Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Linux Kernel MEDIUM 5.5
CVE-2016-8461

An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is…

Mitigation only
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2016-8462

An information disclosure vulnerability in the bootloader could enable a local attacker to access data outside of its permission level. This issue is…

Fix: after 7.1.0
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2016-8396

An information disclosure vulnerability in the MediaTek video driver could enable a local malicious application to access data outside of its permiss…

Fix: after 7.1.0
Fix from $1,600 2017-01-12
Linux Kernel MEDIUM 5.5
CVE-2016-8397

An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio…

Mitigation only
Fix from $1,600 2017-01-12
Linux Kernel MEDIUM 5.5
CVE-2016-8400

An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of it…

Mitigation only
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2016-6773

An information disclosure vulnerability in the ih264d decoder in Mediaserver could enable a local malicious application to access data outside of its…

Mitigation only
Fix from $1,600 2017-01-12
Web2py HIGH 7.5
CVE-2016-4806EPSS 10%

Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended user to read/access web server…

Fix: after 2.14.5
Fix from $1,950 2017-01-11
Metrocluster Tiebreaker HIGH 7.5
CVE-2016-6820

MetroCluster Tiebreaker for clustered Data ONTAP in versions before 1.2 discloses sensitive information in cleartext which may be viewed by an unauth…

Fix: after 1.1
Fix from $1,950 2017-01-11
Gemfire For Pivotal Cloud Foundry CRITICAL 9.8
CVE-2016-9885

An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, …

Mitigation only
Fix from $2,300 2017-01-06
Total Security MEDIUM 5.5
CVE-2016-4306

Multiple information leaks exist in various IOCTL handlers of the Kaspersky Internet Security KLDISK driver. Specially crafted IOCTL requests can cau…

No fix yet
Fix from $1,600 2017-01-06
Ntp MEDIUM 5.3
CVE-2016-1550

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb34b9cc89b92a8fef2f459004865c9…

No fix yet
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2367

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux MEDIUM 5.9
CVE-2016-2372

An information leak exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT data sent via the server could potentially result i…

Fix: after 2.10.12
Fix from $1,600 2017-01-06
Ubuntu Linux HIGH 8.1
CVE-2016-2374

An exploitable memory corruption vulnerability exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT MultiMX message sent via…

Fix: after 2.10.12
Fix from $1,950 2017-01-06
Piwigo CRITICAL 9.8
CVE-2016-10105

admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosur…

Fix: after 2.8.3
Fix from $2,300 2017-01-03
Qemu MEDIUM 6.5
CVE-2016-9845

QEMU (aka Quick Emulator) built with the Virtio GPU Device emulator support is vulnerable to an information leakage issue. It could occur while proce…

Fix: 2.8.0+
Fix from $1,600 2016-12-29
Tools MEDIUM 5.5
CVE-2016-5328

VMware Tools 9.x and 10.x before 10.1.0 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory add…

Fix: after 10.0.8
Fix from $1,600 2016-12-29
Fusion MEDIUM 5.5
CVE-2016-5329

VMware Fusion 8.x before 8.5 on OS X, when System Integrity Protection (SIP) is enabled, allows local users to determine kernel memory addresses and …

Mitigation only
Fix from $1,600 2016-12-29
Linux Kernel MEDIUM 5.5
CVE-2016-9756

arch/x86/kvm/emulate.c in the Linux kernel before 4.8.12 does not properly initialize Code Segment (CS) in certain error cases, which allows local us…

Fix: after 4.8.11
Fix from $1,600 2016-12-28
Android MEDIUM 5.5
CVE-2016-6910

The non-existent notification listener vulnerability was introduced in the initial Android 5.0.2 builds for the Samsung Galaxy S6 Edge devices, but t…

Mitigation only
Fix from $1,600 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-7555

The avi_read_header function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to memory leak when decoding an AVI file that has a crafted…

Fix: after 3.1.3
Fix from $1,600 2016-12-23
Snap Creator Framework HIGH 7.5
CVE-2016-7172

NetApp Snap Creator Framework before 4.3.1 discloses sensitive information which could be viewed by an unauthorized user.

Fix: after 4.3.0
Fix from $1,950 2016-12-21
Windows 10 MEDIUM 5.5
CVE-2016-7295

The Common Log File System (CLFS) driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serv…

Mitigation only
Fix from $1,600 2016-12-20
Windows 10 MEDIUM 5.5
CVE-2016-7219

The Crypto driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Wi…

Mitigation only
Fix from $1,600 2016-12-20
Office For Mac MEDIUM 6.5
CVE-2016-7257EPSS 23%

The GDI component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Office for Mac 2011, and Office 2016 for Mac all…

Mitigation only
Fix from $1,600 2016-12-20
Windows 10 MEDIUM 5.5
CVE-2016-7258

The kernel in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 mishandles page-fault system calls, which allows local users to obtai…

Mitigation only
Fix from $1,600 2016-12-20
Solution Manager HIGH 7.5
CVE-2016-10005

Webdynpro in SAP Solman 7.1 through 7.31 allows remote attackers to obtain sensitive information via webdynpro/dispatcher/sap.com/caf~eu~gp~example~t…

No fix yet
Fix from $1,950 2016-12-19
Simatic S7 300 Cpu Firmware MEDIUM 5.9
CVE-2016-9159

A vulnerability has been identified in SIMATIC S7-300 CPU family (All versions), SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS varia…

Mitigation only
Fix from $1,600 2016-12-17
Gpu Driver MEDIUM 6.1
CVE-2016-8820

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where a ch…

Patch available
Fix from $1,600 2016-12-16
Tika MEDIUM 5.3
CVE-2015-3271EPSS 7%

Apache Tika server (aka tika-server) in Apache Tika 1.9 might allow remote attackers to read arbitrary files via the HTTP fileUrl header.

Mitigation only
Fix from $1,600 2016-12-15