Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Linux Kernel HIGH 7.8
CVE-2016-2066

Integer signedness error in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions f…

Fix: after 3.19.8
Fix from $1,950 2016-06-13
Linux Kernel HIGH 7.8
CVE-2016-2061

Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions fo…

Fix: after 3.19.8
Fix from $1,950 2016-06-13
Linux Kernel HIGH 7.0
CVE-2016-2059

The msm_ipc_router_bind_control_port function in net/ipc_router/ipc_router_core.c in the IPC router kernel module for the Linux kernel 3.x, as used i…

Fix: after 7.0
Fix from $1,950 2016-05-05
Linux Kernel HIGH 7.8
CVE-2016-2854

The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leve…

Fix: after 4.20.15
Fix from $1,950 2016-05-02
Linux Kernel HIGH 7.8
CVE-2016-2853

The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mount…

Fix: after 4.20.15
Fix from $1,950 2016-05-02
Linux Kernel HIGH 7.8
CVE-2016-1575

The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which allows local users to gain priv…

Fix: after 4.5.2
Fix from $1,950 2016-05-02
Windows 10 1507 HIGH 7.8
CVE-2016-0151 KEVEPSS 63%

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 …

Patch available
Fix from $1,950 2016-04-12
Ubuntu Linux HIGH 7.8
CVE-2015-8539

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl command…

Fix: 4.4+
Fix from $1,950 2016-02-08
Ubuntu Linux HIGH 8.4
CVE-2016-1572

mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mount…

Fix: 109+
Fix from $1,950 2016-01-22
Debian Linux HIGH 7.5
CVE-2015-8467

The samldb_check_user_account_control_acl function in dsdb/samdb/ldb_modules/samldb.c in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x befor…

Fix: 4.1.22 / 4.2.7+
Fix from $1,950 2015-12-29
Acrobat MEDIUM 6.8
CVE-2015-5106

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Acrobat HIGH 7.2
CVE-2015-5090

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 15.006.30060 / 15.008.20082+
Fix from $1,950 2015-07-15
Acrobat HIGH 7.5
CVE-2015-4446EPSS 5%

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,950 2015-07-15
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-0192

Unspecified vulnerability in IBM Java 8 before SR1, 7 R1 before SR2 FP11, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 F…

Fix: 5.0.16.10 / 6.1.8.4+
Fix from $2,300 2015-07-02
Mguard Firmware HIGH 9.0
CVE-2014-9193

Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP conf…

Fix: after 7.6.6
Fix from $1,950 2014-12-20
Linux Kernel HIGH 7.8
CVE-2014-9322

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register,…

Fix: 3.2.65 / 3.4.106+
Fix from $1,950 2014-12-17
Debian Linux HIGH 7.2
CVE-2014-3689

The vmware-vga driver (hw/display/vmware_vga.c) in QEMU allows local guest users to write to qemu memory locations and gain privileges via unspecifie…

Fix: after 2.1.3
Fix from $1,950 2014-11-14
Keystone MEDIUM 6.5
CVE-2014-0204

OpenStack Identity (Keystone) before 2014.1.1 does not properly handle when a role is assigned to a group that has the same ID as a user, which allow…

Fix: 2014.1.1+
Fix from $1,600 2014-11-03
Linux Kernel HIGH 7.2
CVE-2014-5206

The do_remount function in fs/namespace.c in the Linux kernel through 3.16.1 does not maintain the MNT_LOCK_READONLY bit across a remount of a bind m…

Fix: 3.10.55 / 3.12.27+
Fix from $1,950 2014-08-18
Linux Kernel MEDIUM 6.2
CVE-2014-5207

fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MA…

Fix: after 3.16.1
Fix from $1,600 2014-08-18
Linux Kernel HIGH 7.2
CVE-2014-3534

arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRAC…

Fix: 3.2.62 / 3.4.101+
Fix from $1,950 2014-08-01
Linux Kernel MEDIUM 6.9
CVE-2014-4943

The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by leveraging data-structure dif…

Fix: 3.2.62 / 3.4.102+
Fix from $1,600 2014-07-19
Keystone MEDIUM 6.0
CVE-2014-3476

OpenStack Identity (Keystone) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 does not properly handle chained delegation, which allo…

Fix: 2013.2.4 / 2014.1.2+
Fix from $1,600 2014-06-17
Firefox MEDIUM 6.9
CVE-2014-1520

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows l…

Fix: 24.5 / 29.0+
Fix from $1,600 2014-04-30
Firefox MEDIUM 6.8
CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended acce…

Fix: 2.26 / 29.0+
Fix from $1,600 2014-04-30
Firefox HIGH 8.8
CVE-2014-1529

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remo…

Fix: 24.5 / 29.0+
Fix from $1,950 2014-04-30
Firefox MEDIUM 5.5
CVE-2014-1496

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privile…

Fix: 2.25 / 24.4+
Fix from $1,600 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1510EPSS 82%

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows re…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Firefox CRITICAL 9.8
CVE-2014-1511EPSS 84%

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the po…

Fix: 24.4 / 28.0+
Fix from $2,300 2014-03-19
Ubuntu Linux MEDIUM 5.8
CVE-2013-6391

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when on…

Fix: 2013.2.1+
Fix from $1,600 2013-12-14