Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
Gpu Driver MEDIUM 5.5
CVE-2016-8826

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a …

Patch available
Fix from $1,600 2016-12-16
Mms Ease Firmware HIGH 7.5
CVE-2015-6574EPSS 5%

The SNAP Lite component in certain SISCO MMS-EASE and AX-S4 ICCP products allows remote attackers to cause a denial of service (CPU consumption) via …

No fix yet
Fix from $1,950 2016-12-15
Ios Xr HIGH 7.5
CVE-2016-9205

A vulnerability in the HTTP 2.0 request handling code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Man…

Mitigation only
Fix from $1,950 2016-12-14
Identity Services Engine HIGH 7.5
CVE-2016-9198

A vulnerability in the Active Directory integration component of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker…

Mitigation only
Fix from $1,950 2016-12-14
iOS MEDIUM 6.5
CVE-2016-6473

A vulnerability in Cisco IOS on Catalyst Switches and Nexus 9300 Series Switches could allow an unauthenticated, adjacent attacker to cause a Layer 2…

Mitigation only
Fix from $1,600 2016-12-14
Web Security Appliance HIGH 7.5
CVE-2016-6469

A vulnerability in HTTP URL parsing of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to cause …

Mitigation only
Fix from $1,950 2016-12-14
Asr 5000 Series Software HIGH 7.5
CVE-2016-6467

A vulnerability in IPv6 packet fragment reassembly of StarOS for Cisco Aggregation Services Router (ASR) 5000 Series Switch could allow an unauthenti…

Mitigation only
Fix from $1,950 2016-12-14
W3m MEDIUM 6.5
CVE-2016-9633

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop an…

Fix: after 0.5.3-32
Fix from $1,600 2016-12-12
phpMyAdmin MEDIUM 5.9
CVE-2016-6632

An issue was discovered in phpMyAdmin where, under certain conditions, phpMyAdmin may not delete temporary files during the import of ESRI files. All…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.9
CVE-2016-6622

An issue was discovered in phpMyAdmin. An unauthenticated user is able to execute a denial-of-service (DoS) attack by forcing persistent connections …

Patch available
Fix from $1,600 2016-12-11
Busybox HIGH 7.5
CVE-2016-6301EPSS 9%

The recv_and_process_client_pkt function in networking/ntpd.c in busybox allows remote attackers to cause a denial of service (CPU and bandwidth cons…

Fix: 1.25.1+
Fix from $1,950 2016-12-09
Solaris MEDIUM 6.5
CVE-2015-8786

The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consu…

Patch available
Fix from $1,600 2016-12-09
Openssh HIGH 7.5
CVE-2016-8858EPSS 29%

The kex_input_kexinit function in kex.c in OpenSSH 6.x and 7.x through 7.3 allows remote attackers to cause a denial of service (memory consumption) …

Patch available
Fix from $1,950 2016-12-09
HTTP Server HIGH 7.5
CVE-2016-8740EPSS 79%

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-…

Patch available
Fix from $1,950 2016-12-05
Linux Kernel MEDIUM 5.5
CVE-2016-9191

The cgroup offline implementation in the Linux kernel through 4.8.11 mishandles certain drain operations, which allows local users to cause a denial …

Fix: after 4.8.11
Fix from $1,600 2016-11-28
Linux Kernel MEDIUM 5.5
CVE-2016-8650

The mpi_powm function in lib/mpi/mpi-pow.c in the Linux kernel through 4.8.11 does not ensure that memory is allocated for limb data, which allows lo…

Fix: after 4.8.11
Fix from $1,600 2016-11-28
\ HIGH 7.5
CVE-2015-8978

In Soap Lite (aka the SOAP::Lite extension for Perl) 1.14 and earlier, an example attack consists of defining 10 or more XML entities, each defined a…

Fix: after 1.14
Fix from $1,950 2016-11-22
Asr 5000 Series Software HIGH 7.5
CVE-2016-6466

A vulnerability in the IPsec component of StarOS for Cisco ASR 5000 Series routers could allow an unauthenticated, remote attacker to terminate all a…

Mitigation only
Fix from $1,950 2016-11-19
Wireshark MEDIUM 5.9
CVE-2016-9376

In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the OpenFlow dissector could crash with memory exhaustion, triggered by network traffic or a capture …

Mitigation only
Fix from $1,600 2016-11-17
Wireshark MEDIUM 5.9
CVE-2016-9375

In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the DTN dissector could go into an infinite loop, triggered by network traffic or a capture file. Thi…

Mitigation only
Fix from $1,600 2016-11-17
Wireshark MEDIUM 5.9
CVE-2016-9374

In Wireshark 2.2.0 to 2.2.1 and 2.0.0 to 2.0.7, the AllJoyn dissector could crash with a buffer over-read, triggered by network traffic or a capture …

Mitigation only
Fix from $1,600 2016-11-17
Wireshark MEDIUM 5.9
CVE-2016-9372

In Wireshark 2.2.0 to 2.2.1, the Profinet I/O dissector could loop excessively, triggered by network traffic or a capture file. This was addressed in…

No fix yet
Fix from $1,600 2016-11-17
Asr 5000 Software HIGH 7.5
CVE-2016-6455

A vulnerability in the Slowpath of StarOS for Cisco ASR 5500 Series routers with Data Processing Card 2 (DPC2) could allow an unauthenticated, remote…

Mitigation only
Fix from $1,950 2016-11-03
Secure Firewall Management Center HIGH 7.5
CVE-2016-6439

A vulnerability in the detection engine reassembly of HTTP packets for Cisco Firepower System Software before 6.0.1 could allow an unauthenticated, r…

Mitigation only
Fix from $1,950 2016-10-27
Wide Area Application Services MEDIUM 5.9
CVE-2016-6437

A vulnerability in the SSL session cache management of Cisco Wide Area Application Services (WAAS) could allow an unauthenticated, remote attacker to…

Mitigation only
Fix from $1,600 2016-10-27
Linux HIGH 7.5
CVE-2016-7039EPSS 8%

The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have un…

Fix: 4.1.37 / 4.4.32+
Fix from $1,950 2016-10-16
Linux Kernel MEDIUM 5.5
CVE-2015-8953

fs/overlayfs/copy_up.c in the Linux kernel before 4.2.6 uses an incorrect cleanup code path, which allows local users to cause a denial of service (d…

Fix: after 4.2.5
Fix from $1,600 2016-10-16
Android MEDIUM 5.9
CVE-2016-5348

The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in…

Patch available
Fix from $1,600 2016-10-10
Cinder HIGH 7.5
CVE-2015-5162

The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not prope…

Fix: after 12.0.3
Fix from $1,950 2016-10-07
Adaptive Security Appliance Software MEDIUM 6.5
CVE-2016-6424

The DHCP Relay implementation in Cisco Adaptive Security Appliance (ASA) Software 8.4.7.29 and 9.1.7.4 allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,600 2016-10-06