Vulnerability index

Browse CVEs

1,210 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper AuthorizationCWE-285 × clear
Debian Linux HIGH 8.1
CVE-2016-7143

The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently …

Fix: after 3.5.2
Fix from $1,950 2016-09-21
Vipr Srm CRITICAL 9.8
CVE-2016-0922

EMC ViPR SRM before 3.7.2 does not restrict the number of password-authentication attempts, which makes it easier for remote attackers to obtain acce…

Fix: after 3.7.1
Fix from $2,300 2016-09-18
Windows 10 HIGH 8.8
CVE-2016-3352EPSS 21%

Microsoft Windows 8.1, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 do not properly check NTLM SSO requests for MSA logins, which makes it eas…

Mitigation only
Fix from $1,950 2016-09-14
Rh1288 V3 Server Firmware CRITICAL 9.8
CVE-2016-6825

Huawei XH620 V3, XH622 V3, and XH628 V3 servers with software before V100R003C00SPC610, RH1288 V3 servers with software before V100R003C00SPC613, RH2…

Mitigation only
Fix from $2,300 2016-09-07
Readynas Surveillance HIGH 7.5
CVE-2016-5676EPSS 54%

cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows …

No fix yet
Fix from $1,950 2016-08-31
Oncell G3001 Firmware CRITICAL 9.8
CVE-2016-5799

Moxa OnCell G3100V2 devices before 2.8 and G3111, G3151, G3211, and G3251 devices before 1.7 do not properly restrict authentication attempts, which …

Fix: after 2.7
Fix from $2,300 2016-08-24
Debian Linux HIGH 7.5
CVE-2016-5420EPSS 15%

curl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection to reuse, which might allow remote attackers to h…

Fix: after 7.50.0
Fix from $1,950 2016-08-10
Factorytalk Energrymetrix HIGH 7.3
CVE-2016-4531EPSS 8%

Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote at…

Fix: after 2.10.00
Fix from $1,950 2016-07-28
Chrome HIGH 8.8
CVE-2016-1711

WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not disable frame navigation during a detach o…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Chrome HIGH 8.8
CVE-2016-1710

The ChromeClientImpl::createWindow method in WebKit/Source/web/ChromeClientImpl.cpp in Blink, as used in Google Chrome before 52.0.2743.82, does not …

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23