Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.5 CVE-2015-8717 The dissect_sdp function in epan/dissectors/packet-sdp.c in the SDP dissector in Wireshark 1.12.x before 1.12.9 does not prevent use of a negative me… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8716 The init_t38_info_conv function in epan/dissectors/packet-t38.c in the T.38 dissector in Wireshark 1.12.x before 1.12.9 does not ensure that a conver… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8715 epan/dissectors/packet-alljoyn.c in the AllJoyn dissector in Wireshark 1.12.x before 1.12.9 does not check for empty arguments, which allows remote a… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8714 The dissect_dcom_OBJREF function in epan/dissectors/packet-dcom.c in the DCOM dissector in Wireshark 1.12.x before 1.12.9 does not initialize a certa… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8713 epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not properly reserve memory for channel ID mappings,… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8712 The dissect_hsdsch_channel_info function in epan/dissectors/packet-umts_fp.c in the UMTS FP dissector in Wireshark 1.12.x before 1.12.9 does not vali… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-8711 epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate conversation data, whi… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 5.5 CVE-2015-3182 epan/dissectors/packet-dec-dnart.c in the DECnet NSP/RT dissector in Wireshark 1.10.12 through 1.10.14 mishandles a certain strdup return value, whic… Wireshark Mitigation only Fix from $1,6002016-01-04 MEDIUM 6.8 CVE-2015-1928 Jazz Team Server in Jazz Foundation in IBM Rational Collaborative Lifecycle Management (CLM) 3.x and 4.x before 4.0.7 IF9, 5.x before 5.0.2 IF11, and… Rational Quality Manager Mitigation only Fix from $1,6002016-01-02 MEDIUM 5.8 CVE-2015-7282 ReadyNet WRT300N-DD devices with firmware 1.0.26 use the same source port number for every DNS query, which makes it easier for remote attackers to s… Wrt300n Dd Firmware Mitigation only Fix from $1,6002015-12-31 MEDIUM 6.1 CVE-2015-2918 The Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1.1 does not properly restrict use of FRAME elements, whic… Orientdb Mitigation only Fix from $1,6002015-12-31 MEDIUM 5.8 CVE-2015-7794 Corega CG-WLNCM4G devices provide an open DNS resolver, which allows remote attackers to cause a denial of service (traffic amplification) via crafte… Cg Wlncm4g Firmware Mitigation only Fix from $1,6002015-12-30 MEDIUM 5.4 CVE-2015-5296EPSS 7% Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3 supports connections that are encrypted but unsigned, which allows man-in… Debian Linux 4.1.22 / 4.2.7+ Fix from $1,6002015-12-29 HIGH 8.7 CVE-2015-7931 The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attac… A840 Telemetry Gateway Base Station Firmware Mitigation only Fix from $1,9502015-12-24 MEDIUM 6.8 CVE-2015-8373 The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a deni… Kea Mitigation only Fix from $1,6002015-12-22 HIGH 7.3 CVE-2015-6934EPSS 5% Serialized-object interfaces in VMware vRealize Orchestrator 6.x, vCenter Orchestrator 5.x, vRealize Operations 6.x, vCenter Operations 5.x, and vCen… Vcenter Orchestrator Mitigation only Fix from $1,9502015-12-21 HIGH 7.2 CVE-2015-6426 Cisco Prime Network Services Controller 3.0 allows local users to bypass intended access restrictions and execute arbitrary commands via additional p… Prime Network Services Controller Mitigation only Fix from $1,9502015-12-18 HIGH 7.5 CVE-2015-7527EPSS 5% lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Wi… Cool Video Gallery No fix yet Fix from $1,9502015-12-17 HIGH 7.5 CVE-2015-8565 Directory traversal vulnerability in Joomla! 3.2.0 through 3.3.x and 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via unknow… Joomla\! Mitigation only Fix from $1,9502015-12-16 HIGH 7.5 CVE-2015-8564 Directory traversal vulnerability in Joomla! 3.4.x before 3.4.6 allows remote attackers to have unspecified impact via directory traversal sequences … Joomla\! Mitigation only Fix from $1,9502015-12-16 HIGH 7.5 CVE-2015-8562EPSS 98% Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP U… Joomla\! No fix yet Fix from $1,9502015-12-16 MEDIUM 5.0 CVE-2015-8476 Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) ema… Debian Linux after 5.2.13 Fix from $1,6002015-12-16 MEDIUM 5.0 CVE-2015-8000EPSS 55% db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion fai… Linux Patch available Fix from $1,6002015-12-16 MEDIUM 6.8 CVE-2015-7216 The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote atta… Fedora after 42.0 Fix from $1,6002015-12-16 MEDIUM 5.0 CVE-2015-7211 Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified… Firefox after 42.0 Fix from $1,6002015-12-16 HIGH 7.2 CVE-2015-6403 The TFTP implementation on Cisco Small Business SPA30x, SPA50x, SPA51x phones 7.5.7 improperly validates firmware-image file integrity, which allows … Spa500 Firmware Mitigation only Fix from $1,9502015-12-15 MEDIUM 6.5 CVE-2015-6361 The administrative web interface on Cisco DPC3939 (XB3) devices with firmware 121109aCMCST allows remote authenticated users to execute arbitrary com… Dpc3939 Wireless Residential Voice Gateway Firmware Mitigation only Fix from $1,6002015-12-13 HIGH 9.3 CVE-2015-7079 dyld in Apple iOS before 9.2 and tvOS before 9.1 mishandles segment validation, which allows attackers to execute arbitrary code in a privileged cont… Tvos after 9.1 Fix from $1,9502015-12-11 HIGH 9.3 CVE-2015-7072 dyld in Apple iOS before 9.2, tvOS before 9.1, and watchOS before 2.1 mishandles segment validation, which allows attackers to execute arbitrary code… Iphone Os after 9.1 Fix from $1,9502015-12-11 HIGH 7.2 CVE-2015-7047 The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to gain privileges via a crafted … Watchos after 10.11.1 Fix from $1,9502015-12-11