Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Android HIGH 7.8
CVE-2016-2494

Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows attackers t…

No fix yet
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2493

The Broadcom Wi-Fi driver in Android before 2016-06-01 on Nexus 5, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus Player, and Pixel C devices allows attack…

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2492

The MediaTek power-management driver in Android before 2016-06-01 on Android One devices allows attackers to gain privileges via a crafted applicatio…

Patch available
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2491

The NVIDIA camera driver in Android before 2016-06-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal …

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2490

The NVIDIA camera driver in Android before 2016-06-01 on Nexus 9 devices allows attackers to gain privileges via a crafted application, aka internal …

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2489

The Qualcomm video driver in Android before 2016-06-01 on Nexus 5, 5X, 6, and 6P devices allows attackers to gain privileges via a crafted applicatio…

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Android HIGH 7.8
CVE-2016-2488

The Qualcomm camera driver in Android before 2016-06-01 on Nexus 5, 5X, 6, 6P, and 7 (2013) devices allows attackers to gain privileges via a crafted…

Fix: after 6.0.1
Fix from $1,950 2016-06-13
Data Domain Os HIGH 8.8
CVE-2016-0910

EMC Data Domain OS 5.5 before 5.5.4.0, 5.6 before 5.6.1.004, and 5.7 before 5.7.2.0 stores session identifiers of GUI users in a world-readable file,…

Fix: after 5.7.1.0
Fix from $1,950 2016-06-10
Openshift HIGH 8.8
CVE-2016-3738

Red Hat OpenShift Enterprise 3.2 does not properly restrict access to STI builds, which allows remote authenticated users to access the Docker socket…

Mitigation only
Fix from $1,950 2016-06-08
Openshift Origin HIGH 8.8
CVE-2016-2160

Red Hat OpenShift Enterprise 3.2 and OpenShift Origin allow remote authenticated users to execute commands with root privileges by changing the root …

Patch available
Fix from $1,950 2016-06-08
Vm Server MEDIUM 6.7
CVE-2016-4962

The libxl device-handling in Xen 4.6.x and earlier allows local OS guest administrators to cause a denial of service (resource consumption or managem…

Mitigation only
Fix from $1,600 2016-06-07
Debian Linux HIGH 7.8
CVE-2015-5723

Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x b…

Fix: after 2.4.7
Fix from $1,950 2016-06-07
Opensuse HIGH 7.8
CVE-2015-5228

The service daemon in CRIU creates log and dump files insecurely, which allows local users to create arbitrary files and take ownership of existing f…

Mitigation only
Fix from $1,950 2016-06-07
Isilon Onefs MEDIUM 6.7
CVE-2016-0908

EMC Isilon OneFS 7.1.x before 7.1.1.9 and 7.2.x before 7.2.1.2 allows local users to obtain root shell access by leveraging administrative privileges.

Mitigation only
Fix from $1,600 2016-06-04
Docker HIGH 7.8
CVE-2016-3697

libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allow…

Fix: after 1.11.1
Fix from $1,950 2016-06-01
Intuitive 650 Tdb Controller HIGH 8.8
CVE-2016-4505

Resource Data Management (RDM) Intuitive 650 TDB Controller devices before 2.1.24 allow remote authenticated users to modify arbitrary passwords via …

Fix: after 2.1
Fix from $1,950 2016-05-31
Connect HIGH 7.8
CVE-2016-4118

Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via…

Fix: after 9.5.2
Fix from $1,950 2016-05-30
FreeBSD HIGH 7.8
CVE-2016-1887

Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows …

No fix yet
Fix from $1,950 2016-05-25
Go HIGH 7.8
CVE-2016-3958

Untrusted search path vulnerability in Go before 1.5.4 and 1.6.x before 1.6.1 on Windows allows local users to gain privileges via a Trojan horse DLL…

Fix: 1.5.4 / 1.6.1+
Fix from $1,950 2016-05-23
Mobile Broadband Hl Service HIGH 7.8
CVE-2016-2855

The Huawei Mobile Broadband HL Service 22.001.25.00.03 and earlier uses a weak ACL for the MobileBrServ program data directory, which allows local us…

Fix: after 22.001.25.00.03
Fix from $1,950 2016-05-23
Linux Kernel HIGH 7.8
CVE-2016-4565

The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denia…

Fix: 3.2.81 / 3.10.103+
Fix from $1,950 2016-05-23
Moodle MEDIUM 5.3
CVE-2016-2190

Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which a…

Fix: after 2.6.11
Fix from $1,600 2016-05-22
Safemode HIGH 8.1
CVE-2016-3693

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obt…

Fix: after 1.2.3
Fix from $1,950 2016-05-20
Itunes HIGH 7.8
CVE-2016-1742

Untrusted search path vulnerability in the installer in Apple iTunes before 12.4 allows local users to gain privileges via a Trojan horse DLL in the …

Fix: after 12.3.1
Fix from $1,950 2016-05-20
Vm Server HIGH 8.4
CVE-2016-4480

The guest_walk_tables function in arch/x86/mm/guest_walk.c in Xen 4.6.x and earlier does not properly handle the Page Size (PS) page table entry bit …

Fix: after 4.6.1
Fix from $1,950 2016-05-18
Player CRITICAL 9.8
CVE-2016-2077

VMware Workstation 11.x before 11.1.3 and VMware Player 7.x before 7.1.3 on Windows incorrectly access an executable file, which allows host OS users…

Mitigation only
Fix from $2,300 2016-05-18
Ubuntu Core Launcher CRITICAL 9.8
CVE-2016-1580

The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when usi…

Mitigation only
Fix from $2,300 2016-05-13
Windows 10 HIGH 7.8
CVE-2016-0197

dxgkrnl.sys in the DirectX Graphics kernel subsystem in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, W…

Mitigation only
Fix from $1,950 2016-05-11
Windows 10 HIGH 7.8
CVE-2016-0196

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-05-11
Windows 10 HIGH 7.8
CVE-2016-0180

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows R…

Mitigation only
Fix from $1,950 2016-05-11