Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Gpu Driver HIGH 7.8
CVE-2016-8824

All versions of NVIDIA Windows GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape where impr…

Patch available
Fix from $1,950 2016-12-16
Joomla\! HIGH 7.5
CVE-2016-9838EPSS 14%

An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored…

Fix: after 3.6.4
Fix from $1,950 2016-12-16
Nagios CRITICAL 9.8
CVE-2016-9565EPSS 23%

MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write to arbitrary files by spoofin…

Fix: after 4.2.1
Fix from $2,300 2016-12-15
Mailcwp CRITICAL 9.8
CVE-2016-1000156

Mailcwp remote file upload vulnerability incomplete fix v1.100

Fix: after 1.100
Fix from $2,300 2016-12-14
Fedora HIGH 7.5
CVE-2016-7952

X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecor…

Fix: after 1.2.2
Fix from $1,950 2016-12-13
Fedora HIGH 7.5
CVE-2016-7946

X.org libXi before 1.7.7 allows remote X servers to cause a denial of service (infinite loop) via vectors involving length fields.

Fix: after 1.7.6
Fix from $1,950 2016-12-13
Webmail HIGH 7.5
CVE-2016-9920EPSS 6%

steps/mail/sendmail.inc in Roundcube before 1.1.7 and 1.2.x before 1.2.3, when no SMTP server is configured and the sendmail program is enabled, does…

Fix: after 1.1.6
Fix from $1,950 2016-12-08
Android MEDIUM 5.9
CVE-2016-5341

The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an …

Fix: after 7.1.0
Fix from $1,600 2016-12-06
Joomla\! CRITICAL 9.8
CVE-2016-9836

The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking…

Fix: after 3.6.4
Fix from $2,300 2016-12-05
Zikula Application Framework CRITICAL 9.8
CVE-2016-9835

Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to laun…

Patch available
Fix from $2,300 2016-12-05
Sicam Pas\/pqs CRITICAL 9.8
CVE-2016-9157

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially…

Fix: 8.09+
Fix from $2,300 2016-12-05
Sicam Pas\/pqs HIGH 7.3
CVE-2016-9156

A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts …

Fix: 8.09+
Fix from $1,950 2016-12-05
Powerkvm MEDIUM 6.5
CVE-2016-3044

The Linux kernel component in IBM PowerKVM 2.1 before 2.1.1.3-65.10 and 3.1 before 3.1.0.2 allows guest OS users to cause a denial of service (host O…

Mitigation only
Fix from $1,600 2016-12-01
Ims Enterprise Suite HIGH 8.1
CVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify …

Fix: after 3.2.0.0
Fix from $1,950 2016-11-30
System Interface Foundation HIGH 7.8
CVE-2016-8223

During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software insta…

Fix: after 1.0.66.0
Fix from $1,950 2016-11-29
Hadoop HIGH 8.8
CVE-2016-5393

In Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3, a remote user who can authenticate with the HDFS NameNode can possibly run arbitrary comm…

Mitigation only
Fix from $1,950 2016-11-29
Linux Kernel MEDIUM 5.5
CVE-2016-8645

The TCP stack in the Linux kernel before 4.8.10 mishandles skb truncation, which allows local users to cause a denial of service (system crash) via a…

Fix: after 4.8.9
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 6.8
CVE-2016-8633

drivers/firewire/net.c in the Linux kernel before 4.8.7, in certain unusual hardware configurations, allows remote attackers to execute arbitrary cod…

Fix: after 4.8.6
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8630

The x86_decode_insn function in arch/x86/kvm/emulate.c in the Linux kernel before 4.8.7, when KVM is enabled, allows local users to cause a denial of…

Fix: after 4.8.6
Fix from $1,600 2016-11-28
Bigfix Remote Control HIGH 8.1
CVE-2016-2929

IBM BigFix Remote Control before 9.1.3 does not properly restrict password choices, which makes it easier for remote attackers to obtain access via a…

Fix: after 9.1.2
Fix from $1,950 2016-11-25
Jazz Reporting Service HIGH 7.5
CVE-2016-0319

The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administr…

Patch available
Fix from $1,950 2016-11-25
Jazz Reporting Service MEDIUM 5.0
CVE-2016-0318

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 does not destroy a Session ID upon a logout action, whi…

Patch available
Fix from $1,600 2016-11-25
Jazz Reporting Service MEDIUM 6.5
CVE-2016-0317

Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote attackers to conduct clickjacking attacks…

Patch available
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6747

A denial of service vulnerability in Mediaserver in Android before 2016-11-05 could enable an attacker to use a specially crafted file to cause a dev…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android CRITICAL 9.8
CVE-2016-6725

A remote code execution vulnerability in the Qualcomm crypto driver in Android before 2016-11-05 could enable a remote attacker to execute arbitrary …

Fix: after 7.0
Fix from $2,300 2016-11-25
Android MEDIUM 5.5
CVE-2016-6724

A denial of service vulnerability in the Input Manager Service in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-1…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6719

An elevation of privilege vulnerability in the Bluetooth component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 20…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6716

An elevation of privilege vulnerability in the AOSP Launcher in Android 7.0 before 2016-11-01 could allow a local malicious application to create sho…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6715

An elevation of privilege vulnerability in the Framework APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-11…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6714

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a …

Fix: after 6.0.1
Fix from $1,600 2016-11-25