Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fedora HIGH 7.5
CVE-2016-5244EPSS 6%

The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remot…

Fix: after 4.6.3
Fix from $1,950 2016-06-27
Linux Kernel MEDIUM 5.5
CVE-2016-5243

The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4.6.3 does not properly copy a certain string, which a…

Fix: after 4.6.3
Fix from $1,600 2016-06-27
Linux Kernel MEDIUM 5.5
CVE-2014-9903

The sched_read_attr function in kernel/sched/core.c in the Linux kernel 3.14-rc before 3.14-rc4 uses an incorrect size, which allows local users to o…

Patch available
Fix from $1,600 2016-06-27
Garoon HIGH 7.5
CVE-2016-1193

Cybozu Garoon 3.7 through 4.2 allows remote attackers to obtain sensitive email-reading information via unspecified vectors.

No fix yet
Fix from $1,950 2016-06-25
Ocean Stor Firmware HIGH 7.3
CVE-2016-5722

Huawei OceanStor 5300 V3, 5500 V3, 5600 V3, 5800 V3, 6800 V3, 18800 V3, and 18500 V3 before V300R003C10 sends the plaintext session token in the HTTP…

Mitigation only
Fix from $1,950 2016-06-24
D3600 Firmware HIGH 7.5
CVE-2015-8289

The password-recovery feature on NETGEAR D3600 devices with firmware 1.0.0.49 and D6000 devices with firmware 1.0.0.49 and earlier allows remote atta…

Fix: after 1.0.0.49
Fix from $1,950 2016-06-20
Internet Security MEDIUM 6.5
CVE-2016-1225

Trend Micro Internet Security 8 and 10 allows remote attackers to read arbitrary files via unspecified vectors.

No fix yet
Fix from $1,600 2016-06-19
Wzr 600dhp3 Firmware MEDIUM 6.5
CVE-2016-4816

BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive…

Fix: after 2.16
Fix from $1,600 2016-06-19
Prime Network Registrar HIGH 7.5
CVE-2016-1427

The System Configuration Protocol (SCP) core messaging interface in Cisco Prime Network Registrar 8.2 before 8.2.3.1 and 8.3 before 8.3.2 allows remo…

Mitigation only
Fix from $1,950 2016-06-18
Office MEDIUM 5.5
CVE-2016-3234EPSS 24%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Office Compatibility Pack SP3, Word Viewer, Word Automation Services on SharePoint Server 20…

Mitigation only
Fix from $1,600 2016-06-16
Windows 10 MEDIUM 5.5
CVE-2016-3215EPSS 34%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 1511, and Microsoft Edge allow remote attackers to obtain sensitive information fr…

Patch available
Fix from $1,600 2016-06-16
Edge MEDIUM 6.5
CVE-2016-3201EPSS 24%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allow remote attackers to obtain sensitive infor…

Mitigation only
Fix from $1,600 2016-06-16
Outlook Web Access MEDIUM 5.5
CVE-2016-0028EPSS 23%

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 SP1, Cumulative Update 11, and Cumulative Update 12 and 2016 Gold and Cumulative Update 1 …

Mitigation only
Fix from $1,600 2016-06-16
Honor Ws851 Firmware HIGH 7.5
CVE-2016-5367

Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to obtain sensitive information via unspecified vectors, aka HWP…

Fix: after 1.1.21.1
Fix from $1,950 2016-06-14
Fedora CRITICAL 9.1
CVE-2015-8869EPSS 5%

OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive in…

Fix: after 4.02.3
Fix from $2,300 2016-06-13
Android MEDIUM 5.5
CVE-2016-2500

Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allow…

Mitigation only
Fix from $1,600 2016-06-13
Android MEDIUM 5.5
CVE-2016-2499

AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does …

Mitigation only
Fix from $1,600 2016-06-13
Android MEDIUM 5.5
CVE-2016-2498

The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a c…

Patch available
Fix from $1,600 2016-06-13
Uptime Infrastructure Monitor HIGH 7.5
CVE-2015-8268

The up.time agent in Idera Uptime Infrastructure Monitor 7.5 and 7.6 on Linux allows remote attackers to read arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,950 2016-06-10
Ubuntu Linux MEDIUM 5.5
CVE-2016-1582

LXD before 2.0.2 does not properly set permissions when switching an unprivileged container into privileged mode, which allows local users to access …

Mitigation only
Fix from $1,600 2016-06-09
Openshift MEDIUM 6.5
CVE-2016-2149

Red Hat OpenShift Enterprise 3.2 allows remote authenticated users to read log files from another namespace by using the same name as a previously de…

Mitigation only
Fix from $1,600 2016-06-08
Openshift MEDIUM 5.5
CVE-2016-2142

Red Hat OpenShift Enterprise 3.1 uses world-readable permissions on the /etc/origin/master/master-config.yaml configuration file, which allows local …

Mitigation only
Fix from $1,600 2016-06-08
Universal Cmbd Foundation HIGH 7.5
CVE-2016-4367EPSS 8%

The Universal Discovery component in HPE Universal CMDB 10.0, 10.01, 10.10, 10.11, 10.20, and 10.21 allows remote attackers to obtain sensitive infor…

Mitigation only
Fix from $1,950 2016-06-08
Matrix Operating Environment HIGH 7.5
CVE-2016-2027

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerabil…

Fix: after 7.5
Fix from $1,950 2016-06-08
Systems Insight Manager HIGH 7.5
CVE-2016-2026

HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerabil…

Fix: after 7.5
Fix from $1,950 2016-06-08
Checkpoint\/restore In Userspace MEDIUM 5.5
CVE-2015-5231

The service daemon in CRIU does not properly restrict access to non-dumpable processes, which allows local users to obtain sensitive information via …

Mitigation only
Fix from $1,600 2016-06-07
Satellite CRITICAL 9.1
CVE-2015-5041

The J9 JVM in IBM SDK, Java Technology Edition 6 before SR16 FP20, 6 R1 before SR8 FP20, 7 before SR9 FP30, and 7 R1 before SR3 FP30 allows remote at…

Fix: 6.0.16.20 / 6.1.8.20+
Fix from $2,300 2016-06-06
Debian Linux MEDIUM 6.5
CVE-2016-1698

The createCustomType function in extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.79 does not val…

Fix: after 51.0.2704.63
Fix from $1,600 2016-06-05
Debian Linux MEDIUM 6.5
CVE-2016-1687

The renderer implementation in Google Chrome before 51.0.2704.63 does not properly restrict public exposure of classes, which allows remote attackers…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome MEDIUM 6.5
CVE-2016-1677

uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to o…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05