Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Icloud HIGH 7.8
CVE-2016-7583

An issue was discovered in certain Apple products. iCloud before 6.0.1 is affected. The issue involves the setup subsystem in the "iCloud" component.…

Fix: after 6.0.0
Fix from $1,950 2017-02-20
Mac Os X HIGH 8.8
CVE-2016-4617

An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process s…

Fix: after 10.11.6
Fix from $1,950 2017-02-20
Iphone Os HIGH 7.8
CVE-2016-4675

An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat…

Fix: 3.1 / 10.0.1+
Fix from $1,950 2017-02-20
Xenserver HIGH 7.5
CVE-2016-9637

The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS adminis…

Mitigation only
Fix from $1,950 2017-02-17
Unified Computing System Director HIGH 8.8
CVE-2017-3801

A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary work…

Mitigation only
Fix from $1,950 2017-02-15
Aix HIGH 7.8
CVE-2016-8972

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: I…

Patch available
Fix from $1,950 2017-02-15
Aix HIGH 7.8
CVE-2016-6079

IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I…

Patch available
Fix from $1,950 2017-02-15
Nagios HIGH 7.8
CVE-2016-10089

Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641.

Fix: after 4.2.4
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1880

The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain …

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1881

The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux c…

Mitigation only
Fix from $1,950 2017-02-15
FreeBSD HIGH 7.8
CVE-2016-1883

The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vector…

Mitigation only
Fix from $1,950 2017-02-15
Nport 5100 Series Firmware CRITICAL 9.8
CVE-2016-9366

An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2…

Fix: after 3.10
Fix from $2,300 2017-02-13
Oncellg3470a Lte Firmware CRITICAL 10.0
CVE-2016-8363

An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W…

Fix: after 10-31-2016
Fix from $2,300 2017-02-13
Deltav MEDIUM 6.8
CVE-2016-9345

An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow…

Mitigation only
Fix from $1,600 2017-02-13
Susiaccess HIGH 7.8
CVE-2016-9353

An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a stat…

Fix: after 3.0
Fix from $1,950 2017-02-13
Pi Web Api 2015 R2 MEDIUM 6.4
CVE-2016-8353

An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the P…

No fix yet
Fix from $1,600 2017-02-13
Jenesys Bas Bridge HIGH 7.1
CVE-2016-8357

An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and…

Fix: after 1.1.8
Fix from $1,950 2017-02-13
Ubuntu Linux CRITICAL 9.8
CVE-2015-8768

click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to instal…

Patch available
Fix from $2,300 2017-02-13
Bubblewrap HIGH 7.0
CVE-2016-8659

Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated …

Fix: after 0.1.1
Fix from $1,950 2017-02-13
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2017-3813

A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated…

No fix yet
Fix from $1,950 2017-02-09
Connect HIGH 7.2
CVE-2016-8494

Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a …

Mitigation only
Fix from $1,950 2017-02-09
Tivoli Storage Manager Fastback HIGH 7.3
CVE-2016-5934

IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted D…

Mitigation only
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8419

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8420

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8421

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8476

An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8480

An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t…

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Linux Kernel HIGH 7.0
CVE-2016-8481

An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.1
Fix from $1,950 2017-02-08
Util Linux HIGH 7.8
CVE-2016-2779

runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's …

Mitigation only
Fix from $1,950 2017-02-07
Linux Kernel HIGH 7.8
CVE-2016-10044

The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users …

Fix: 3.16.43 / 4.4.24+
Fix from $1,950 2017-02-07