Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Windows 10 MEDIUM 5.0
CVE-2017-8471

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,…

Patch available
Fix from $1,600 2017-06-15
Windows 10 MEDIUM 5.0
CVE-2017-8473

Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow a…

Patch available
Fix from $1,600 2017-06-15
Windows 10 MEDIUM 5.0
CVE-2017-8474

The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151…

Patch available
Fix from $1,600 2017-06-15
Office MEDIUM 5.0
CVE-2017-0282

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, …

Patch available
Fix from $1,600 2017-06-15
Office MEDIUM 5.0
CVE-2017-0284

Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, …

Patch available
Fix from $1,600 2017-06-15
Secure Remote Services MEDIUM 5.3
CVE-2017-4986

EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system.

Mitigation only
Fix from $1,600 2017-06-14
Android MEDIUM 5.5
CVE-2017-0639

An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission le…

Mitigation only
Fix from $1,600 2017-06-14
Android MEDIUM 5.5
CVE-2017-0645

An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This…

Mitigation only
Fix from $1,600 2017-06-14
Android MEDIUM 5.5
CVE-2017-0646

An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission le…

Mitigation only
Fix from $1,600 2017-06-14
Android MEDIUM 5.5
CVE-2017-0647

An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. …

Mitigation only
Fix from $1,600 2017-06-14
Android HIGH 7.1
CVE-2016-10339

In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.

Mitigation only
Fix from $1,950 2017-06-13
Android MEDIUM 5.5
CVE-2017-8239

In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leadi…

Patch available
Fix from $1,600 2017-06-13
Linux Kernel MEDIUM 5.5
CVE-2017-9605

The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux ker…

Fix: after 4.11.4
Fix from $1,600 2017-06-13
Fedora MEDIUM 5.5
CVE-2016-3696

The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.

Fix: after 2.8.4
Fix from $1,600 2017-06-13
Secure Firewall Management Center MEDIUM 6.5
CVE-2017-6673

A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use …

Mitigation only
Fix from $1,600 2017-06-13
Ultra Services Framework HIGH 7.5
CVE-2017-6681

A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a re…

Mitigation only
Fix from $1,950 2017-06-13
Elastic Services Controller MEDIUM 6.5
CVE-2017-6691

A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information …

Mitigation only
Fix from $1,600 2017-06-13
Ultra Services Platform MEDIUM 5.5
CVE-2017-6695

A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More…

Mitigation only
Fix from $1,600 2017-06-13
Elastic Services Controller MEDIUM 5.5
CVE-2017-6696

A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive use…

Mitigation only
Fix from $1,600 2017-06-13
Elastic Services Controller MEDIUM 6.5
CVE-2017-6697

A vulnerability in the web interface of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive system c…

Mitigation only
Fix from $1,600 2017-06-13
Debian Linux HIGH 7.8
CVE-2017-4966

An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb…

Mitigation only
Fix from $1,950 2017-06-13
Inotes MEDIUM 5.7
CVE-2017-1214

IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. I…

Patch available
Fix from $1,600 2017-06-12
Libgcrypt MEDIUM 5.9
CVE-2017-9526

In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover…

Fix: after 1.7.6
Fix from $1,600 2017-06-11
Dezie MEDIUM 5.3
CVE-2016-7832

Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to obtain an arbitrary DBM (Cybozu Dezie proprietary format) file v…

Mitigation only
Fix from $1,600 2017-06-09
Groupsession MEDIUM 6.5
CVE-2017-2165

GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as e…

Fix: after 4.6.4
Fix from $1,600 2017-06-09
Ts Wrlp Firmware HIGH 7.5
CVE-2016-7814

I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authen…

Fix: after 1.00.01
Fix from $1,950 2017-06-09
Slideshow HIGH 7.5
CVE-2015-3634

The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attack…

Patch available
Fix from $1,950 2017-06-08
Websphere Application Server MEDIUM 5.3
CVE-2016-9736

IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.

Patch available
Fix from $1,600 2017-06-08
Fedora MEDIUM 5.5
CVE-2016-3095

server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.

Fix: after 2.8.1
Fix from $1,600 2017-06-08
Enterprise Linux Desktop HIGH 7.5
CVE-2016-4992

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Patch available
Fix from $1,950 2017-06-08