Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Android MEDIUM 5.5
CVE-2016-6713

A remote denial of service vulnerability in Mediaserver in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 could enable an attacker to use a …

Fix: after 6.0.1
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6708

An elevation of privilege in the System UI in Android 7.0 before 2016-11-01 could enable a local malicious user to bypass the security prompt of your…

Fix: after 7.0
Fix from $1,600 2016-11-25
Android HIGH 7.8
CVE-2016-6703

A remote code execution vulnerability in an Android runtime library in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo…

Fix: after 6.0.1
Fix from $1,950 2016-11-25
Android HIGH 7.8
CVE-2016-6702

A remote code execution vulnerability in libjpeg in Android 4.x before 4.4.4, 5.0.x before 5.0.2, and 5.1.x before 5.1.1 could enable an attacker usi…

Mitigation only
Fix from $1,950 2016-11-25
Android HIGH 7.8
CVE-2016-6701

A remote code execution vulnerability in libskia in Android 7.0 before 2016-11-01 could enable an attacker using a specially crafted file to cause me…

Fix: after 7.0
Fix from $1,950 2016-11-25
Ccid1445 Dn18 Firmware CRITICAL 9.8
CVE-2016-9155

The following SIEMENS branded IP Camera Models CCMW3025, CVMW3025-IR, CFMW3025 prior to version 1.41_SP18_S1; CCPW3025, CCPW5025 prior to version 0.1…

Patch available
Fix from $2,300 2016-11-22
Primary Setup Tool MEDIUM 6.4
CVE-2016-7165

A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2…

Fix: after 14.0
Fix from $1,600 2016-11-15
Windows 10 HIGH 7.8
CVE-2016-7248EPSS 22%

Microsoft Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote…

Mitigation only
Fix from $1,950 2016-11-10
Windows 10 HIGH 7.5
CVE-2016-7247EPSS 6%

Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allow physically pro…

Mitigation only
Fix from $1,950 2016-11-10
Office MEDIUM 5.5
CVE-2016-7244EPSS 16%

Microsoft Office 2007 SP3 allows remote attackers to cause a denial of service (application hang) via a crafted Office document, aka "Microsoft Offic…

Mitigation only
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.5
CVE-2016-7237EPSS 67%

Local Security Authority Subsystem Service (LSASS) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wi…

No fix yet
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.1
CVE-2016-7226

Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local us…

No fix yet
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.1
CVE-2016-7225

Virtual Hard Disk Driver in Windows 10 Gold, 1511, and 1607 and Windows Server 2016 does not properly restrict access to files, which allows local us…

No fix yet
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.1
CVE-2016-7224

Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Serv…

No fix yet
Fix from $1,600 2016-11-10
Windows 10 MEDIUM 6.1
CVE-2016-7223

Virtual Hard Disk Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, and 1607, and Windows Serv…

Mitigation only
Fix from $1,600 2016-11-10
Windows 10 HIGH 7.8
CVE-2016-7212EPSS 70%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows…

Mitigation only
Fix from $1,950 2016-11-10
Receiver Desktop MEDIUM 6.8
CVE-2016-9111

Incorrect access control mechanisms in Citrix Receiver Desktop Lock 4.5 allow an attacker to bypass the authentication requirement by leveraging phys…

No fix yet
Fix from $1,600 2016-11-07
Pillow HIGH 7.8
CVE-2016-9190

Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure …

Fix: after 3.3.1
Fix from $1,950 2016-11-04
Exponent Cms HIGH 7.5
CVE-2016-9182

Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method …

Patch available
Fix from $1,950 2016-11-04
Financial Transaction Manager MEDIUM 5.7
CVE-2016-3060

Payments Director in IBM Financial Transaction Manager (FTM) for ACH Services, Check Services, and Corporate Payment Services (CPS) 3.0.0.x before fp…

Patch available
Fix from $1,600 2016-10-29
Open Source Security Information And Event Management CRITICAL 9.8
CVE-2016-8580EPSS 7%

PHP object injection vulnerabilities exist in multiple widget files in AlienVault OSSIM and USM before 5.3.2. These vulnerabilities allow arbitrary P…

Fix: after 5.3.1
Fix from $2,300 2016-10-28
Peoplesoft Enterprise Peopletools HIGH 7.6
CVE-2016-8296

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote authenticated …

Patch available
Fix from $1,950 2016-10-25
Peoplesoft Enterprise Peopletools HIGH 8.2
CVE-2016-8293

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to a…

Patch available
Fix from $1,950 2016-10-25
Peoplesoft Enterprise Peopletools HIGH 8.2
CVE-2016-8291

Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.54 and 8.55 allows remote attackers to a…

Patch available
Fix from $1,950 2016-10-25
Platform Security For Java HIGH 7.6
CVE-2016-8281

Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allow…

Patch available
Fix from $1,950 2016-10-25
Flexcube Universal Banking MEDIUM 6.1
CVE-2016-5622

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through…

Patch available
Fix from $1,600 2016-10-25
Flexcube Universal Banking MEDIUM 5.4
CVE-2016-5620

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through…

Patch available
Fix from $1,600 2016-10-25
Flexcube Universal Banking HIGH 8.1
CVE-2016-5619

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through…

Patch available
Fix from $1,950 2016-10-25
Vm Virtualbox MEDIUM 6.8
CVE-2016-5610

Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to a…

Fix: 5.0.28 / 5.1.8+
Fix from $1,600 2016-10-25
Vm Virtualbox MEDIUM 5.5
CVE-2016-5608

Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to a…

Fix: 5.0.28 / 5.1.8+
Fix from $1,600 2016-10-25