Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 7.0
CVE-2016-3890

The Java Debug Wire Protocol (JDWP) implementation in adb/sockets.cpp in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x be…

Patch available
Fix from $1,950 2016-09-11
Android MEDIUM 6.8
CVE-2016-3889

Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mecha…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3887

providers/settings/SettingsProvider.java in Android 7.0 before 2016-09-01 does not properly enforce the DISALLOW_CONFIG_VPN setting, which allows att…

Patch available
Fix from $1,950 2016-09-11
Android MEDIUM 6.8
CVE-2016-3886

systemui/statusbar/phone/QuickStatusBarHeader.java in the System UI Tuner in Android 7.0 before 2016-09-01 does not prevent tuner changes on the lock…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3885

debuggerd/debuggerd.cpp in Debuggerd in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles t…

Patch available
Fix from $1,950 2016-09-11
Android MEDIUM 6.8
CVE-2016-3876

providers/settings/SettingsProvider.java in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 allows physically proximate attackers to bypass t…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 6.8
CVE-2016-3875

server/wm/WindowManagerService.java in Android 6.x before 2016-09-01 does not enforce the DISALLOW_SAFE_BOOT setting, which allows physically proxima…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3874

CORE/HDD/src/wlan_hdd_wext.c in the Qualcomm Wi-Fi driver in Android before 2016-09-05 on Nexus 5X devices does not properly validate the arguments a…

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3873

The NVIDIA kernel in Android before 2016-09-05 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal bug 295…

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3871

Multiple buffer overflows in codecs/mp3dec/SoftMP3.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3870

omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3869

The Broadcom Wi-Fi driver in Android before 2016-09-05 on Nexus 5, Nexus 6, Nexus 6P, Nexus 9, Nexus Player, and Pixel C devices allows attackers to …

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3868

The Qualcomm power driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka …

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3867

The Qualcomm IPA driver in Android before 2016-09-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka An…

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3866

The Qualcomm sound driver in Android before 2016-09-05 on Nexus 5X, 6, and 6P devices allows attackers to gain privileges via a crafted application, …

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3865

The Synaptics touchscreen driver in Android before 2016-09-05 on Nexus 5X and 9 devices allows attackers to gain privileges via a crafted application…

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3864

The Qualcomm radio interface layer in Android before 2016-09-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allows attackers to …

Fix: after 7.0
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3861EPSS 10%

LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 mishandles conversions…

Patch available
Fix from $1,950 2016-09-11
Android HIGH 7.8
CVE-2016-3859

The Qualcomm camera driver in Android before 2016-09-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted applicati…

Fix: after 7.0
Fix from $1,950 2016-09-11
Drupal HIGH 8.8
CVE-2016-6211

The User module in Drupal 7.x before 7.44 allows remote authenticated users to gain privileges via vectors involving contributed or custom code that …

Mitigation only
Fix from $1,950 2016-09-09
Fortiswitch CRITICAL 9.8
CVE-2016-4573

Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-224D-FPOE, FSW-248D-POE, FSW-248D-FPOE, FSW-424D, FSW-424D-POE, FSW-424D…

Mitigation only
Fix from $2,300 2016-09-09
Jboss Operations Network HIGH 8.8
CVE-2016-5422

The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, wh…

Fix: after 3.3.6
Fix from $1,950 2016-09-07
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2016-6369

Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges…

Mitigation only
Fix from $1,950 2016-08-25
Rapidstream HIGH 7.8
CVE-2016-7089

WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLO…

No fix yet
Fix from $1,950 2016-08-24
Aironet Access Point Software HIGH 7.8
CVE-2016-6362

Cisco Aironet 1800, 2800, and 3800 devices with software before 8.2.110.0, 8.2.12x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow local users to …

Mitigation only
Fix from $1,950 2016-08-22
Authentication Manager Prime HIGH 8.1
CVE-2016-0915

The Self-Service Portal in EMC RSA Authentication Manager (AM) Prime Self-Service 3.0 and 3.1 before 3.1 1915.42871 allows remote authenticated users…

Mitigation only
Fix from $1,950 2016-08-22
Big Ip Global Traffic Manager HIGH 7.5
CVE-2015-8022

The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10,…

Mitigation only
Fix from $1,950 2016-08-19
Iphone Os HIGH 7.8
CVE-2016-4654

IOMobileFrameBuffer in Apple iOS before 9.3.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory…

Mitigation only
Fix from $1,950 2016-08-18
Secure Firewall Management Center HIGH 8.8
CVE-2016-1458

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.0.3, 5.3.1.x before 5.3.1.2, and 5.4.x before 5.4.0.1 and Cisco Adaptiv…

Mitigation only
Fix from $1,950 2016-08-18
Secure Firewall Management Center HIGH 8.8
CVE-2016-1457

The web-based GUI in Cisco Firepower Management Center 4.x and 5.x before 5.3.1.2 and 5.4.x before 5.4.0.1 and Cisco Adaptive Security Appliance (ASA…

Mitigation only
Fix from $1,950 2016-08-18