Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
File Transfer Appliance HIGH 7.8
CVE-2016-2353

The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows local users to add an SSH key to an arbitrary group, and consequently gain priv…

Fix: after 9_11_210
Fix from $1,950 2016-05-07
File Transfer Appliance HIGH 8.8
CVE-2016-2352EPSS 5%

The Accellion File Transfer Appliance (FTA) before FTA_9_12_40 allows remote authenticated users to execute arbitrary commands by leveraging the YUM_…

Fix: after 9_11_210
Fix from $1,950 2016-05-07
Linux Kernel HIGH 7.8
CVE-2015-2686

net/socket.c in the Linux kernel 3.19 before 3.19.3 does not validate certain range data for (1) sendto and (2) recvfrom system calls, which allows l…

Patch available
Fix from $1,950 2016-05-02
Debian Linux HIGH 7.8
CVE-2015-8325

The do_setup_env function in session.c in sshd in OpenSSH through 7.2p2, when the UseLogin feature is enabled and PAM is configured to read .pam_envi…

Fix: after 7.2
Fix from $1,950 2016-05-01
Firefox MEDIUM 5.4
CVE-2016-2817

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inh…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 5.0
CVE-2016-2810

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that le…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Firefox MEDIUM 5.5
CVE-2016-2809

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by …

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Application Policy Infrastructure Controller Enterprise Module HIGH 7.5
CVE-2016-1386

The API in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0(1) allows remote attackers to spoof administrative noti…

Mitigation only
Fix from $1,950 2016-04-28
Acuvim Iir Net Firmware HIGH 8.6
CVE-2016-2293

The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover settings via a dire…

Fix: after 3.08
Fix from $1,950 2016-04-21
Altiris It Management Suite MEDIUM 5.5
CVE-2016-2202

The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local us…

Fix: after 7.6
Fix from $1,600 2016-04-20
iOS HIGH 7.5
CVE-2016-1384

The NTP implementation in Cisco IOS 15.1 and 15.5 and IOS XE 3.2 through 3.17 allows remote attackers to modify the system time via crafted packets, …

Mitigation only
Fix from $1,950 2016-04-20
Fedora HIGH 8.8
CVE-2016-3960

Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privi…

Patch available
Fix from $1,950 2016-04-19
Leap MEDIUM 5.5
CVE-2016-4036

The quagga package before 0.99.23-2.6.1 in openSUSE and SUSE Linux Enterprise Server 11 SP 1 uses weak permissions for /etc/quagga, which allows loca…

Mitigation only
Fix from $1,600 2016-04-18
Android MEDIUM 6.1
CVE-2016-2423

server/telecom/CallsManager.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not…

Mitigation only
Fix from $1,600 2016-04-18
Android HIGH 7.8
CVE-2016-2422

Wi-Fi in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not prevent use of a Wi-Fi CA certificate i…

Mitigation only
Fix from $1,950 2016-04-18
Android MEDIUM 6.1
CVE-2016-2421

Setup Wizard in Android 5.1.x before 5.1.1 and 6.x before 2016-04-01 allows physically proximate attackers to bypass the Factory Reset Protection pro…

Patch available
Fix from $1,600 2016-04-18
Android HIGH 7.8
CVE-2016-2420

rootdir/init.rc in Android 4.x before 4.4.4 does not ensure that the /data/tombstones directory exists for the Debuggerd component, which allows atta…

Mitigation only
Fix from $1,950 2016-04-18
Android CRITICAL 9.8
CVE-2016-2419

media/libmedia/IDrm.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize a certain key-request data structure, which allows attack…

Mitigation only
Fix from $2,300 2016-04-18
Android CRITICAL 9.8
CVE-2016-2416

libs/gui/BufferQueueConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does n…

Mitigation only
Fix from $2,300 2016-04-18
Android CRITICAL 9.8
CVE-2016-2417EPSS 5%

media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initia…

No fix yet
Fix from $2,300 2016-04-18
Android HIGH 7.8
CVE-2016-2413

media/libmedia/IOMX.cpp in mediaserver in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 does not initialize a handle poin…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 7.8
CVE-2016-2412

include/core/SkPostConfig.h in Skia, as used in System_server in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 201…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 7.4
CVE-2016-2410

A Qualcomm video kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that leverages control …

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.1
CVE-2016-2409

A Texas Instruments (TI) haptic kernel driver in Android 6.x before 2016-04-01 allows attackers to gain privileges via a crafted application that lev…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.8
CVE-2016-0850

The PORCHE_PAIRING_CONFLICT feature in Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allow…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0847

The Telecom Component in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 allows attackers to spoof the originating telephon…

Mitigation only
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0846

libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-0…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0844

The Qualcomm RF driver in Android 6.x before 2016-04-01 does not properly restrict access to socket ioctl calls, which allows attackers to gain privi…

Patch available
Fix from $1,950 2016-04-18
Android HIGH 8.4
CVE-2016-0843

The Qualcomm ARM processor performance-event manager in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-04-01 a…

Patch available
Fix from $1,950 2016-04-18
Junos HIGH 8.8
CVE-2016-1264

Race condition in the Op command in Juniper Junos OS before 12.1X44-D55, 12.1X46 before 12.1X46-D40, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R11,…

Fix: after 12.1x44
Fix from $1,950 2016-04-15