Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MEDIUM 5.0 CVE-2015-4638 The FastL4 virtual server in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and PEM 11.3.0 through 11.5.2 and 11.6.0 through 11.… Big Ip Advanced Firewall Manager Mitigation only Fix from $1,6002015-09-18 MEDIUM 5.0 CVE-2015-5879 XNU in the kernel in Apple iOS before 9 does not properly validate the headers of TCP packets, which allows remote attackers to bypass the sequence-n… Iphone Os after 10.10.5 Fix from $1,6002015-09-18 MEDIUM 5.0 CVE-2015-7231 The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a… Commerce Commonwealth Patch available Fix from $1,6002015-09-17 MEDIUM 6.8 CVE-2015-6828 The tweet_info function in class/__functions.php in the SecureMoz Security Audit plugin 1.0.5 and earlier for WordPress does not use an HTTPS session… Security Audit after 1.0.5 Fix from $1,6002015-09-16 HIGH 7.5 CVE-2015-4499 Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during acco… Bugzilla Patch available Fix from $1,9502015-09-14 MEDIUM 5.0 CVE-2015-6908EPSS 20% The ber_get_next function in libraries/liblber/io.c in OpenLDAP 2.4.42 and earlier allows remote attackers to cause a denial of service (reachable as… Openldap after 10.11.1 Fix from $1,6002015-09-11 HIGH 9.3 CVE-2015-2530EPSS 16% Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 9.3 CVE-2015-2514EPSS 15% Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 9.3 CVE-2015-2513EPSS 19% Windows Journal in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold a… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 9.3 CVE-2015-2506EPSS 16% atmfd.dll in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.5 CVE-2015-6826 The ff_rv34_decode_init_thread_copy function in libavcodec/rv34.c in FFmpeg before 2.7.2 does not initialize certain structure members, which allows … Ubuntu Linux after 2.7.1 Fix from $1,9502015-09-06 HIGH 7.5 CVE-2015-6825 The ff_frame_thread_init function in libavcodec/pthread_frame.c in FFmpeg before 2.7.2 mishandles certain memory-allocation failures, which allows re… Ffmpeg after 2.7.1 Fix from $1,9502015-09-06 HIGH 7.5 CVE-2015-6824 The sws_init_context function in libswscale/utils.c in FFmpeg before 2.7.2 does not initialize certain pixbuf data structures, which allows remote at… Ubuntu Linux after 2.7.1 Fix from $1,9502015-09-06 HIGH 7.5 CVE-2015-6821 The ff_mpv_common_init function in libavcodec/mpegvideo.c in FFmpeg before 2.7.2 does not properly maintain the encoding context, which allows remote… Ffmpeg after 2.7.1 Fix from $1,9502015-09-06 HIGH 7.1 CVE-2015-5986EPSS 26% openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE … Bind after 9.10.2 Fix from $1,9502015-09-05 HIGH 7.8 CVE-2015-5722EPSS 34% buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure… Bind after 9.10.2 Fix from $1,9502015-09-05 HIGH 9.4 CVE-2015-6259 The JavaServer Pages (JSP) component in Cisco Integrated Management Controller (IMC) Supervisor before 1.0.0.1 and UCS Director (formerly Cloupia Uni… Integrated Management Controller Supervisor after 5.2.0.0 Fix from $1,9502015-09-04 MEDIUM 5.5 CVE-2014-2332 Check_MK before 1.2.2p3 and 1.2.3x before 1.2.3i5 allows remote authenticated users to delete arbitrary files via a request to an unspecified link, r… Check Mk after 1.2.3 Fix from $1,6002015-08-31 MEDIUM 6.5 CVE-2015-2140 HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows remote authenticate… Systems Insight Manager after 7.4 Fix from $1,6002015-08-27 MEDIUM 6.4 CVE-2015-6563 The monitor component in sshd in OpenSSH before 7.0 on non-OpenBSD platforms accepts extraneous username data in MONITOR_REQ_PAM_INIT_CTX requests, w… Openssh after 10.11.0 Fix from $1,6002015-08-24 MEDIUM 5.0 CVE-2015-6258 The Internet Access Point Protocol (IAPP) module on Cisco Wireless LAN Controller (WLC) devices with software 8.1(104.37) allows remote attackers to … Wireless Lan Controller Software Mitigation only Fix from $1,6002015-08-22 MEDIUM 5.0 CVE-2015-6256 Cisco ASR 5000 devices with software 19.0.M0.60828 allow remote attackers to cause a denial of service (OSPF process restart) via crafted length fiel… Asr 5000 Series Software Mitigation only Fix from $1,6002015-08-22 HIGH 9.0 CVE-2015-4534 Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 al… Documentum Content Server Mitigation only Fix from $1,9502015-08-20 MEDIUM 6.5 CVE-2015-4329 The administrator web interface in Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary … Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-08-20 MEDIUM 5.0 CVE-2015-4321 The Unicast Reverse Path Forwarding (uRPF) implementation in Cisco Adaptive Security Appliance (ASA) Software 9.3(1.50), 9.3(2.100), 9.3(3), and 9.4(… Adaptive Security Appliance Software Mitigation only Fix from $1,6002015-08-20 MEDIUM 5.5 CVE-2015-4316 The Mobile and Remote Access (MRA) endpoint-validation feature in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 improperly va… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-08-20 HIGH 7.2 CVE-2015-4327 The CLI in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to obtain root privileges by writing script argum… Telepresence Video Communication Server Software Mitigation only Fix from $1,9502015-08-20 MEDIUM 5.5 CVE-2015-4315 The Call Policy Configuration page in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.3 improperly validates external DTDs, which… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-08-20 HIGH 7.2 CVE-2015-3805 Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different… Iphone Os after 10.10.4 Fix from $1,9502015-08-17 HIGH 7.2 CVE-2015-3803 Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted multi-architecture execu… Iphone Os after 10.10.4 Fix from $1,9502015-08-17