Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-6686

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6685

The kernel in Android before 2016-10-05 on Nexus 6P devices allows attackers to obtain sensitive information via a crafted application, aka internal …

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6684

The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Android One devices allows attackers to o…

Mitigation only
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6683

The kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6682

drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6681

drivers/misc/qcom/qdsp6v2/audio_utils.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices does…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android HIGH 7.8
CVE-2016-6680

CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obtain…

Fix: after 7.0
Fix from $1,950 2016-10-10
Android MEDIUM 5.5
CVE-2016-6679

CORE/HDD/src/wlan_hdd_hostapd.c in the Qualcomm Wi-Fi driver in Android before 2016-10-05 on Nexus 5X and Android One devices allows attackers to obt…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6678

The Motorola USBNet driver in Android before 2016-10-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6677

The NVIDIA GPU driver in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3924

services/audioflinger/Effects.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 …

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3918

email/provider/AttachmentProvider.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7…

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3902

drivers/platform/msm/ipa/ipa_qmi_service.c in the Qualcomm IPA driver in Android before 2016-10-05 on Nexus 5X and 6P devices allows attackers to obt…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3860

sound/soc/msm/qdsp6v2/audio_calibration.c in the Qualcomm sound driver in Android before 2016-10-05 on Nexus 5X, Nexus 6P, and Android One devices al…

Fix: after 7.0
Fix from $1,600 2016-10-10
Linux Kernel MEDIUM 5.5
CVE-2015-8950

arch/arm64/mm/dma-mapping.c in the Linux kernel before 4.0.3, as used in the ION subsystem in Android and other products, does not initialize certain…

Fix: after 4.0.2
Fix from $1,600 2016-10-10
Fedora HIGH 7.5
CVE-2015-2080EPSS 75%

The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via i…

No fix yet
Fix from $1,950 2016-10-07
Mypixs HIGH 7.5
CVE-2015-1000012EPSS 9%

Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin

No fix yet
Fix from $1,950 2016-10-06
Mp3 Jplayer MEDIUM 5.3
CVE-2015-1000008

Path Disclosure Vulnerability in wordpress plugin MP3-jPlayer v2.3.2

Mitigation only
Fix from $1,600 2016-10-06
Wptf Image Gallery HIGH 7.5
CVE-2015-1000007

Remote file download vulnerability in wptf-image-gallery v1.03

No fix yet
Fix from $1,950 2016-10-06
Cloud Foundry Cf Mysql HIGH 7.5
CVE-2016-6653

The MariaDB audit_plugin component in Pivotal Cloud Foundry (PCF) cf-mysql-release 27 and 28 allows remote attackers to obtain sensitive information …

Mitigation only
Fix from $1,950 2016-10-06
Secure Firewall Management Center MEDIUM 6.5
CVE-2016-6435EPSS 37%

The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug …

No fix yet
Fix from $1,600 2016-10-06
Sterling Secure Proxy MEDIUM 5.3
CVE-2016-6026

The Configuration Manager in IBM Sterling Secure Proxy (SSP) 3.4.2 before 3.4.2.0 iFix 8 and 3.4.3 before 3.4.3.0 iFix 1 allows man-in-the-middle att…

Mitigation only
Fix from $1,600 2016-10-06
Nx Os HIGH 7.5
CVE-2016-1455

Cisco NX-OS before 7.0(3)I2(2e) and 7.0(3)I4 before 7.0(3)I4(1) has an incorrect iptables local-interface configuration, which allows remote attacker…

Mitigation only
Fix from $1,950 2016-10-05
Fortiwlc HIGH 7.2
CVE-2016-7561

Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by…

Fix: after 6.1-2-29
Fix from $1,950 2016-10-05
Firesight System Software MEDIUM 6.5
CVE-2016-6420

Cisco FireSIGHT System Software 4.10.3 through 5.4.0 in Firepower Management Center allows remote authenticated users to bypass authorization checks …

Mitigation only
Fix from $1,600 2016-10-05
Aspect Matrix Building Automation Front End Solutions Application HIGH 7.5
CVE-2016-2307

American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End So…

Fix: after 2.0
Fix from $1,950 2016-10-05
Ceph Storage HIGH 7.5
CVE-2016-7031

The RGW code in Ceph before 10.0.1, when authenticated-read ACL is applied to a bucket, allows remote attackers to list the bucket contents via a URL.

Fix: after 10.0.0
Fix from $1,950 2016-10-03
MongoDB MEDIUM 5.5
CVE-2016-6494

The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by rea…

Fix: 3.0.15 / 3.2.14+
Fix from $1,600 2016-10-03
Websphere Application Server HIGH 7.5
CVE-2016-5986

IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, 8.5.x before 8.5.5.11, 9.0.x before 9.0.0.2, and Liberty before 16…

Patch available
Fix from $1,950 2016-10-01
Trex MEDIUM 5.3
CVE-2016-6146

The NameServer in SAP TREX 7.10 Revision 63 allows remote attackers to obtain sensitive TNS information via an unspecified query, aka SAP Security No…

No fix yet
Fix from $1,600 2016-09-27