Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
HIGH 9.3 CVE-2015-5014 IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an execut… Cognos Disclosure Management Patch available Fix from $1,9502015-10-26 HIGH 7.2 CVE-2015-5945 The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters. Mac Os X after 10.11.0 Fix from $1,9502015-10-23 HIGH 7.1 CVE-2015-7004 The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app. Iphone Os after 9.0.2 Fix from $1,9502015-10-23 MEDIUM 5.0 CVE-2015-7750 The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3… Screenos after 6.3.0 Fix from $1,6002015-10-19 HIGH 7.8 CVE-2015-7749 The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspeci… Junos after 15.1x49 Fix from $1,9502015-10-19 MEDIUM 5.0 CVE-2015-7748 Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R… Junos Mitigation only Fix from $1,6002015-10-19 MEDIUM 5.0 CVE-2015-6334 Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process rest… Asr 5000 Software Mitigation only Fix from $1,6002015-10-16 HIGH 10.0 CVE-2015-7838 ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors. Storage Manager after 6.1 Fix from $1,9502015-10-15 MEDIUM 6.9 CVE-2015-6318 Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.1 and X8.5.2 allows local users to write to arbitrary files via an unspecified sy… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-10-12 MEDIUM 5.0 CVE-2015-1047 vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartb… Vcenter Server Patch available Fix from $1,6002015-10-12 HIGH 7.5 CVE-2015-1303 bindings/core/v8/V8DOMWrapper.h in Blink, as used in Google Chrome before 45.0.2454.101, does not perform a rethrow action to propagate information a… Chrome after 45.0.2454.93 Fix from $1,9502015-10-12 MEDIUM 6.8 CVE-2015-5234 IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .app… Enterprise Linux Desktop after 1.5.2 Fix from $1,6002015-10-09 MEDIUM 6.8 CVE-2015-1337 Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk imag… Ubuntu Linux No fix yet Fix from $1,6002015-10-09 MEDIUM 5.0 CVE-2015-5883 The bidirectional text-display and text-selection implementations in Terminal in Apple OS X before 10.11 interpret directional override formatting ch… Mac Os X after 10.10.5 Fix from $1,6002015-10-09 HIGH 10.0 CVE-2015-5780 The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has u… Safari after 8.0.8 Fix from $1,9502015-10-09 HIGH 10.0 CVE-2015-6598 libstagefright in Android before 5.1.1 LMY48T allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via … Android after 5.1 Fix from $1,9502015-10-06 HIGH 7.8 CVE-2015-7686 Algorithmic complexity vulnerability in Address.pm in the Email-Address module 1.908 and earlier for Perl allows remote attackers to cause a denial o… Email Address after 1.908 Fix from $1,9502015-10-06 MEDIUM 6.8 CVE-2014-9751 The read_network_packet function in ntp_io.c in ntpd in NTP 4.x before 4.2.8p1 on Linux and OS X does not properly determine whether a source IP addr… Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 MEDIUM 5.8 CVE-2014-9750EPSS 6% ntp_crypto.c in ntpd in NTP 4.x before 4.2.8p1, when Autokey Authentication is enabled, allows remote attackers to obtain sensitive information from … Enterprise Linux Desktop 4.2.8+ Fix from $1,6002015-10-06 HIGH 9.3 CVE-2015-6602 libutils in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file, as demo… Android after 5.1.1 Fix from $1,9502015-10-02 HIGH 9.3 CVE-2015-3876 libstagefright in Android through 5.1.1 LMY48M allows remote attackers to execute arbitrary code via crafted metadata in a (1) MP3 or (2) MP4 file. Android after 5.1.1 Fix from $1,9502015-10-02 HIGH 9.3 CVE-2015-3837 The OpenSSLX509Certificate class in org/conscrypt/OpenSSLX509Certificate.java in Android before 5.1.1 LMY48I improperly includes certain context data… Android after 5.1 Fix from $1,9502015-10-01 MEDIUM 6.8 CVE-2015-7337 The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via … Notebook after 3.2.1 Fix from $1,6002015-09-29 HIGH 7.5 CVE-2015-5074EPSS 8% Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.… X2crm after 5.0.8 Fix from $1,9502015-09-29 HIGH 7.8 CVE-2015-6279 The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE… iOS Mitigation only Fix from $1,9502015-09-28 HIGH 7.8 CVE-2015-6278 The IPv6 snooping functionality in the first-hop security subsystem in Cisco IOS 12.2, 15.0, 15.1, 15.2, 15.3, 15.4, and 15.5 and IOS XE 3.2SE, 3.3SE… iOS Mitigation only Fix from $1,9502015-09-28 HIGH 7.8 CVE-2015-6282 Cisco IOS XE 2.x and 3.x before 3.10.6S, 3.11.xS through 3.13.xS before 3.13.3S, and 3.14.xS through 3.15.xS before 3.15.1S allows remote attackers t… Ios Xe Mitigation only Fix from $1,9502015-09-26 HIGH 7.5 CVE-2015-7375 Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime e… Web Studio after 7.1.3.6 Fix from $1,9502015-09-25 HIGH 7.5 CVE-2015-7374 The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vec… Web Studio after 7.1.3.6 Fix from $1,9502015-09-25 HIGH 10.0 CVE-2015-5568EPSS 20% Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad… Flash Player after 18.0.0.199 Fix from $1,9502015-09-22