Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2015-3854 packages/SystemUI/src/com/android/systemui/power/PowerNotificationWarnings.java in Android 5.x allows attackers to bypass a DEVICE_POWER permission r… Android Patch available Fix from $1,9502016-08-07 CRITICAL 9.8 CVE-2016-5144 The Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 52.0.2743.116, mishandles the script-path hostname, remoteBase… Chrome after 52.0.2743.82 Fix from $2,3002016-08-07 MEDIUM 5.5 CVE-2016-6198 The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, whi… Linux Kernel after 4.5.4 Fix from $1,6002016-08-06 HIGH 7.8 CVE-2014-9865 drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly restrict user-space … Android after 6.0.1 Fix from $1,9502016-08-06 MEDIUM 5.5 CVE-2016-3839 Bluetooth in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to cause a denial of servic… Android Patch available Fix from $1,6002016-08-05 MEDIUM 5.5 CVE-2016-3838 Android 6.x before 2016-08-01 allows attackers to cause a denial of service (loss of locked-screen 911 functionality) via a crafted application that … Android Patch available Fix from $1,6002016-08-05 HIGH 7.5 CVE-2014-9901 The Qualcomm Wi-Fi driver in Android before 2016-08-05 on Nexus 7 (2013) devices makes incorrect snprintf calls, which allows remote attackers to cau… Android after 6.0.1 Fix from $1,9502016-08-05 CRITICAL 9.8 CVE-2016-6150 The multi-tenant database container feature in SAP HANA does not properly encrypt communications, which allows remote attackers to bypass intended ac… Hana No fix yet Fix from $2,3002016-08-05 HIGH 8.1 CVE-2016-6144 The SQL interface in SAP HANA before Revision 102 does not limit the number of login attempts for the SYSTEM user when the password_lock_for_system_u… Hana after 1.00.73.00.389160 Fix from $1,9502016-08-05 CRITICAL 9.8 CVE-2016-6140EPSS 6% SAP TREX 7.10 Revision 63 allows remote attackers to write to arbitrary files via vectors related to RFC-Gateway, aka SAP Security Note 2203591. Trex No fix yet Fix from $2,3002016-08-05 HIGH 8.8 CVE-2016-6258 The PV pagetable code in arch/x86/mm.c in Xen 4.7.x and earlier allows local 32-bit PV guest OS administrators to gain host OS privileges by leveragi… Xenserver Patch available Fix from $1,9502016-08-02 CRITICAL 9.8 CVE-2016-5229EPSS 7% Atlassian Bamboo before 5.11.4.1 and 5.12.x before 5.12.3.1 does not properly restrict permitted deserialized classes, which allows remote attackers … Bamboo after 5.11.3 Fix from $2,3002016-08-02 CRITICAL 9.8 CVE-2016-4373 The AdminUI in HPE Operations Manager (OM) before 9.21.130 on Linux, Unix, and Solaris allows remote attackers to execute arbitrary commands via a cr… Operations Manager after 9.21.120 Fix from $2,3002016-08-01 HIGH 8.8 CVE-2016-1608EPSS 11% vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated users to execute arbitrary com… Filr after 2.0 Fix from $1,9502016-08-01 MEDIUM 6.2 CVE-2016-3992 cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$… Debian Linux Mitigation only Fix from $1,6002016-07-26 MEDIUM 6.5 CVE-2016-5130 content/renderer/history_controller.cc in Google Chrome before 52.0.2743.82 does not properly restrict multiple uses of a JavaScript forward method, … Chrome after 51.0.2704.106 Fix from $1,6002016-07-23 HIGH 7.5 CVE-2016-4591 WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 mishandles the location variable, which allows remote attackers to acces… Webkit No fix yet Fix from $1,9502016-07-22 HIGH 8.1 CVE-2016-5388EPSS 51% Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not prote… Enterprise Linux Desktop Patch available Fix from $1,9502016-07-19 HIGH 8.1 CVE-2016-5386EPSS 5% The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI app… Fedora 1.6.3+ Fix from $1,9502016-07-19 HIGH 8.8 CVE-2016-5661 Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execu… Civic Platform Citizen Access Portal Mitigation only Fix from $1,9502016-07-15 HIGH 7.4 CVE-2016-0340 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session expiration, which allow… Security Identity Manager Adapter Mitigation only Fix from $1,9502016-07-15 MEDIUM 5.6 CVE-2016-0339 IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 mishandles session identifiers after logou… Security Identity Manager Adapter Mitigation only Fix from $1,6002016-07-15 HIGH 8.1 CVE-2016-5807 Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and re… Lighthouse Sms after 5.1 Fix from $1,9502016-07-15 CRITICAL 9.8 CVE-2016-5008 libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers… Libvirt after 1.3.5 Fix from $2,3002016-07-13 CRITICAL 9.8 CVE-2016-4215EPSS 6% Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous befo… Acrobat after 15.016.20045 Fix from $2,3002016-07-13 MEDIUM 5.5 CVE-2016-3818 libc in Android 4.x before 4.4.4 allows remote attackers to cause a denial of service (device hang or reboot) via a crafted file, aka internal bug 28… Android Mitigation only Fix from $1,6002016-07-11 MEDIUM 5.5 CVE-2014-9798 platform/msm_shared/dev_tree.c in the Qualcomm bootloader in Android before 2016-07-05 on Nexus 5 devices does not check the relationship between tag… Android after 6.0.1 Fix from $1,6002016-07-11 HIGH 8.8 CVE-2016-0315 The Report Builder and Data Collection Component (DCC) in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2 ifix016 and 6.x before 6.0.1 ifix005 main… Jazz Reporting Service Mitigation only Fix from $1,9502016-07-08 HIGH 7.5 CVE-2016-4979EPSS 19% The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not properly recognize the "SSLVerifyClient require" direc… HTTP Server Patch available Fix from $1,9502016-07-06 HIGH 8.8 CVE-2016-0906 The web-restore interface in Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar through 7.1.2 and 7.2.x through 7.2.1 allows remo… Avamar after 7.2.1 Fix from $1,9502016-07-06