Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Huawei Firmware MEDIUM 5.9
CVE-2016-5435

Memory leak in Huawei IPS Module, NGFW Module, NIP6300, NIP6600, and Secospace USG6300, USG6500, USG6600, USG9500, and AntiDDoS8000 V500R001C00 befor…

Mitigation only
Fix from $1,600 2016-06-24
Ios Xe MEDIUM 6.5
CVE-2016-1428

Double free vulnerability in Cisco IOS XE 3.15S, 3.16S, and 3.17S allows remote authenticated users to cause a denial of service (device restart) via…

Mitigation only
Fix from $1,600 2016-06-23
iOS HIGH 7.5
CVE-2015-6289

Cisco IOS 15.5(3)M on Integrated Services Router (ISR) 800, 819, and 829 devices allows remote attackers to cause a denial of service (memory consump…

Mitigation only
Fix from $1,950 2016-06-23
Ios Xe MEDIUM 6.5
CVE-2016-1432

Cisco IOS XE 3.15S and 3.16S on cBR-8 Converged Broadband Router devices allows remote authenticated users to cause a denial of service (NULL pointer…

Mitigation only
Fix from $1,600 2016-06-18
Ubuntu Linux HIGH 7.5
CVE-2016-5300EPSS 7%

The XML parser in Expat does not use sufficient entropy for hash initialization, which allows context-dependent attackers to cause a denial of servic…

Fix: 2.2.0+
Fix from $1,950 2016-06-16
Debian Linux HIGH 7.5
CVE-2014-9747

The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode,…

Fix: after 2.5.3
Fix from $1,950 2016-06-07
Symfony HIGH 7.5
CVE-2016-4423

The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x…

Fix: after 2.3.40
Fix from $1,950 2016-06-01
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2016-1379

Cisco Adaptive Security Appliance (ASA) Software 9.0 through 9.5.1 mishandles IPsec error processing, which allows remote authenticated users to caus…

Mitigation only
Fix from $1,600 2016-05-28
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2016-1385

The XML parser in Cisco Adaptive Security Appliance (ASA) Software through 9.5.2 allows remote authenticated users to cause a denial of service (inst…

Mitigation only
Fix from $1,600 2016-05-26
Fedora HIGH 7.5
CVE-2016-4021

The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU co…

Fix: after 0.29
Fix from $1,950 2016-05-26
Web Security Appliance \(wsa\) HIGH 7.5
CVE-2016-1383

Memory leak in Cisco AsyncOS through 8.8 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of service (memory consump…

Mitigation only
Fix from $1,950 2016-05-25
Web Security Appliance HIGH 7.5
CVE-2016-1381

Memory leak in Cisco AsyncOS 8.5 through 9.0 before 9.0.1-162 on Web Security Appliance (WSA) devices allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2016-05-25
PHP HIGH 7.5
CVE-2015-8877

The gdImageScaleTwoPass function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.0, as used in PHP before 5.6.12, uses incons…

Fix: after 5.6.11
Fix from $1,950 2016-05-22
Anti Virus Engine CRITICAL 9.1
CVE-2016-2208EPSS 19%

The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute arbitrary code or cause a deni…

Fix: after 20151.1.0.32
Fix from $2,300 2016-05-19
iOS HIGH 7.5
CVE-2016-1399

The packet-processing microcode in Cisco IOS 15.2(2)EA, 15.2(2)EA1, 15.2(2)EA2, and 15.2(4)EA on Industrial Ethernet 4000 devices and 15.2(2)EB and 1…

Mitigation only
Fix from $1,950 2016-05-14
Debian Linux HIGH 7.5
CVE-2015-5727

The BER decoder in Botan 1.10.x before 1.10.10 and 1.11.x before 1.11.19 allows remote attackers to cause a denial of service (memory consumption) vi…

Mitigation only
Fix from $1,950 2016-05-13
Enterprise Application Platform HIGH 7.5
CVE-2016-2094

The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshak…

Mitigation only
Fix from $1,950 2016-05-06
Asa With Firepower Services HIGH 7.5
CVE-2016-1369

The Adaptive Security Appliance (ASA) 5585-X FirePOWER Security Services Processor (SSP) module for Cisco ASA with FirePOWER Services 5.3.1 through 6…

Mitigation only
Fix from $1,950 2016-05-05
Firesight System Software HIGH 7.5
CVE-2016-1368

Cisco FirePOWER System Software 5.3.x through 5.3.0.6 and 5.4.x through 5.4.0.3 on FirePOWER 7000 and 8000 appliances, and on the Advanced Malware Pr…

Mitigation only
Fix from $1,950 2016-05-05
Ubuntu Linux MEDIUM 5.9
CVE-2016-4008EPSS 26%

The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows rem…

Fix: after 4.7
Fix from $1,600 2016-05-05
OpenSSL HIGH 7.5
CVE-2016-2109EPSS 29%

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remo…

Fix: after 1.0.1s
Fix from $1,950 2016-05-05
Wireshark MEDIUM 5.9
CVE-2016-4419

epan/dissectors/packet-spice.c in the SPICE dissector in Wireshark 2.x before 2.0.2 mishandles capability data, which allows remote attackers to caus…

Mitigation only
Fix from $1,600 2016-05-01
Ubuntu Linux MEDIUM 5.5
CVE-2016-3156

The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of s…

Fix: after 4.5.1
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 6.2
CVE-2016-2847

fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (me…

Fix: after 4.4.8
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 5.5
CVE-2016-2550

The Linux kernel before 4.5 allows local users to bypass file-descriptor limits and cause a denial of service (memory consumption) by leveraging inco…

Fix: after 4.4.8
Fix from $1,600 2016-04-27
Linux Kernel MEDIUM 6.2
CVE-2015-1339

Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (me…

Fix: after 4.3.6
Fix from $1,600 2016-04-27
Adaptive Security Appliance Software HIGH 7.5
CVE-2016-1367

The DHCPv6 relay implementation in Cisco Adaptive Security Appliance (ASA) Software 9.4.1 allows remote attackers to cause a denial of service (devic…

Mitigation only
Fix from $1,950 2016-04-21
Wireless Lan Controller Software CRITICAL 9.8
CVE-2016-1363EPSS 6%

Buffer overflow in the redirection functionality in Cisco Wireless LAN Controller (WLC) Software 7.2 through 7.4 before 7.4.140.0(MD) and 7.5 through…

Fix: 7.4.140.0 / 8.0.115.0+
Fix from $2,300 2016-04-21
Aireos HIGH 7.5
CVE-2016-1362

Cisco AireOS 4.1 through 7.4.120.0, 7.5.x, and 7.6.100.0 on Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,950 2016-04-21
Enterprise Linux HIGH 7.5
CVE-2016-0741

slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of ser…

Patch available
Fix from $1,950 2016-04-19