Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Websphere Portal MEDIUM 6.5
CVE-2016-5954

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF30, 8.0.0 through 8.0.0.1 CF21, and 8.5.0 before…

Patch available
Fix from $1,600 2016-09-12
Android MEDIUM 5.5
CVE-2016-3899

OMXCodec.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 bef…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3898

Telephony in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 allows attackers to cause a denial of s…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3884

server/notification/NotificationManagerService.java in the Notification Manager Service in Android 6.x before 2016-09-01 and 7.0 before 2016-09-01 la…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3883

internal/telephony/SMSDispatcher.java in Telephony in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3880

Multiple buffer overflows in rtsp/ASessionDescription.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x bef…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3879

arm-wt-22k/lib_src/eas_mdls.c in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-09-01 allows re…

Patch available
Fix from $1,600 2016-09-11
Android MEDIUM 5.5
CVE-2016-3878

decoder/ih264d_api.c in mediaserver in Android 6.x before 2016-09-01 mishandles the case of decoding zero MBs, which allows remote attackers to cause…

Patch available
Fix from $1,600 2016-09-11
Android HIGH 7.8
CVE-2016-3863

Multiple stack-based buffer overflows in the AVCC reassembly implementation in Utils.cpp in libstagefright in MediaMuxer in Android 4.x before 4.4.4,…

Patch available
Fix from $1,950 2016-09-11
Honor 6 Firmware HIGH 7.0
CVE-2016-6179

The WiFi driver in Huawei Honor 6 smartphones with software H60-L01 before H60-L01C00B850, H60-L11 before H60-L11C00B850, H60-L21 before H60-L21C00B8…

Mitigation only
Fix from $1,950 2016-09-07
Linux MEDIUM 6.5
CVE-2016-5404

The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrar…

Patch available
Fix from $1,600 2016-09-07
Uma HIGH 7.5
CVE-2016-7107

Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 SPH206 allows remote attackers to reset arbitrary user passwords and consequently aff…

Mitigation only
Fix from $1,950 2016-09-07
E9000 Chassis MEDIUM 6.6
CVE-2016-6898

XML external entity (XXE) vulnerability in the Hyper Management Module (HMM) in Huawei E9000 rack servers with software before V100R001C00SPC296 allo…

Mitigation only
Fix from $1,600 2016-09-07
Rails HIGH 7.5
CVE-2016-6317

Action Record in Ruby on Rails 4.2.x before 4.2.7.1 does not properly consider differences in parameter handling between the Active Record component …

Mitigation only
Fix from $1,950 2016-09-07
Honor 4c Firmware HIGH 7.0
CVE-2016-6184

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C0…

Mitigation only
Fix from $1,950 2016-09-07
Honor 4c Firmware HIGH 7.0
CVE-2016-6183

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C0…

Mitigation only
Fix from $1,950 2016-09-07
Honor 4c Firmware HIGH 7.0
CVE-2016-6182

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C0…

Mitigation only
Fix from $1,950 2016-09-07
Honor 4c Firmware HIGH 7.0
CVE-2016-6181

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C0…

Mitigation only
Fix from $1,950 2016-09-07
Honor 4c Firmware HIGH 7.0
CVE-2016-6180

The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C0…

Mitigation only
Fix from $1,950 2016-09-07
Big Ip Link Controller CRITICAL 9.8
CVE-2016-5022

F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1…

Mitigation only
Fix from $2,300 2016-09-07
Cloudforms HIGH 8.8
CVE-2016-5383

The web UI in Red Hat CloudForms 4.1 allows remote authenticated users to execute arbitrary code via vectors involving "Lack of field filters."

Mitigation only
Fix from $1,950 2016-08-26
Big Ip Edge Gateway HIGH 7.5
CVE-2016-5023

Virtual servers in F5 BIG-IP systems 11.2.1 HF11 through HF15, 11.4.1 HF4 through HF10, 11.5.3 through 11.5.4, 11.6.0 HF5 through HF7, and 12.0.0, wh…

Mitigation only
Fix from $1,950 2016-08-26
Repeater HIGH 7.5
CVE-2016-5673

UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionali…

Fix: after 1201
Fix from $1,950 2016-08-25
Zp Ibh 13w HIGH 7.5
CVE-2016-5650

ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to trigger association with an arbi…

Mitigation only
Fix from $1,950 2016-08-24
1766 L32awa HIGH 7.3
CVE-2016-5645EPSS 30%

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded …

Mitigation only
Fix from $1,950 2016-08-24
Big Ip Application Acceleration Manager HIGH 7.5
CVE-2016-5736

The default configuration of the IPsec IKE peer listener in F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.1 before HF16, 11.4.x, 11.5.…

Mitigation only
Fix from $1,950 2016-08-19
Sentry HIGH 8.8
CVE-2016-0760

Multiple incomplete blacklist vulnerabilities in Apache Sentry before 1.7.0 allow remote authenticated users to execute arbitrary code via the (1) re…

Mitigation only
Fix from $1,950 2016-08-19
Edge HIGH 7.0
CVE-2016-3319EPSS 19%

The PDF library in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows 10 Gold and 1511, and Microsoft Edge allows remote attackers to ex…

Mitigation only
Fix from $1,950 2016-08-09
Windows 10 MEDIUM 5.3
CVE-2016-3299EPSS 14%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Win…

Mitigation only
Fix from $1,600 2016-08-09
Connections Portlets MEDIUM 6.5
CVE-2016-2989

Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users…

Patch available
Fix from $1,600 2016-08-08