Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Connections MEDIUM 6.5
CVE-2015-7461

XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cau…

Fix: after 3.0.1.1
Fix from $1,600 2018-03-20
Cloudengine 12800 Firmware MEDIUM 5.3
CVE-2016-8782

Huawei CloudEngine 12800 V100R003C00, V100R003C10, V100R005C00, V100R005C10, V100R006C00 have a memory leak vulnerability. An unauthenticated attacke…

Mitigation only
Fix from $1,600 2018-03-09
Libid3tag HIGH 7.5
CVE-2004-2779

id3_utf16_deserialize() in utf16.c in libid3tag through 0.15.1b misparses ID3v2 tags encoded in UTF-16 with an odd number of bytes, triggering an end…

Fix: after 0.15.1b
Fix from $1,950 2018-02-20
Qpdf MEDIUM 5.5
CVE-2015-9252

An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, relat…

Fix: 7.0.0+
Fix from $1,600 2018-02-13
Linux Kernel MEDIUM 5.5
CVE-2014-8171

The memory resource controller (aka memcg) in the Linux kernel allows local users to cause a denial of service (deadlock) by spawning new processes w…

Mitigation only
Fix from $1,600 2018-02-09
Prime Network HIGH 8.6
CVE-2018-0137

A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (Do…

Mitigation only
Fix from $1,950 2018-02-08
Nx Os HIGH 7.4
CVE-2018-0102

A vulnerability in the Pong tool of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, r…

Mitigation only
Fix from $1,950 2018-01-18
Industrial Ethernet 4010 Series Firmware MEDIUM 6.7
CVE-2018-0088

A vulnerability in one of the diagnostic test CLI commands on Cisco Industrial Ethernet 4010 Series Switches running Cisco IOS Software could allow a…

Mitigation only
Fix from $1,600 2018-01-18
Ios Xr MEDIUM 5.3
CVE-2017-12355

A vulnerability in the Local Packet Transport Services (LPTS) ingress frame-processing functionality of Cisco IOS XR Software could allow an unauthen…

Mitigation only
Fix from $1,600 2017-11-30
Meeting Server MEDIUM 6.5
CVE-2017-12362

A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resultin…

Fix: 2.2.2+
Fix from $1,600 2017-11-30
Meeting Server MEDIUM 5.8
CVE-2017-12311

A vulnerability in the H.264 decoder function of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a Cisco Meeting Server…

Mitigation only
Fix from $1,600 2017-11-16
Rf Gateway 1 Firmware HIGH 7.5
CVE-2017-12318

A vulnerability in the TCP state machine of Cisco RF Gateway 1 devices could allow an unauthenticated, remote attacker to prevent an affected device …

Mitigation only
Fix from $1,950 2017-11-16
Xerces2 Java HIGH 7.5
CVE-2012-0881EPSS 17%

Apache Xerces2 Java Parser before 2.12.0 allows remote attackers to cause a denial of service (CPU consumption) via a crafted message to an XML servi…

Fix: after 2.11.0
Fix from $1,950 2017-10-30
Junos HIGH 7.5
CVE-2016-4921

By flooding a Juniper Networks router running Junos OS with specially crafted IPv6 traffic, all available resources can be consumed, leading to the i…

Mitigation only
Fix from $1,950 2017-10-13
Secure Firewall Management Center HIGH 8.6
CVE-2017-12245

A vulnerability in SSL traffic decryption for Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause …

Mitigation only
Fix from $1,950 2017-10-05
Adaptive Security Appliance Software HIGH 8.6
CVE-2017-12246EPSS 7%

A vulnerability in the implementation of the direct authentication feature in Cisco Adaptive Security Appliance (ASA) Software could allow an unauthe…

Mitigation only
Fix from $1,950 2017-10-05
Wide Area Application Services MEDIUM 6.5
CVE-2017-12256

A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,600 2017-10-05
Ios Xe MEDIUM 6.5
CVE-2017-12222

A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch…

Mitigation only
Fix from $1,600 2017-09-29
iOS HIGH 7.5
CVE-2017-12231 KEVEPSS 7%

A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS 12.4 through 15.6 could allow an unauthenticate…

Fix: after 15.6
Fix from $1,950 2017-09-29
iOS MEDIUM 6.5
CVE-2017-12232 KEV

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS 15.0 through…

Fix: after 15.6
Fix from $1,600 2017-09-29
iOS HIGH 7.5
CVE-2017-12237 KEVEPSS 7%

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS 15.0 through 15.6 and Cisco IOS XE 3.5 through 16.5 could allow an…

Fix: after 16.5
Fix from $1,950 2017-09-29
iOS MEDIUM 6.5
CVE-2017-12238 KEV

A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS 15.0 through 15.4 for Cisco Catalyst 6800 Series Switches could allow an …

Fix: after 15.4
Fix from $1,600 2017-09-29
Googlemaps MEDIUM 5.9
CVE-2014-9686

The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial…

Fix: after 3.2
Fix from $1,600 2017-09-28
Spa 301 Firmware HIGH 7.5
CVE-2017-12219

A vulnerability in the handling of IP fragments for the Cisco Small Business SPA300, SPA500, and SPA51x Series IP Phones could allow an unauthenticat…

Mitigation only
Fix from $1,950 2017-09-21
Wide Area Application Services MEDIUM 5.3
CVE-2017-12250

A vulnerability in the HTTP web interface for Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to cause an…

Mitigation only
Fix from $1,600 2017-09-21
Node.js MEDIUM 6.5
CVE-2015-2927

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

Fix: after 1.0.5
Fix from $1,600 2017-09-20
iOS MEDIUM 5.3
CVE-2017-12211

A vulnerability in the IPv6 Simple Network Management Protocol (SNMP) code of Cisco IOS and Cisco IOS XE Software could allow an authenticated, remot…

Mitigation only
Fix from $1,600 2017-09-07
iOS HIGH 7.5
CVE-2017-6627 KEVEPSS 6%

A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote atta…

Mitigation only
Fix from $1,950 2017-09-07
Yesmax Hd Firmware HIGH 7.5
CVE-2017-6631

A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthent…

Mitigation only
Fix from $1,950 2017-09-07
Connected Grid Network Management System HIGH 7.5
CVE-2017-6780

A vulnerability in the TCP throttling process for Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to cause…

Fix: after 3.2.0-182
Fix from $1,950 2017-09-07