Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-6752

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6751

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6750

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6749

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.1.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6748

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6746

An information disclosure vulnerability in the NVIDIA GPU driver in Android before 2016-11-05 could enable a local malicious application to access da…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6721

An information disclosure vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a local malicious appl…

Fix: after 6.0.1
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6718

An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016-11-01 could enable a local malicious application to…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6710

An information disclosure vulnerability in the download manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11-01, and 7.0 bef…

Fix: 5.0.2 / 5.1.1+
Fix from $1,600 2016-11-25
Android MEDIUM 5.9
CVE-2016-6709

An information disclosure vulnerability in Conscrypt and BoringSSL in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable a man-in-t…

Fix: after 6.0.1
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6698

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-3907

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-3906

An information disclosure vulnerability in Qualcomm components including the GPU driver, power driver, SMSM Point-to-Point driver, and sound driver i…

Fix: after 7.0
Fix from $1,600 2016-11-25
Samsung Mobile MEDIUM 5.5
CVE-2016-9567

The mDNIe system service on Samsung Mobile S7 devices with M(6.0) software does not properly restrict setmDNIeScreenCurtain API calls, enabling attac…

Mitigation only
Fix from $1,600 2016-11-23
Simatic Cp 343 1 Firmware MEDIUM 5.3
CVE-2016-8672

A vulnerability has been identified in SIMATIC CP 343-1 Advanced (incl. SIPLUS NET variant) (All versions < V3.0.53), SIMATIC CP 443-1 Advanced (incl…

Mitigation only
Fix from $1,600 2016-11-23
Linux Kernel MEDIUM 5.0
CVE-2016-7917

The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is…

Fix: after 4.4.32
Fix from $1,600 2016-11-16
Linux Kernel MEDIUM 5.5
CVE-2015-8964

The tty_set_termios_ldisc function in drivers/tty/tty_ldisc.c in the Linux kernel before 4.5 allows local users to obtain sensitive information from …

Fix: after 4.4.32
Fix from $1,600 2016-11-16
Exponent Cms MEDIUM 5.3
CVE-2016-9286

framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows …

Patch available
Fix from $1,600 2016-11-11
Exponent Cms MEDIUM 5.3
CVE-2016-9285

framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modifie…

Patch available
Fix from $1,600 2016-11-11
Exponent Cms MEDIUM 5.3
CVE-2016-9284

getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via…

Patch available
Fix from $1,600 2016-11-11
Sql Server MEDIUM 6.5
CVE-2016-7252EPSS 18%

Microsoft SQL Server 2016 mishandles the FILESTREAM path, which allows remote authenticated users to gain privileges via unspecified vectors, aka "SQ…

Mitigation only
Fix from $1,600 2016-11-10
Excel For Mac MEDIUM 6.5
CVE-2016-7233EPSS 22%

Microsoft Word 2007, Office 2010 SP2, Word 2010 SP2, Word for Mac 2011, Excel for Mac 2011, Word Viewer, Office Compatibility Pack SP3, Word Automati…

Mitigation only
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.5
CVE-2016-7210EPSS 21%

atmfd.dll in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT…

Mitigation only
Fix from $1,600 2016-11-10
Gpu Driver MEDIUM 5.5
CVE-2016-7386

For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerabilit…

Fix: 342.00 / 375.63+
Fix from $1,600 2016-11-08
Exponent Cms HIGH 7.5
CVE-2016-9184

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in t…

Patch available
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9183

In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method …

Patch available
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9135

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version param…

Patch available
Fix from $1,950 2016-11-03
Exponent Cms HIGH 7.5
CVE-2016-9134

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure.

Patch available
Fix from $1,950 2016-11-03
GitLab MEDIUM 6.5
CVE-2016-9086EPSS 5%

GitLab versions 8.9.x and above contain a critical security flaw in the "import/export project" feature of GitLab. Added in GitLab 8.9, this feature …

Patch available
Fix from $1,600 2016-11-03
Mujs HIGH 7.5
CVE-2016-9017

Artifex Software, Inc. MuJS before a5c747f1d40e8d6659a37a8d25f13fb5acf8e767 allows context-dependent attackers to obtain sensitive information by usi…

Fix: after 5c337af4b3df80cf967e4f9f6a21522de84b392a
Fix from $1,950 2016-10-28