Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Jdk CRITICAL 9.6
CVE-2016-5568

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability vi…

Patch available
Fix from $2,300 2016-10-25
Solaris MEDIUM 5.3
CVE-2016-5566

Unspecified vulnerability in Oracle Sun Solaris 11.3 allows remote attackers to affect confidentiality via unknown vectors.

Patch available
Fix from $1,600 2016-10-25
Hospitality Opera 5 Property Services HIGH 7.7
CVE-2016-5565

Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5…

Patch available
Fix from $1,950 2016-10-25
Iprocurement HIGH 7.6
CVE-2016-5562

Unspecified vulnerability in the Oracle iProcurement component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remo…

Patch available
Fix from $1,950 2016-10-25
Siebel Customer Order Management MEDIUM 5.4
CVE-2016-5560

Unspecified vulnerability in the Siebel UI Framework component in Oracle Siebel CRM 16.1 allows remote authenticated users to affect confidentiality …

Patch available
Fix from $1,600 2016-10-25
Advanced Pricing HIGH 8.2
CVE-2016-5557

Unspecified vulnerability in the Oracle Advanced Pricing component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows …

Patch available
Fix from $1,950 2016-10-25
Jdk CRITICAL 9.6
CVE-2016-5556

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, and 8u102 allows remote attackers to affect confidentiality, integrity, and availability vi…

Patch available
Fix from $2,300 2016-10-25
Platform Security For Java HIGH 7.6
CVE-2016-5536

Unspecified vulnerability in the Oracle Platform Security for Java component in Oracle Fusion Middleware 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allow…

Patch available
Fix from $1,950 2016-10-25
Siebel User Interface Framework MEDIUM 6.5
CVE-2016-5534

Unspecified vulnerability in the Siebel Apps - Customer Order Management component in Oracle Siebel CRM 16.1 allows remote authenticated users to aff…

Patch available
Fix from $1,600 2016-10-25
Primavera P6 Enterprise Project Portfolio Management MEDIUM 5.4
CVE-2016-5533

Unspecified vulnerability in the Primavera P6 Enterprise Project Portfolio Management component in Oracle Primavera Products Suite 8.4, 15.x, and 16.…

Patch available
Fix from $1,600 2016-10-25
Shipping Execution MEDIUM 5.3
CVE-2016-5532

Unspecified vulnerability in the Oracle Shipping Execution component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allow…

Patch available
Fix from $1,600 2016-10-25
Agile Product Lifecycle Management MEDIUM 5.9
CVE-2016-5527

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,600 2016-10-25
Agile Product Lifecycle Management HIGH 7.3
CVE-2016-5526

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,950 2016-10-25
Agile Product Lifecycle Management MEDIUM 6.5
CVE-2016-5521

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,600 2016-10-25
Applications Dba MEDIUM 5.5
CVE-2016-5517

Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 12.1.3 allows local users to affect confidentiality via…

Patch available
Fix from $1,600 2016-10-25
Flexcube Universal Banking MEDIUM 5.4
CVE-2016-5502

Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through…

Patch available
Fix from $1,600 2016-10-25
Database MEDIUM 6.4
CVE-2016-5497

Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity,…

Patch available
Fix from $1,600 2016-10-25
Discoverer HIGH 7.5
CVE-2016-5495

Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality…

Patch available
Fix from $1,950 2016-10-25
Sun Zfs Storage Appliance Kit HIGH 7.1
CVE-2016-5492

Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun Systems Products Suite AK 2013 allows local users to affe…

Patch available
Fix from $1,950 2016-10-25
Commerce Service Center HIGH 8.2
CVE-2016-5491

Unspecified vulnerability in the Oracle Commerce Service Center component in Oracle Commerce 10.0.3.5 and 10.2.0.5 allows remote attackers to affect …

Patch available
Fix from $1,950 2016-10-25
Commerce Guided Search HIGH 8.2
CVE-2016-5482

Unspecified vulnerability in the Oracle Commerce Guided Search component in Oracle Commerce 6.2.2, 6.3.0, 6.4.1.2, and 6.5.0 through 6.5.2 allows rem…

Patch available
Fix from $1,950 2016-10-25
Tgcaptcha2 HIGH 7.5
CVE-2016-1000032

TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.

Mitigation only
Fix from $1,950 2016-10-25
Commons Fileupload CRITICAL 9.8
CVE-2016-1000031EPSS 34%

Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution

Fix: after 1.3.2
Fix from $2,300 2016-10-25
Security Guardium Database Activity Monitor HIGH 8.8
CVE-2016-0241

IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authent…

Patch available
Fix from $1,950 2016-10-22
Edge MEDIUM 5.3
CVE-2016-3392EPSS 10%

The Edge Content Security Policy feature in Microsoft Edge does not properly validate documents, which allows remote attackers to bypass intended acc…

Mitigation only
Fix from $1,600 2016-10-14
Windows 10 HIGH 7.8
CVE-2016-0142EPSS 20%

Video Control in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers…

Mitigation only
Fix from $1,950 2016-10-14
Acrobat CRITICAL 9.8
CVE-2016-6958

Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.017.20053
Fix from $2,300 2016-10-13
Enterprise Linux Desktop HIGH 8.8
CVE-2016-4286EPSS 6%

Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637 on Linux allows attackers to…

Fix: after 23.0.0.162
Fix from $1,950 2016-10-13
Sapcryptolib MEDIUM 6.5
CVE-2016-4407

The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures, which allows remote authenticated users to imperson…

Mitigation only
Fix from $1,600 2016-10-13
Netweaver HIGH 7.5
CVE-2016-3635

SAP Netweaver 7.4 allows remote authenticated users to bypass an intended Unified Connectivity (UCON) access control list and execute arbitrary Remot…

Mitigation only
Fix from $1,950 2016-10-13