04-12 HIGH 7.5 CVE-2016-3678 Huawei Quidway S9700, S5700, S5300, S9300, and S7700 switches with software before V200R003SPH012 allow remote attackers to cause a denial of service… S5300 Firmware Mitigation only Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-2381EPSS 9% Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. Perl 5.23.9 / 12.1.2.0.4+ Fix from $1,9502016-04-08