Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Android HIGH 7.5
CVE-2015-3854

packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission r…

Patch available
Fix from $1,950 2016-08-07
Chrome CRITICAL 9.8
CVE-2016-5144

The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase…

Fix: after 52.0.2743.82
Fix from $2,300 2016-08-07
Linux Kernel MEDIUM 5.5
CVE-2016-6198

The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, whi…

Fix: after 4.5.4
Fix from $1,600 2016-08-06
Android HIGH 7.8
CVE-2014-9865

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space …

Fix: after 6.0.1
Fix from $1,950 2016-08-06
Android MEDIUM 5.5
CVE-2016-3839

Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of servic…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3838

Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that …

Patch available
Fix from $1,600 2016-08-05
Android HIGH 7.5
CVE-2014-9901

The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cau…

Fix: after 6.0.1
Fix from $1,950 2016-08-05
Hana CRITICAL 9.8
CVE-2016-6150

The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac…

No fix yet
Fix from $2,300 2016-08-05
Hana HIGH 8.1
CVE-2016-6144

The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_u…

Fix: after 1.00.73.00.389160
Fix from $1,950 2016-08-05
Trex CRITICAL 9.8
CVE-2016-6140EPSS 6%

SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591.

No fix yet
Fix from $2,300 2016-08-05
Xenserver HIGH 8.8
CVE-2016-6258

The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveragi…

Patch available
Fix from $1,950 2016-08-02
Bamboo CRITICAL 9.8
CVE-2016-5229EPSS 7%

Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers …

Fix: after 5.11.3
Fix from $2,300 2016-08-02
Operations Manager CRITICAL 9.8
CVE-2016-4373

The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a cr…

Fix: after 9.21.120
Fix from $2,300 2016-08-01
Filr HIGH 8.8
CVE-2016-1608EPSS 11%

vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary com…

Fix: after 2.0
Fix from $1,950 2016-08-01
Debian Linux MEDIUM 6.2
CVE-2016-3992

cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$…

Mitigation only
Fix from $1,600 2016-07-26
Chrome MEDIUM 6.5
CVE-2016-5130

content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, …

Fix: after 51.0.2704.106
Fix from $1,600 2016-07-23
Webkit HIGH 7.5
CVE-2016-4591

WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to acces…

No fix yet
Fix from $1,950 2016-07-22
Enterprise Linux Desktop HIGH 8.1
CVE-2016-5388EPSS 51%

Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote…

Patch available
Fix from $1,950 2016-07-19
Fedora HIGH 8.1
CVE-2016-5386EPSS 5%

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI app…

Fix: 1.6.3+
Fix from $1,950 2016-07-19
Civic Platform Citizen Access Portal HIGH 8.8
CVE-2016-5661

Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execu…

Mitigation only
Fix from $1,950 2016-07-15
Security Identity Manager Adapter HIGH 7.4
CVE-2016-0340

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow…

Mitigation only
Fix from $1,950 2016-07-15
Security Identity Manager Adapter MEDIUM 5.6
CVE-2016-0339

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou…

Mitigation only
Fix from $1,600 2016-07-15
Lighthouse Sms HIGH 8.1
CVE-2016-5807

Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and re…

Fix: after 5.1
Fix from $1,950 2016-07-15
Libvirt CRITICAL 9.8
CVE-2016-5008

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers…

Fix: after 1.3.5
Fix from $2,300 2016-07-13
Acrobat CRITICAL 9.8
CVE-2016-4215EPSS 6%

Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.016.20045
Fix from $2,300 2016-07-13
Android MEDIUM 5.5
CVE-2016-3818

libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28…

Mitigation only
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2014-9798

platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tag…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Jazz Reporting Service HIGH 8.8
CVE-2016-0315

The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 main…

Mitigation only
Fix from $1,950 2016-07-08
HTTP Server HIGH 7.5
CVE-2016-4979EPSS 19%

The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc…

Patch available
Fix from $1,950 2016-07-06
Avamar HIGH 8.8
CVE-2016-0906

The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remo…

Fix: after 7.2.1
Fix from $1,950 2016-07-06