Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Glibc HIGH 7.5
CVE-2016-5417

Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows…

Fix: after 2.23
Fix from $1,950 2017-02-17
Softcms HIGH 7.5
CVE-2016-9332EPSS 8%

An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could pro…

Fix: after 1.5
Fix from $1,950 2017-02-13
Dacenter MEDIUM 5.5
CVE-2016-9354

An issue was discovered in Moxa DACenter Versions 1.4 and older. A specially crafted project file may cause the program to crash because of Uncontrol…

Fix: after 1.4
Fix from $1,600 2017-02-13
Nsd HIGH 7.5
CVE-2016-6173

NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer wi…

Fix: after 4.1.10
Fix from $1,950 2017-02-09
Debian Linux HIGH 7.5
CVE-2016-7448

The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations…

Fix: after 1.3.24
Fix from $1,950 2017-02-06
Linux Kernel HIGH 7.8
CVE-2016-10153

The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users t…

Patch available
Fix from $1,950 2017-02-06
Sogo MEDIUM 6.5
CVE-2016-6188

Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large …

Patch available
Fix from $1,600 2017-02-03
Lepton MEDIUM 5.5
CVE-2016-6235

The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) …

Patch available
Fix from $1,600 2017-02-02
Websphere Application Server HIGH 7.5
CVE-2016-8919

IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and ca…

Patch available
Fix from $1,950 2017-02-01
Asa Cx Context Aware Security Software HIGH 8.6
CVE-2016-9225

A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an …

Mitigation only
Fix from $1,950 2017-02-01
Expressway HIGH 8.6
CVE-2017-3790

A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow…

Mitigation only
Fix from $1,950 2017-02-01
Pacman MEDIUM 5.5
CVE-2016-5434

libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature …

Patch available
Fix from $1,600 2017-01-30
Crypto\+\+ HIGH 7.5
CVE-2016-7544

Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in…

Patch available
Fix from $1,950 2017-01-30
Dwr 932b Firmware HIGH 7.5
CVE-2016-10186

An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules.

No fix yet
Fix from $1,950 2017-01-30
Oceanstor 5800 V3 HIGH 7.5
CVE-2016-5822

Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted H…

Mitigation only
Fix from $1,950 2017-01-27
Asr 5000 Series Software MEDIUM 5.3
CVE-2016-9216

An IKE Packet Parsing Denial of Service Vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attac…

Mitigation only
Fix from $1,600 2017-01-26
Tcpreplay HIGH 7.5
CVE-2016-6160

tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to …

Fix: after 4.1.1
Fix from $1,950 2017-01-23
Uglifyjs HIGH 7.5
CVE-2015-8858

The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka…

Fix: after 2.5.0
Fix from $1,950 2017-01-23
Jasper MEDIUM 5.5
CVE-2016-8883

The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a …

Fix: after 1.900.7
Fix from $1,600 2017-01-13
Ntp HIGH 7.5
CVE-2016-9312EPSS 31%

ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet.

Fix: after 4.2.8
Fix from $1,950 2017-01-13
Linux Kernel MEDIUM 5.5
CVE-2016-8463

A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device h…

Patch available
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2016-6764

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu…

Mitigation only
Fix from $1,600 2017-01-12
Android MEDIUM 5.5
CVE-2016-6767

A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu…

Mitigation only
Fix from $1,600 2017-01-12
Python Priority Library HIGH 7.5
CVE-2016-6580

A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having…

Mitigation only
Fix from $1,950 2017-01-10
Hpack HIGH 7.5
CVE-2016-6581

A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attac…

Mitigation only
Fix from $1,950 2017-01-10
Dcs 7050t Eos Software HIGH 7.5
CVE-2016-6894

Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of s…

Fix: after 4.15
Fix from $1,950 2017-01-04
Docker MEDIUM 6.5
CVE-2016-6595

The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequen…

Mitigation only
Fix from $1,600 2017-01-04
Ffmpeg MEDIUM 5.5
CVE-2016-6881

The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a cra…

Fix: after 3.1.2
Fix from $1,600 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-7122

The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a craf…

Fix: after 3.1.3
Fix from $1,600 2016-12-23
Ffmpeg MEDIUM 5.5
CVE-2016-9561

The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of…

Fix: after 3.2
Fix from $1,600 2016-12-23