Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Automation License Manager CRITICAL 9.1
CVE-2016-8565

Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete direct…

Fix: after 5.3
Fix from $2,300 2016-10-13
Android MEDIUM 5.5
CVE-2016-6690

The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cau…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3925

server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked W…

Patch available
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-3923

The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and conse…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 6.5
CVE-2016-3882

Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attacker…

Patch available
Fix from $1,600 2016-10-10
Cloudforms Management Engine HIGH 8.8
CVE-2016-7040

Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba…

Mitigation only
Fix from $1,950 2016-10-07
Fedora HIGH 7.5
CVE-2016-6323

The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI …

Fix: after 2.24
Fix from $1,950 2016-10-07
Simple Image Manipulator HIGH 7.5
CVE-2015-1000010EPSS 7%

Remote file download in simple-image-manipulator v1.0 wordpress plugin

No fix yet
Fix from $1,950 2016-10-06
Google Adsense And Hotel Booking CRITICAL 9.1
CVE-2015-1000009

Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05

No fix yet
Fix from $2,300 2016-10-06
Big Ip Local Traffic Manager CRITICAL 9.8
CVE-2016-5745

F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6…

Mitigation only
Fix from $2,300 2016-10-05
Netweaver HIGH 7.5
CVE-2016-4551

The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to …

Mitigation only
Fix from $1,950 2016-10-05
Websphere Application Server HIGH 7.5
CVE-2016-5983

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4…

Patch available
Fix from $1,950 2016-10-05
Ubuntu Linux MEDIUM 5.5
CVE-2016-1372

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file.

Fix: after 0.99.1
Fix from $1,600 2016-10-03
Ubuntu Linux MEDIUM 5.5
CVE-2016-1371

ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executabl…

Fix: after 0.99.1
Fix from $1,600 2016-10-03
Big Ip Policy Enforcement Manager CRITICAL 9.8
CVE-2016-5700EPSS 6%

Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 befo…

Mitigation only
Fix from $2,300 2016-10-03
Chrome MEDIUM 6.5
CVE-2016-5176

Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors.

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-29
Anyoffice Secureapp MEDIUM 6.5
CVE-2016-6826

Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachmen…

Mitigation only
Fix from $1,600 2016-09-26
P8 Firmware MEDIUM 5.5
CVE-2016-8279

The video driver in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B362, CRR-UL20 before CRR-UL20C00B362, CRR-CL00 before CRR-CL0…

Fix: after 6.9
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-5972

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 8.8
CVE-2016-5963

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authe…

Patch available
Fix from $1,950 2016-09-26
Spectrum Control MEDIUM 5.4
CVE-2016-5943

IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access re…

Patch available
Fix from $1,600 2016-09-26
Chrome HIGH 7.1
CVE-2016-5173

The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers t…

Fix: after 53.0.2785.101
Fix from $1,950 2016-09-25
Safari MEDIUM 6.5
CVE-2016-4760

WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against…

Fix: after 12.4.3
Fix from $1,600 2016-09-25
Mac Os X CRITICAL 9.1
CVE-2016-4694

The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applicati…

Fix: after 10.11.6
Fix from $2,300 2016-09-25
Firefox HIGH 8.8
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Firefox HIGH 8.8
CVE-2016-5273

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta…

Fix: after 48.0.2
Fix from $1,950 2016-09-22
Cxf Fediz CRITICAL 9.8
CVE-2016-4464

The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured…

Mitigation only
Fix from $2,300 2016-09-21
Shiro HIGH 7.5
CVE-2016-6802EPSS 10%

Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path.

No fix yet
Fix from $1,950 2016-09-20
Outlook MEDIUM 6.5
CVE-2016-3366EPSS 16%

Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement…

Mitigation only
Fix from $1,600 2016-09-14
Windows 10 HIGH 8.8
CVE-2016-3345EPSS 32%

The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Win…

Mitigation only
Fix from $1,950 2016-09-14