Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Db2 HIGH 7.3
CVE-2016-5995

Untrusted search path vulnerability in IBM DB2 9.7 through FP11, 10.1 through FP5, 10.5 before FP8, and 11.1 GA on Linux, AIX, and HP-UX allows local…

Patch available
Fix from $1,950 2016-10-01
Cloud Foundry Uaa Bosh HIGH 8.8
CVE-2016-6651

The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH…

Fix: after 242.0
Fix from $1,950 2016-09-30
Gnutls HIGH 7.5
CVE-2016-7444

The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCS…

Fix: after 3.4.14
Fix from $1,950 2016-09-27
Debian Linux MEDIUM 5.9
CVE-2016-7142

The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof ce…

Fix: after 2.0.22
Fix from $1,600 2016-09-26
Linux Virtual Delivery Agent HIGH 7.8
CVE-2016-6276

Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified…

Fix: after 1.3
Fix from $1,950 2016-09-26
Jboss Enterprise Application Platform HIGH 8.8
CVE-2016-5406

The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by…

Fix: after 7.0.1
Fix from $1,950 2016-09-26
Iphone Os HIGH 7.8
CVE-2016-4778

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Iphone Os HIGH 7.8
CVE-2016-4777

The kernel in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows attackers to execute arbitrary code in a privileged…

Fix: 3.0 / 10.0+
Fix from $1,950 2016-09-25
Mac Os X HIGH 7.8
CVE-2016-4716

diskutil in DiskArbitration in Apple OS X before 10.12 allows local users to gain privileges via unspecified vectors.

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Mac Os X MEDIUM 5.3
CVE-2016-4713

CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Application Policy Infrastructure Controller HIGH 7.8
CVE-2016-6413

The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local u…

Mitigation only
Fix from $1,950 2016-09-24
Email Security Appliance Firmware CRITICAL 9.8
CVE-2016-6406

Cisco IronPort AsyncOS 9.1.2-023, 9.1.2-028, 9.1.2-036, 9.7.2-046, 9.7.2-047, 9.7.2-054, 10.0.0-124, and 10.0.0-125 on Email Security Appliance (ESA)…

Mitigation only
Fix from $2,300 2016-09-22
Quickstart Cloud Installer HIGH 8.4
CVE-2016-6322

Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password f…

Mitigation only
Fix from $1,950 2016-09-22
Xen HIGH 8.2
CVE-2016-7093

Xen 4.5.3, 4.6.3, and 4.7.x allow local HVM guest OS administrators to overwrite hypervisor memory and consequently gain host OS privileges by levera…

Patch available
Fix from $1,950 2016-09-21
Xen HIGH 8.2
CVE-2016-7092

The get_page_from_l3e function in arch/x86/mm.c in Xen allows local 32-bit PV guest OS administrators to gain host OS privileges via vectors related …

Patch available
Fix from $1,950 2016-09-21
Performance Center HIGH 8.3
CVE-2016-4382

HPE Performance Center 11.52, 12.00, 12.01, 12.20, and 12.50 allows remote attackers to bypass intended access restrictions via unspecified vectors, …

Mitigation only
Fix from $1,950 2016-09-21
Avamar Server MEDIUM 6.5
CVE-2016-0921

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use weak permissions for unspecified directories, whic…

Fix: after 7.3.0
Fix from $1,600 2016-09-21
Vnx1 Oe Firmware CRITICAL 9.8
CVE-2016-0917

The SMB service in EMC VNXe (VNXe3200 Operating Environment prior to 3.1.5.8711957 and VNXe3100/3150/3300 Operating Environment prior to 2.4.4.22638)…

Mitigation only
Fix from $2,300 2016-09-21
Avamar Server MEDIUM 6.7
CVE-2016-0905

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 allow local users to obtain root privileges by leverag…

Fix: after 7.3.0
Fix from $1,600 2016-09-21
MySQL CRITICAL 9.8
CVE-2016-6662EPSS 68%

Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17;…

Fix: 5.5.51 / 10.0.27+
Fix from $2,300 2016-09-20
Eh6108h\+ Firmware CRITICAL 9.8
CVE-2016-6536

The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions…

Mitigation only
Fix from $2,300 2016-09-19
Unified Computing System HIGH 7.8
CVE-2016-6402

UCS Manager and UCS 6200 Fabric Interconnects in Cisco Unified Computing System (UCS) through 3.0(2d) allow local users to obtain OS root access via …

Mitigation only
Fix from $1,950 2016-09-18
Documentum D2 MEDIUM 5.3
CVE-2016-6644

EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of …

Fix: after 4.6
Fix from $1,600 2016-09-17
Windows 10 MEDIUM 5.5
CVE-2016-3373EPSS 17%

The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windo…

No fix yet
Fix from $1,600 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3355

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 20…

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3349

The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to …

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3348EPSS 13%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 HIGH 7.8
CVE-2016-3346

Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafte…

Mitigation only
Fix from $1,950 2016-09-14
Windows 10 MEDIUM 6.3
CVE-2016-3302

Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly …

Patch available
Fix from $1,600 2016-09-14
Firesight System Software CRITICAL 9.1
CVE-2016-6394

Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hija…

Mitigation only
Fix from $2,300 2016-09-12