Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Splunk CRITICAL 9.8
CVE-2016-10126

Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef…

Mitigation only
Fix from $2,300 2017-01-10
Scaleio HIGH 8.8
CVE-2016-9867

An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI …

Fix: after 2.0.1.0
Fix from $1,950 2017-01-06
Openssh HIGH 7.0
CVE-2016-10010

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to ga…

Fix: after 7.3
Fix from $1,950 2017-01-05
Arlo Base Station Firmware HIGH 8.1
CVE-2016-10116

NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with fi…

Fix: after 1.8.1_6094
Fix from $1,950 2017-01-04
Thinpro HIGH 7.8
CVE-2016-2246

HP ThinPro 4.4 through 6.1 mishandles the keyboard layout control panel and virtual keyboard application, which allows local users to bypass intended…

Patch available
Fix from $1,950 2016-12-29
Workstation Player HIGH 7.8
CVE-2016-7086

The installer in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows allows local users to gain pri…

Mitigation only
Fix from $1,950 2016-12-29
Vrealize Operations CRITICAL 10.0
CVE-2016-7457

VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to gain privileges, or halt and remove virtual machines, vi…

Mitigation only
Fix from $2,300 2016-12-29
Vrealize Operations HIGH 8.5
CVE-2016-7462

The Suite REST API in VMware vRealize Operations (aka vROps) 6.x before 6.4.0 allows remote authenticated users to write arbitrary content to files o…

Mitigation only
Fix from $1,950 2016-12-29
Linux Kernel HIGH 7.0
CVE-2016-6786

kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users…

Fix: 3.2.85 / 3.16.40+
Fix from $1,950 2016-12-28
Linux Kernel HIGH 7.0
CVE-2016-6787

kernel/events/core.c in the performance subsystem in the Linux kernel before 4.0 mismanages locks during certain migrations, which allows local users…

Fix: 3.2.85 / 3.16.40+
Fix from $1,950 2016-12-28
Wampserver HIGH 7.5
CVE-2016-10031

WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYSTEM privileges. This could po…

No fix yet
Fix from $1,950 2016-12-27
Wampserver MEDIUM 5.3
CVE-2016-10072

WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but…

No fix yet
Fix from $1,600 2016-12-27
Cloudcenter Orchestrator CRITICAL 9.8
CVE-2016-9223

A vulnerability in the Docker Engine configuration of Cisco CloudCenter Orchestrator (CCO; formerly CliQr) could allow an unauthenticated, remote att…

Mitigation only
Fix from $2,300 2016-12-26
Sprecon E Service Program HIGH 7.5
CVE-2016-10041

An issue was discovered in Sprecher Automation SPRECON-E Service Program before 3.43 SP0. Under certain preconditions, it is possible to execute tele…

Mitigation only
Fix from $1,950 2016-12-25
Windows 10 HIGH 7.8
CVE-2016-7260

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-12-20
Windows 10 HIGH 7.8
CVE-2016-7271

The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual t…

Mitigation only
Fix from $1,950 2016-12-20
Office HIGH 7.8
CVE-2016-7275

Microsoft Office 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016 mishandles library loading, which allows local users to gain privileges via a crafted appl…

Mitigation only
Fix from $1,950 2016-12-20
Joomla\! HIGH 7.5
CVE-2016-9837

An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 l…

Fix: after 3.6.4
Fix from $1,950 2016-12-16
Nagios HIGH 7.8
CVE-2016-9566

base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root privileges via a symlink att…

Fix: after 4.2.3
Fix from $1,950 2016-12-15
Ios Xr HIGH 7.8
CVE-2016-9215

A vulnerability in Cisco IOS XR Software could allow an authenticated, local attacker to log in to the device with the privileges of the root user. M…

Mitigation only
Fix from $1,950 2016-12-14
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2016-9192

A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to install and execute an arbitra…

Mitigation only
Fix from $1,950 2016-12-14
Hybrid Media Service HIGH 7.8
CVE-2016-6470

A vulnerability in the installation procedure of the Cisco Hybrid Media Service could allow an authenticated, local attacker to elevate privileges to…

Mitigation only
Fix from $1,950 2016-12-14
Fireamp Connector Endpoint Software HIGH 7.8
CVE-2016-6449

A vulnerability in the system management of certain FireAMP system processes in Cisco FireAMP Connector Endpoint software could allow an authenticate…

Mitigation only
Fix from $1,950 2016-12-14
Fedora CRITICAL 9.8
CVE-2016-7944

Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, w…

Fix: after 5.0.2
Fix from $2,300 2016-12-13
Fedora CRITICAL 9.8
CVE-2016-7942

The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, wh…

Fix: after 1.6.3
Fix from $2,300 2016-12-13
Android HIGH 7.8
CVE-2016-6706

An elevation of privilege vulnerability in libstagefright in Mediaserver in Android 7.0 before 2016-11-01 could enable a local malicious application …

Fix: after 7.0
Fix from $1,950 2016-12-13
Graphics Driver HIGH 7.8
CVE-2016-5647

The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allow…

Fix: after 15.40.4404
Fix from $1,950 2016-12-13
phpMyAdmin CRITICAL 9.8
CVE-2016-9849

An issue was discovered in phpMyAdmin. It is possible to bypass AllowRoot restriction ($cfg['Servers'][$i]['AllowRoot']) and deny rules for username …

Patch available
Fix from $2,300 2016-12-11
Fedora HIGH 8.1
CVE-2016-9014EPSS 6%

Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS …

Mitigation only
Fix from $1,950 2016-12-09
Linux Kernel HIGH 7.8
CVE-2016-9120

Race condition in the ion_ioctl function in drivers/staging/android/ion/ion.c in the Linux kernel before 4.6 allows local users to gain privileges or…

Fix: 3.16.40 / 3.18.51+
Fix from $1,950 2016-12-08