Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Mate S Firmware HIGH 7.1
CVE-2016-8794

Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before…

Mitigation only
Fix from $1,950 2017-04-02
Usg5500 Firmware HIGH 7.5
CVE-2016-8798

Huawei USG5500 with software V300R001C00 and V300R001C00 allows attackers to bypass the anti-DDoS module of the USGs to cause a denial of service con…

Mitigation only
Fix from $1,950 2017-04-02
Campus S7700 Firmware HIGH 8.8
CVE-2014-4707

Huawei Campus S7700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300; S9300 with software V200R001C00SPC300, V200R002C00SPC100, …

Mitigation only
Fix from $1,950 2017-04-02
Hisuite HIGH 7.8
CVE-2016-8273

Huawei PC client software HiSuite 4.0.5.300_OVE uses insecure HTTP for upgrade software package download and does not check the integrity of the soft…

Mitigation only
Fix from $1,950 2017-04-02
Anti Malware Scan Engine HIGH 7.3
CVE-2016-8032

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local attackers to bypass local security …

Patch available
Fix from $1,950 2017-03-31
Wi Fi Pineapple Firmware HIGH 7.5
CVE-2015-4624EPSS 37%

Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.

No fix yet
Fix from $1,950 2017-03-31
Ambari CRITICAL 9.8
CVE-2016-6807

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that …

Mitigation only
Fix from $2,300 2017-03-28
Nextcloud Server MEDIUM 5.3
CVE-2016-9467

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in…

Fix: 9.0.6 / 9.0.54+
Fix from $1,600 2017-03-28
Nextcloud Server MEDIUM 5.3
CVE-2016-9468

Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message…

Fix: 9.0.6 / 9.0.54+
Fix from $1,600 2017-03-28
Go Jose HIGH 7.5
CVE-2016-9122

go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when val…

Fix: after 1.0.3
Fix from $1,950 2017-03-28
Nextcloud MEDIUM 5.3
CVE-2016-9460

Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the f…

Fix: after 9.0.51
Fix from $1,600 2017-03-28
Libgit2 MEDIUM 5.9
CVE-2016-10130

The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof ser…

Fix: after 0.24.5
Fix from $1,600 2017-03-24
Imagemagick CRITICAL 9.8
CVE-2016-10144

coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check.

Fix: 6.9.7-1+
Fix from $2,300 2017-03-24
Mediawiki MEDIUM 5.3
CVE-2015-8627

MediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 do not properly normalize IP addresses containing zero…

Fix: after 1.23.11
Fix from $1,600 2017-03-23
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-7468

An unauthenticated remote attacker may be able to disrupt services on F5 BIG-IP 11.4.1 - 11.5.4 devices with maliciously crafted network traffic. Thi…

Mitigation only
Fix from $1,600 2017-03-23
Edirectory HIGH 7.5
CVE-2016-5747

A security vulnerability in cookie handling in the http stack implementation in NDSD in Novell eDirectory before 9.0.1 allows remote attackers to byp…

Fix: after 9.0
Fix from $1,950 2017-03-23
Access Manager HIGH 8.8
CVE-2016-5750

The certificate upload feature in iManager in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 could be used to upload JSP pages …

Mitigation only
Fix from $1,950 2017-03-23
Imagemagick CRITICAL 9.8
CVE-2016-5239

The gnuplot delegate functionality in ImageMagick before 6.9.4-0 and GraphicsMagick allows remote attackers to execute arbitrary commands via unspeci…

Fix: after 6.9.3-9
Fix from $2,300 2017-03-15
Application Control MEDIUM 5.5
CVE-2013-7460

A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows aut…

Fix: after 6.1.0
Fix from $1,600 2017-03-14
Application Control MEDIUM 5.5
CVE-2013-7461

A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenti…

Fix: after 6.1.0
Fix from $1,600 2017-03-14
Application Control MEDIUM 5.9
CVE-2014-9920

Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before…

Mitigation only
Fix from $1,600 2017-03-14
Agent MEDIUM 5.3
CVE-2015-8987

Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attacke…

Fix: after 4.8.0
Fix from $1,600 2017-03-14
Host Intrusion Prevention Services MEDIUM 6.3
CVE-2016-8007

Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipul…

Fix: after 8.0
Fix from $1,600 2017-03-14
Application Control HIGH 7.8
CVE-2016-8010

Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and …

Fix: after 10.2
Fix from $1,950 2017-03-14
Xcomfort Ethernet Communication Interface HIGH 7.5
CVE-2016-9368

An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource lo…

Fix: after 1.07
Fix from $1,950 2017-03-14
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2016-9245

In F5 BIG-IP systems 12.1.0 - 12.1.2, malicious requests made to virtual servers with an HTTP profile can cause the TMM to restart. The issue is expo…

Mitigation only
Fix from $1,600 2017-03-07
Debian Linux HIGH 7.5
CVE-2016-6255EPSS 27%

Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a POST request without a registe…

Fix: after 1.6.20
Fix from $1,950 2017-03-07
Thinkserver Firmware HIGH 7.5
CVE-2016-8236

Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions ea…

Fix: after 3.76.208
Fix from $1,950 2017-03-03
Imagemagick HIGH 7.8
CVE-2016-10065

The ReadVIFFImage function in coders/viff.c in ImageMagick before 7.0.1-0 allows remote attackers to cause a denial of service (application crash) or…

Fix: after 6.9.7-10
Fix from $1,950 2017-03-03
Dropbear Ssh HIGH 8.8
CVE-2016-7408

The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.

Fix: after 2016.73
Fix from $1,950 2017-03-03