Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox HIGH 7.4
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changin…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Firefox HIGH 8.8
CVE-2016-1954

The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prev…

Fix: after 44.0.2
Fix from $1,950 2016-03-13
Android MEDIUM 6.1
CVE-2016-0832

Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection pr…

Mitigation only
Fix from $1,600 2016-03-12
Android HIGH 7.8
CVE-2016-0826

libcameraservice in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not require use of the ICameraSe…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.0
CVE-2016-0822

The MediaTek connectivity kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application that leverag…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.8
CVE-2016-0820

The MediaTek Wi-Fi kernel driver in Android 6.0.1 before 2016-03-01 allows attackers to gain privileges via a crafted application, aka internal bug 2…

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.8
CVE-2016-0819

The Qualcomm performance component in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows attackers to gain privilege…

Mitigation only
Fix from $1,950 2016-03-12
Tivoli Monitoring CRITICAL 9.9
CVE-2015-7411

The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gai…

Mitigation only
Fix from $2,300 2016-03-12
Windows 10 MEDIUM 6.8
CVE-2016-0133

The USB Mass Storage Class driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012…

Mitigation only
Fix from $1,600 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0096

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0095

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

Mitigation only
Fix from $1,950 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0094

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

No fix yet
Fix from $1,950 2016-03-09
Windows 10 HIGH 7.8
CVE-2016-0093

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

No fix yet
Fix from $1,950 2016-03-09
Office HIGH 7.8
CVE-2016-0057

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 does not properly sign an unspecified binary file, which allows local users to gain privilege…

Mitigation only
Fix from $1,950 2016-03-09
Chrome CRITICAL 9.8
CVE-2016-1636

The PendingScript::notifyFinished function in WebKit/Source/core/dom/PendingScript.cpp in Google Chrome before 49.0.2623.75 relies on memory-cache in…

Fix: after 48.0.2564.116
Fix from $2,300 2016-03-06
Chrome HIGH 8.8
CVE-2016-1632

The Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly maintain own properties, which allows remote attackers to bypass inte…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Chrome HIGH 8.8
CVE-2016-1631

The PPB_Flash_MessageLoop_Impl::InternalRun function in content/renderer/pepper/ppb_flash_message_loop_impl.cc in the Pepper plugin in Google Chrome …

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Chrome HIGH 8.8
CVE-2016-1630

The ContainerNode::parserRemoveChild function in WebKit/Source/core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 49.0.2623.75, mis…

Fix: after 48.0.2564.116
Fix from $1,950 2016-03-06
Wireshark HIGH 7.8
CVE-2016-2521

Untrusted search path vulnerability in the WiresharkApplication class in ui/qt/wireshark_application.cpp in Wireshark 1.12.x before 1.12.10 and 2.0.x…

Mitigation only
Fix from $1,950 2016-02-28
Debian Linux MEDIUM 6.3
CVE-2016-0763EPSS 11%

The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x befo…

Mitigation only
Fix from $1,600 2016-02-25
Tomcat HIGH 8.8
CVE-2016-0714EPSS 13%

The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles s…

Mitigation only
Fix from $1,950 2016-02-25
Nx Os CRITICAL 9.8
CVE-2016-1341

Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to ga…

Mitigation only
Fix from $2,300 2016-02-24
Moodle MEDIUM 6.8
CVE-2015-5266

The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 all…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Moodle MEDIUM 5.4
CVE-2015-5264

The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypa…

Fix: after 2.6.11
Fix from $1,600 2016-02-22
Chrome CRITICAL 9.8
CVE-2016-1629

Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified …

Fix: after 48.0.2564.109
Fix from $2,300 2016-02-21
Tivoli Storage Flashcopy Manager For Vmware CRITICAL 10.0
CVE-2015-7425

The Data Protection component in the VMware vSphere GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spect…

Mitigation only
Fix from $2,300 2016-02-21
Asr 5000 Series Software HIGH 7.5
CVE-2016-1335

The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key auth…

Mitigation only
Fix from $1,950 2016-02-19
Encryption Management Server HIGH 7.8
CVE-2015-8150

Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.

Fix: after 3.3.2
Fix from $1,950 2016-02-18
Netscaler CRITICAL 9.8
CVE-2016-2071

Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e b…

Mitigation only
Fix from $2,300 2016-02-17
PostgreSQL HIGH 8.8
CVE-2016-0766

PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 does not properly restrict access to u…

Fix: 9.1.20 / 9.2.15+
Fix from $1,950 2016-02-17