Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Debian Linux MEDIUM 6.5
CVE-2016-2860

The newEntry function in ptserver/ptprocs.c in OpenAFS before 1.6.17 allows remote authenticated users from foreign Kerberos realms to bypass intende…

Fix: after 1.6.16
Fix from $1,600 2016-05-13
Acrobat CRITICAL 9.8
CVE-2016-1117EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 9.8
CVE-2016-1062EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 10.0
CVE-2016-1044EPSS 7%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 9.8
CVE-2016-1042EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 10.0
CVE-2016-1041EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 9.8
CVE-2016-1040EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 9.8
CVE-2016-1039EPSS 6%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Acrobat CRITICAL 10.0
CVE-2016-1038EPSS 7%

Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.010.20060
Fix from $2,300 2016-05-11
Office HIGH 8.8
CVE-2016-0183EPSS 16%

The Windows font library in Microsoft Office 2010 SP2, Word 2010 SP2, Word Automation Services on SharePoint Server 2010 SP2, and Office Web Apps 201…

Mitigation only
Fix from $1,950 2016-05-11
Windows 10 HIGH 7.8
CVE-2016-0182EPSS 20%

Windows Journal in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to e…

Mitigation only
Fix from $1,950 2016-05-11
Windows 10 HIGH 7.8
CVE-2016-0179EPSS 24%

Windows Shell in Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows remote attackers to execute arbit…

Mitigation only
Fix from $1,950 2016-05-11
Windows 10 HIGH 8.8
CVE-2016-0170EPSS 49%

GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, …

No fix yet
Fix from $1,950 2016-05-11
Debian Linux HIGH 8.8
CVE-2016-3105

The convert extension in Mercurial before 3.8 might allow context-dependent attackers to execute arbitrary code via a crafted git repository name.

Fix: after 3.7.3
Fix from $1,950 2016-05-09
Cordova MEDIUM 5.3
CVE-2015-5207

Apache Cordova iOS before 4.0.0 might allow attackers to bypass a URL whitelist protection mechanism in an app and load arbitrary resources by levera…

Fix: after 3.9.1
Fix from $1,600 2016-05-09
Netbackup Appliance CRITICAL 9.8
CVE-2015-6552

The management-services protocol implementation in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x…

Mitigation only
Fix from $2,300 2016-05-07
Netbackup Appliance CRITICAL 9.8
CVE-2015-6550

bpcd in Veritas NetBackup 7.x through 7.5.0.7, 7.6.0.x through 7.6.0.4, 7.6.1.x through 7.6.1.2, and 7.7.x before 7.7.2 and NetBackup Appliance throu…

Mitigation only
Fix from $2,300 2016-05-07
Network Node Manager I HIGH 8.1
CVE-2016-2014

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to modify data or cause a denial of serv…

Patch available
Fix from $1,950 2016-05-07
Network Node Manager I HIGH 8.8
CVE-2016-2009

HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to execute arbitrary commands via a craf…

Patch available
Fix from $1,950 2016-05-07
Subversion MEDIUM 6.8
CVE-2016-2167EPSS 7%

The canonicalize_username function in svnserve/cyrus_auth.c in Apache Subversion before 1.8.16 and 1.9.x before 1.9.4, when Cyrus SASL authentication…

Fix: after 1.8.15
Fix from $1,600 2016-05-05
Linux Kernel MEDIUM 6.1
CVE-2014-9717

fs/namespace.c in the Linux kernel before 4.0.2 processes MNT_DETACH umount2 system calls without verifying that the MNT_LOCKED flag is unset, which …

Fix: after 4.0.1
Fix from $1,600 2016-05-02
Linux Kernel HIGH 7.8
CVE-2012-6689

The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local use…

Fix: 3.0.44 / 3.2.30+
Fix from $1,950 2016-05-02
Firefox MEDIUM 6.5
CVE-2016-2816

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replac…

Fix: after 45.0.2
Fix from $1,600 2016-04-30
Ec Cube MEDIUM 6.3
CVE-2016-1200

The management screen in LOCKON EC-CUBE 3.0.7 through 3.0.9 allows remote authenticated users to bypass intended access restrictions via unspecified …

Patch available
Fix from $1,600 2016-04-30
Linux Kernel MEDIUM 5.5
CVE-2015-8845

The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend…

Fix: after 4.4
Fix from $1,600 2016-04-27
Wireshark MEDIUM 5.9
CVE-2016-4081

epan/dissectors/packet-iax2.c in the IAX2 dissector in Wireshark 1.12.x before 1.12.11 and 2.0.x before 2.0.3 uses an incorrect integer data type, wh…

Mitigation only
Fix from $1,600 2016-04-25
Wireshark MEDIUM 5.9
CVE-2016-4076

epan/dissectors/packet-ncp2222.inc in the NCP dissector in Wireshark 2.0.x before 2.0.3 does not properly initialize memory for search patterns, whic…

Mitigation only
Fix from $1,600 2016-04-25
Foxit Reader HIGH 7.8
CVE-2016-4064

Use-after-free vulnerability in the XFA forms handling functionality in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers t…

Fix: after 7.3.0.118
Fix from $1,950 2016-04-22
Bluedriver HIGH 8.8
CVE-2016-2354

The Bluetooth functionality in Lemur Vehicle Monitors BlueDriver before 2016-04-07 supports unrestricted pairing without a PIN, which allows remote a…

Fix: after 6.3.2
Fix from $1,950 2016-04-22
Linux CRITICAL 9.8
CVE-2016-3427 KEVEPSS 92%

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confi…

Fix: 2.1.22 / 2.2.18+
Fix from $2,300 2016-04-21