Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.1 CVE-2016-8565 Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete direct… Automation License Manager after 5.3 Fix from $2,3002016-10-13 MEDIUM 5.5 CVE-2016-6690 The sound driver in the kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, and Nexus Player devices allows attackers to cau… Android after 7.0 Fix from $1,6002016-10-10 MEDIUM 5.5 CVE-2016-3925 server/wifi/anqp/ANQPFactory.java in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows attackers to cause a denial of service (blocked W… Android Patch available Fix from $1,6002016-10-10 MEDIUM 5.5 CVE-2016-3923 The Accessibility services in Android 7.0 before 2016-10-01 mishandle motion events, which allows attackers to conduct touchjacking attacks and conse… Android after 7.0 Fix from $1,6002016-10-10 MEDIUM 6.5 CVE-2016-3882 Off-by-one error in server/wifi/anqp/VenueNameElement.java in Wi-Fi in Android 6.x before 2016-10-01 and 7.0 before 2016-10-01 allows remote attacker… Android Patch available Fix from $1,6002016-10-10 HIGH 8.8 CVE-2016-7040 Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-ba… Cloudforms Management Engine Mitigation only Fix from $1,9502016-10-07 HIGH 7.5 CVE-2016-6323 The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI … Fedora after 2.24 Fix from $1,9502016-10-07 HIGH 7.5 CVE-2015-1000010EPSS 7% Remote file download in simple-image-manipulator v1.0 wordpress plugin Simple Image Manipulator No fix yet Fix from $1,9502016-10-06 CRITICAL 9.1 CVE-2015-1000009 Open proxy in Wordpress plugin google-adsense-and-hotel-booking v1.05 Google Adsense And Hotel Booking No fix yet Fix from $2,3002016-10-06 CRITICAL 9.8 CVE-2016-5745 F5 BIG-IP LTM systems 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF11, 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6… Big Ip Local Traffic Manager Mitigation only Fix from $2,3002016-10-05 HIGH 7.5 CVE-2016-4551 The (1) SAP_BASIS and (2) SAP_ABA components 7.00 SP Level 0031 in SAP NetWeaver 2004s might allow remote attackers to spoof IP addresses written to … Netweaver Mitigation only Fix from $1,9502016-10-05 HIGH 7.5 CVE-2016-5983 IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.43, 8.0 before 8.0.0.13, 8.5 before 8.5.5.11, 9.0 before 9.0.0.2, and Liberty before 16.0.0.4… Websphere Application Server Patch available Fix from $1,9502016-10-05 MEDIUM 5.5 CVE-2016-1372 ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted 7z file. Ubuntu Linux after 0.99.1 Fix from $1,6002016-10-03 MEDIUM 5.5 CVE-2016-1371 ClamAV (aka Clam AntiVirus) before 0.99.2 allows remote attackers to cause a denial of service (application crash) via a crafted mew packer executabl… Ubuntu Linux after 0.99.1 Fix from $1,6002016-10-03 CRITICAL 9.8 CVE-2016-5700EPSS 6% Virtual servers in F5 BIG-IP systems 11.5.0, 11.5.1 before HF11, 11.5.2, 11.5.3, 11.5.4 before HF2, 11.6.0 before HF8, 11.6.1 before HF1, 12.0.0 befo… Big Ip Policy Enforcement Manager Mitigation only Fix from $2,3002016-10-03 MEDIUM 6.5 CVE-2016-5176 Google Chrome before 53.0.2785.113 allows remote attackers to bypass the SafeBrowsing protection mechanism via unspecified vectors. Chrome after 53.0.2785.101 Fix from $1,6002016-09-29 MEDIUM 6.5 CVE-2016-6826 Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachmen… Anyoffice Secureapp Mitigation only Fix from $1,6002016-09-26 MEDIUM 5.5 CVE-2016-8279 The video driver in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B362, CRR-UL20 before CRR-UL20C00B362, CRR-CL00 before CRR-CL0… P8 Firmware after 6.9 Fix from $1,6002016-09-26 MEDIUM 6.8 CVE-2016-5972 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows… Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,6002016-09-26 HIGH 8.8 CVE-2016-5963 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 does not properly validate updates, which allows remote authe… Security Privileged Identity Manager Virtual Appliance Patch available Fix from $1,9502016-09-26 MEDIUM 5.4 CVE-2016-5943 IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticated users to bypass intended access re… Spectrum Control Patch available Fix from $1,6002016-09-26 HIGH 7.1 CVE-2016-5173 The extensions subsystem in Google Chrome before 53.0.2785.113 does not properly restrict access to Object.prototype, which allows remote attackers t… Chrome after 53.0.2785.101 Fix from $1,9502016-09-25 MEDIUM 6.5 CVE-2016-4760 WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to conduct DNS rebinding attacks against… Safari after 12.4.3 Fix from $1,6002016-09-25 CRITICAL 9.1 CVE-2016-4694 The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applicati… Mac Os X after 10.11.6 Fix from $2,3002016-09-25 HIGH 8.8 CVE-2016-5283 Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFR… Firefox after 48.0.2 Fix from $1,9502016-09-22 HIGH 8.8 CVE-2016-5273 The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote atta… Firefox after 48.0.2 Fix from $1,9502016-09-22 CRITICAL 9.8 CVE-2016-4464 The application plugins in Apache CXF Fediz 1.2.x before 1.2.3 and 1.3.x before 1.3.1 do not match SAML AudienceRestriction values against configured… Cxf Fediz Mitigation only Fix from $2,3002016-09-21 HIGH 7.5 CVE-2016-6802EPSS 10% Apache Shiro before 1.3.2 allows attackers to bypass intended servlet filters and gain access by leveraging use of a non-root servlet context path. Shiro No fix yet Fix from $1,9502016-09-20 MEDIUM 6.5 CVE-2016-3366EPSS 16% Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016, and Outlook 2016 for Mac do not properly implement… Outlook Mitigation only Fix from $1,6002016-09-14 HIGH 8.8 CVE-2016-3345EPSS 32% The SMBv1 server in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Win… Windows 10 Mitigation only Fix from $1,9502016-09-14