Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Edge MEDIUM 6.5
CVE-2016-3374EPSS 26%

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote at…

Mitigation only
Fix from $1,600 2016-09-14
Windows 10 MEDIUM 5.5
CVE-2016-3371EPSS 40%

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windo…

No fix yet
Fix from $1,600 2016-09-14
Edge MEDIUM 6.5
CVE-2016-3370EPSS 22%

The PDF library in Microsoft Edge, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote at…

Mitigation only
Fix from $1,600 2016-09-14
Office MEDIUM 6.5
CVE-2016-0141

The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save oper…

Mitigation only
Fix from $1,600 2016-09-14
iOS MEDIUM 5.3
CVE-2016-6398

The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from…

Mitigation only
Fix from $1,600 2016-09-12
Tivoli Storage Manager For Space Management MEDIUM 5.5
CVE-2016-5927

IBM Tivoli Storage Manager for Space Management (aka Spectrum Protect for Space Management) 6.3.x before 6.3.2.6, 6.4.x before 6.4.3.3, and 7.1.x bef…

Patch available
Fix from $1,600 2016-09-12
PHP MEDIUM 5.3
CVE-2016-7128EPSS 8%

The exif_process_IFD_in_TIFF function in ext/exif/exif.c in PHP before 5.6.25 and 7.x before 7.0.10 mishandles the case of a thumbnail offset that ex…

Fix: after 5.6.24
Fix from $1,600 2016-09-12
Android MEDIUM 5.5
CVE-2016-3897

The WifiEnterpriseConfig class in net/wifi/WifiEnterpriseConfig.java in Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3896

AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows attackers to obtain sensitive EmailAc…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3895

Integer overflow in the Region::unflatten function in libs/ui/Region.cpp in mediaserver in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 al…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3894

The Qualcomm DMA component in Android before 2016-09-05 on Nexus 6 devices allows attackers to obtain sensitive information via a crafted application…

Fix: after 7.0
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3893

The wcdcal_hwdep_ioctl_shared function in sound/soc/codecs/wcdcal-hwdep.c in the Qualcomm sound codec in Android before 2016-09-05 on Nexus 6P device…

Fix: after 7.0
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3892

The Qualcomm SPMI driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafte…

Fix: after 7.0
Fix from $1,600 2016-09-11
Drupal MEDIUM 5.3
CVE-2016-6212

The Views module 7.x-3.x before 7.x-3.14 in Drupal 7.x and the Views module in Drupal 8.x before 8.1.3 might allow remote authenticated users to bypa…

Mitigation only
Fix from $1,600 2016-09-09
Junos CRITICAL 9.8
CVE-2016-1279

J-Web in Juniper Junos OS before 12.1X46-D45, 12.1X46-D50, 12.1X47 before 12.1X47-D35, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D25, 13.3 before 1…

Fix: after 12.1x46
Fix from $2,300 2016-09-09
Uma MEDIUM 6.5
CVE-2016-7108

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote authenticated users to obtain the MD5 hashes of arbitrary user p…

Mitigation only
Fix from $1,600 2016-09-07
Rh5885 V3 Server Firmware HIGH 7.5
CVE-2016-6899

The Intelligent Baseboard Management Controller (iBMC) in Huawei RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers with sof…

Mitigation only
Fix from $1,950 2016-09-07
Rh1288 V3 Server Firmware HIGH 7.5
CVE-2016-6838

Huawei X6800 and XH620 V3 servers with software before V100R003C00SPC606, RH1288 V3 servers with software before V100R003C00SPC613, RH2288 V3 servers…

Mitigation only
Fix from $1,950 2016-09-07
S12700 MEDIUM 5.3
CVE-2016-6670

Huawei S7700, S9300, S9700, and S12700 devices with software before V200R008C00SPC500 use random numbers with insufficient entropy to generate self-s…

Mitigation only
Fix from $1,600 2016-09-07
Tryton MEDIUM 5.3
CVE-2016-1241

Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to disc…

Mitigation only
Fix from $1,600 2016-09-07
Resteasy MEDIUM 6.5
CVE-2016-6345

RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.

Mitigation only
Fix from $1,600 2016-09-07
Jboss Bpm Suite MEDIUM 5.3
CVE-2016-6344

Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attacke…

Mitigation only
Fix from $1,600 2016-09-07
Chrome MEDIUM 5.3
CVE-2016-7153EPSS 14%

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for …

Mitigation only
Fix from $1,600 2016-09-06
Safari MEDIUM 5.3
CVE-2016-7152EPSS 14%

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for r…

Mitigation only
Fix from $1,600 2016-09-06
Jose Php MEDIUM 5.3
CVE-2016-5430

The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which m…

Fix: 2.2.1+
Fix from $1,600 2016-09-03
Small Business 220 Series Smart Plus Switches CRITICAL 9.8
CVE-2016-1473

Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community, which allows remote attackers to read or modify SNMP o…

Mitigation only
Fix from $2,300 2016-09-02
Jwcrypto MEDIUM 5.3
CVE-2016-6298

The _Rsa15 class in the RSA 1.5 algorithm implementation in jwa.py in jwcrypto before 0.3.2 lacks the Random Filling protection mechanism, which make…

Fix: 0.3.2+
Fix from $1,600 2016-09-01
Clustered Data Ontap MEDIUM 6.5
CVE-2016-3064

NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant informat…

Fix: after 8.2.4
Fix from $1,600 2016-09-01
Jboss Enterprise Application Platform HIGH 7.5
CVE-2016-2183EPSS 96%

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately…

Fix: 0.10.47 / 0.12.16+
Fix from $1,950 2016-09-01
Readynas Surveillance HIGH 7.5
CVE-2016-5677EPSS 12%

NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622…

No fix yet
Fix from $1,950 2016-08-31