Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Debian Linux HIGH 7.5
CVE-2016-2849

Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh…

Mitigation only
Fix from $1,950 2016-05-13
Fedora HIGH 7.5
CVE-2015-7827

Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, …

Fix: after 1.10.13
Fix from $1,950 2016-05-13
Acrobat CRITICAL 9.8
CVE-2016-1112

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat HIGH 7.5
CVE-2016-1092

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $1,950 2016-05-11
Acrobat HIGH 7.5
CVE-2016-1079EPSS 10%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $1,950 2016-05-11
Windows 8.1 MEDIUM 5.5
CVE-2016-0190

Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB …

Mitigation only
Fix from $1,600 2016-05-11
Windows 10 MEDIUM 6.5
CVE-2016-0169EPSS 43%

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

No fix yet
Fix from $1,600 2016-05-11
Windows 10 MEDIUM 6.5
CVE-2016-0168EPSS 43%

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

No fix yet
Fix from $1,600 2016-05-11
.net Framework MEDIUM 5.9
CVE-2016-0149EPSS 8%

Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext informa…

Mitigation only
Fix from $1,600 2016-05-11
Android MEDIUM 5.5
CVE-2016-2460

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure…

Mitigation only
Fix from $1,600 2016-05-09
Android MEDIUM 5.5
CVE-2016-2459

mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure…

Mitigation only
Fix from $1,600 2016-05-09
Android MEDIUM 5.5
CVE-2016-2458

The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attach…

Mitigation only
Fix from $1,600 2016-05-09
Netbackup Appliance MEDIUM 5.9
CVE-2015-6551

Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS fo…

Mitigation only
Fix from $1,600 2016-05-07
Network Node Manager I MEDIUM 6.5
CVE-2016-2013

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unsp…

Patch available
Fix from $1,600 2016-05-07
Ubuntu Linux MEDIUM 5.5
CVE-2016-3717EPSS 20%

The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image.

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop MEDIUM 5.9
CVE-2016-2107EPSS 89%

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which …

Fix: after 1.0.1s
Fix from $1,600 2016-05-05
Ubuntu Linux HIGH 7.5
CVE-2016-2117EPSS 6%

The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which a…

Fix: after 4.5.2
Fix from $1,950 2016-05-02
Linux Kernel MEDIUM 5.5
CVE-2015-4176

fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by lev…

Fix: after 4.0.1
Fix from $1,600 2016-05-02
Firefox MEDIUM 6.5
CVE-2016-2813

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Ec Cube MEDIUM 5.3
CVE-2016-1199

The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via …

Patch available
Fix from $1,600 2016-04-30
Service Desk MEDIUM 6.5
CVE-2016-1595EPSS 7%

LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to co…

Fix: after 7.1
Fix from $1,600 2016-04-22
Service Desk MEDIUM 6.5
CVE-2016-1594EPSS 7%

Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as de…

Fix: after 7.1
Fix from $1,600 2016-04-22
Integraxor MEDIUM 5.3
CVE-2016-2302

Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.

Fix: after 4.2.4502
Fix from $1,600 2016-04-22
Acuvim Ii Net Firmware HIGH 7.5
CVE-2016-2294

The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-se…

Fix: after 3.08
Fix from $1,950 2016-04-21
Hadoop MEDIUM 6.2
CVE-2015-1776

Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk…

Mitigation only
Fix from $1,600 2016-04-19
Dotcms MEDIUM 6.5
CVE-2016-3688

SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/p…

Fix: after 3.3.1
Fix from $1,600 2016-04-19
Chrome HIGH 8.1
CVE-2016-1651

fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc42…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Bc Java MEDIUM 5.5
CVE-2016-2427

The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it e…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-2426

server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 5.5
CVE-2016-2425

mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 support…

Patch available
Fix from $1,600 2016-04-18