Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Security Qradar Incident Forensics MEDIUM 6.5
CVE-2016-2968

IBM Security QRadar Incident Forensics 7.2.x before 7.2.7 allows remote attackers to bypass authentication, and obtain sensitive information or modif…

Mitigation only
Fix from $1,600 2016-07-02
Prime Collaboration Provisioning CRITICAL 9.8
CVE-2016-1416

Cisco Prime Collaboration Provisioning 10.6 SP2 (aka 10.6.0.10602) mishandles LDAP authentication, which allows remote attackers to obtain administra…

Mitigation only
Fix from $2,300 2016-07-02
Messagesight HIGH 8.8
CVE-2016-0375

JMS Client in IBM MessageSight 1.1.x through 1.1.0.1, 1.2.x through 1.2.0.3, and 2.0.x through 2.0.0.0 allows remote authenticated users to obtain ad…

Mitigation only
Fix from $1,950 2016-07-01
Tririga Application Platform HIGH 8.8
CVE-2016-0374

The builder tools in IBM TRIRIGA Application Platform 3.3 before 3.3.2.6, 3.4 before 3.4.2.4, and 3.5 before 3.5.0.2 allow remote authenticated users…

Mitigation only
Fix from $1,950 2016-07-01
Big Ip Wan Optimization Manager HIGH 8.8
CVE-2016-5020

F5 BIG-IP before 12.0.0 HF3 allows remote authenticated users to modify the account configuration of users with the Resource Administration role and …

Mitigation only
Fix from $1,950 2016-06-30
Bios Efi Driver HIGH 8.2
CVE-2016-5729

Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2016-06-30
Solution Center HIGH 7.8
CVE-2016-5249

Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Se…

Fix: after 3.3.002
Fix from $1,950 2016-06-30
Solution Center MEDIUM 5.5
CVE-2016-5248

The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via …

Fix: after 3.3.002
Fix from $1,600 2016-06-30
Mate 8 Firmware HIGH 7.8
CVE-2016-5231

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows at…

Mitigation only
Fix from $1,950 2016-06-30
Mate 8 Firmware HIGH 8.8
CVE-2016-5230

Huawei Mate8 NXT-AL before NXT-AL10C00B182, NXT-CL before NXT-CL00C92B182, NXT-DL before NXT-DL00C17B182, and NXT-TL before NXT-TL00C01B182 allows at…

Mitigation only
Fix from $1,950 2016-06-30
General Parallel File System Storage Server HIGH 7.0
CVE-2016-0263

IBM Spectrum Scale 4.1 before 4.1.1.5 and 4.2 before 4.2.0.2 and General Parallel File System 3.5 before 3.5.0.30 allow local users to gain privilege…

Mitigation only
Fix from $1,950 2016-06-29
Linux Kernel HIGH 7.8
CVE-2016-4440

arch/x86/kvm/vmx.c in the Linux kernel through 4.6.3 mishandles the APICv on/off state, which allows guest OS users to obtain direct APIC MSR access …

Fix: 4.7+
Fix from $1,950 2016-06-27
Fusioninsight Hd HIGH 7.8
CVE-2016-5723

Huawei FusionInsight HD before V100R002C60SPC200 allows local users to gain root privileges via unspecified vectors.

No fix yet
Fix from $1,950 2016-06-24
Curl HIGH 7.8
CVE-2016-4802

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to exe…

Fix: after 7.49.0
Fix from $1,950 2016-06-24
Ip Phone 8800 Series Firmware HIGH 7.0
CVE-2016-1435

Cisco 8800 phones with software 11.0(1) do not properly enforce mounted-filesystem permissions, which allows local users to write to arbitrary files …

Mitigation only
Fix from $1,950 2016-06-23
Fonality HIGH 7.8
CVE-2016-2363

Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 uses weak permissions for the /var/www/rpc/surun script, which allows local us…

Mitigation only
Fix from $1,950 2016-06-20
Emc Data Domain Os CRITICAL 9.8
CVE-2016-0912

EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging acc…

Fix: after 5.7.1.0
Fix from $2,300 2016-06-19
Emc Data Domain Os HIGH 8.2
CVE-2016-0911

EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 has a default no_root_squash option for NFS exports, which makes it easier for remote attackers to …

Fix: after 5.7.1.0
Fix from $1,950 2016-06-19
Virtualization Manager HIGH 7.8
CVE-2016-3643 KEV

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by…

Fix: after 6.3.1
Fix from $1,950 2016-06-17
Windows HIGH 7.3
CVE-2016-4158

Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privile…

Fix: after 3.6.0.248
Fix from $1,950 2016-06-16
Creative Cloud HIGH 7.3
CVE-2016-4157

Untrusted search path vulnerability in the installer in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to ga…

Fix: after 3.6.0.248
Fix from $1,950 2016-06-16
Windows 10 HIGH 7.8
CVE-2016-3225EPSS 43%

The SMB server component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and…

No fix yet
Fix from $1,950 2016-06-16
Windows 10 HIGH 8.1
CVE-2016-3223EPSS 21%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Win…

No fix yet
Fix from $1,950 2016-06-16
Windows 10 HIGH 7.8
CVE-2016-3221EPSS 6%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-06-16
Windows 10 HIGH 7.8
CVE-2016-3220EPSS 6%

atmfd.dll in the Adobe Type Manager Font Driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windo…

No fix yet
Fix from $1,950 2016-06-16
Windows 10 HIGH 7.8
CVE-2016-3219EPSS 6%

The kernel-mode driver in Microsoft Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation o…

No fix yet
Fix from $1,950 2016-06-16
Windows 10 HIGH 7.8
CVE-2016-3218

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-06-16
Internet Explorer HIGH 8.8
CVE-2016-3213EPSS 67%

The Web Proxy Auto Discovery (WPAD) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window…

Mitigation only
Fix from $1,950 2016-06-16
Honor Ws851 Firmware CRITICAL 9.8
CVE-2016-5365

Stack-based buffer overflow in Huawei Honor WS851 routers with software 1.1.21.1 and earlier allows remote attackers to execute arbitrary commands wi…

Fix: after 1.1.21.1
Fix from $2,300 2016-06-14
Firefox HIGH 7.8
CVE-2016-2826

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification d…

Fix: after 46.0.1
Fix from $1,950 2016-06-13