Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Openshift HIGH 7.1
CVE-2016-3708

Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth…

Mitigation only
Fix from $1,950 2016-06-08
Openshift MEDIUM 5.3
CVE-2016-3703

Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/…

Mitigation only
Fix from $1,600 2016-06-08
Discovery And Dependency Mapping Inventory HIGH 8.8
CVE-2016-4369

HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated u…

Mitigation only
Fix from $1,950 2016-06-08
Gluster Storage Management Console MEDIUM 6.5
CVE-2014-8177

The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass …

Mitigation only
Fix from $1,600 2016-06-07
Ubuntu Linux MEDIUM 6.5
CVE-2016-1699

WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, …

Fix: after 51.0.2704.63
Fix from $1,600 2016-06-05
Chrome HIGH 8.8
CVE-2016-1697

The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not pre…

Fix: after 51.0.2704.63
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1696

The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the…

Fix: after 51.0.2704.63
Fix from $1,950 2016-06-05
Chrome MEDIUM 5.3
CVE-2016-1694

browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier fo…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux MEDIUM 5.3
CVE-2016-1693

browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Softw…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Ubuntu Linux MEDIUM 5.3
CVE-2016-1692

WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Chrome MEDIUM 6.1
CVE-2016-1682

The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used i…

Fix: after 50.0.2661.102
Fix from $1,600 2016-06-05
Debian Linux HIGH 8.8
CVE-2016-1676

extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allow…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Ubuntu Linux HIGH 8.8
CVE-2016-1675

Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Docume…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Chrome HIGH 8.8
CVE-2016-1672

The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 m…

Fix: after 50.0.2661.102
Fix from $1,950 2016-06-05
Xenapp HIGH 7.5
CVE-2016-4810

Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set …

Mitigation only
Fix from $1,950 2016-06-01
Esc 8832 Data Controller HIGH 7.5
CVE-2016-4502

Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier allows remote attackers to bypass intended access restrictions and exec…

Fix: after 3.02
Fix from $1,950 2016-05-31
Esc 8832 Data Controller CRITICAL 9.1
CVE-2016-4501

Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote attackers to bypass authentica…

Fix: after 3.02
Fix from $2,300 2016-05-31
Release Control CRITICAL 9.8
CVE-2016-1999EPSS 6%

The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, rel…

Patch available
Fix from $2,300 2016-05-30
Evolved Programmable Network Manager HIGH 8.8
CVE-2016-1406

The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticate…

Mitigation only
Fix from $1,950 2016-05-25
Foreman HIGH 8.8
CVE-2016-3728

Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote att…

Patch available
Fix from $1,950 2016-05-20
Foreman MEDIUM 5.4
CVE-2016-2100

Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1…

Fix: after 1.10.2
Fix from $1,600 2016-05-20
Mac Os X MEDIUM 5.3
CVE-2016-1844

The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified …

Fix: after 10.11.4
Fix from $1,600 2016-05-20
Iphone Os HIGH 7.5
CVE-2016-1842

MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1806

Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1805

CoreStorage in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app.

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Mac Os X HIGH 7.8
CVE-2016-1797

Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbi…

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Bluemix MEDIUM 6.5
CVE-2016-0323

The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate val…

Mitigation only
Fix from $1,600 2016-05-17
Chrome HIGH 8.8
CVE-2016-1668

The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.10…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Debian Linux HIGH 8.8
CVE-2016-1667

The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.…

Fix: after 50.0.2661.87
Fix from $1,950 2016-05-14
Base Vxfs 50 MEDIUM 5.5
CVE-2016-2016

Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 1…

Patch available
Fix from $1,600 2016-05-14