Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2016-2849 Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which migh… Debian Linux Mitigation only Fix from $1,9502016-05-13 HIGH 7.5 CVE-2015-7827 Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, … Fedora after 1.10.13 Fix from $1,9502016-05-13 CRITICAL 9.8 CVE-2016-1112 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo… Acrobat after 15.010.20060 Fix from $2,3002016-05-11 HIGH 7.5 CVE-2016-1092 Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo… Acrobat after 15.010.20060 Fix from $1,9502016-05-11 HIGH 7.5 CVE-2016-1079EPSS 10% Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo… Acrobat after 15.010.20060 Fix from $1,9502016-05-11 MEDIUM 5.5 CVE-2016-0190 Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB … Windows 8.1 Mitigation only Fix from $1,6002016-05-11 MEDIUM 6.5 CVE-2016-0169EPSS 43% GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, … Windows 10 No fix yet Fix from $1,6002016-05-11 MEDIUM 6.5 CVE-2016-0168EPSS 43% GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, … Windows 10 No fix yet Fix from $1,6002016-05-11 MEDIUM 5.9 CVE-2016-0149EPSS 8% Microsoft .NET Framework 2.0 SP2, 3.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows man-in-the-middle attackers to obtain sensitive cleartext informa… .net Framework Mitigation only Fix from $1,6002016-05-11 MEDIUM 5.5 CVE-2016-2460 mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure… Android Mitigation only Fix from $1,6002016-05-09 MEDIUM 5.5 CVE-2016-2459 mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not initialize certain data structure… Android Mitigation only Fix from $1,6002016-05-09 MEDIUM 5.5 CVE-2016-2458 The compose functionality in AOSP Mail in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-05-01 does not properly restrict attach… Android Mitigation only Fix from $1,6002016-05-09 MEDIUM 5.9 CVE-2015-6551 Veritas NetBackup 7.x through 7.5.0.7 and 7.6.0.x through 7.6.0.4 and NetBackup Appliance through 2.5.4 and 2.6.0.x through 2.6.0.4 do not use TLS fo… Netbackup Appliance Mitigation only Fix from $1,6002016-05-07 MEDIUM 6.5 CVE-2016-2013 HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unsp… Network Node Manager I Patch available Fix from $1,6002016-05-07 MEDIUM 5.5 CVE-2016-3717EPSS 20% The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. Ubuntu Linux Patch available Fix from $1,6002016-05-05 MEDIUM 5.9 CVE-2016-2107EPSS 89% The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which … Enterprise Linux Desktop after 1.0.1s Fix from $1,6002016-05-05 HIGH 7.5 CVE-2016-2117EPSS 6% The atl2_probe function in drivers/net/ethernet/atheros/atlx/atl2.c in the Linux kernel through 4.5.2 incorrectly enables scatter/gather I/O, which a… Ubuntu Linux after 4.5.2 Fix from $1,9502016-05-02 MEDIUM 5.5 CVE-2015-4176 fs/namespace.c in the Linux kernel before 4.0.2 does not properly support mount connectivity, which allows local users to read arbitrary files by lev… Linux Kernel after 4.0.1 Fix from $1,6002016-05-02 MEDIUM 6.5 CVE-2016-2813 Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to … Firefox after 45.0.2 Fix from $1,6002016-04-30 MEDIUM 5.3 CVE-2016-1199 The login page in the management screen in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to bypass intended IP address restrictions via … Ec Cube Patch available Fix from $1,6002016-04-30 MEDIUM 6.5 CVE-2016-1595EPSS 7% LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to co… Service Desk after 7.1 Fix from $1,6002016-04-22 MEDIUM 6.5 CVE-2016-1594EPSS 7% Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as de… Service Desk after 7.1 Fix from $1,6002016-04-22 MEDIUM 5.3 CVE-2016-2302 Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages. Integraxor after 4.2.4502 Fix from $1,6002016-04-22 HIGH 7.5 CVE-2016-2294 The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-se… Acuvim Ii Net Firmware after 3.08 Fix from $1,9502016-04-21 MEDIUM 6.2 CVE-2015-1776 Apache Hadoop 2.6.x encrypts intermediate data generated by a MapReduce job and stores it along with the encryption key in a credentials file on disk… Hadoop Mitigation only Fix from $1,6002016-04-19 MEDIUM 6.5 CVE-2016-3688 SQL injection vulnerability in dotCMS before 3.5 allows remote administrators to execute arbitrary SQL commands via the c0-e3 parameter to dwr/call/p… Dotcms after 3.3.1 Fix from $1,6002016-04-19 HIGH 8.1 CVE-2016-1651 fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 50.0.2661.75, does not properly implement the sycc420_to_rgb and sycc42… Chrome after 49.0.2623.112 Fix from $1,9502016-04-18 MEDIUM 5.5 CVE-2016-2427 The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it e… Bc Java Mitigation only Fix from $1,6002016-04-18 MEDIUM 5.5 CVE-2016-2426 server/content/ContentService.java in the Framework component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201… Android Mitigation only Fix from $1,6002016-04-18 MEDIUM 5.5 CVE-2016-2425 mail/compose/ComposeActivity.java in AOSP Mail in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 support… Android Patch available Fix from $1,6002016-04-18