Vulnerability index

Browse CVEs

1,961 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Resource Management ErrorsCWE-399 × clear
HIGH 7.5 CVE-2016-5417 Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows… Glibc after 2.23 Fix from $1,9502017-02-17 HIGH 7.5 CVE-2016-9332EPSS 8% An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate input. An attacker could pro… Softcms after 1.5 Fix from $1,9502017-02-13 MEDIUM 5.5 CVE-2016-9354 An issue was discovered in Moxa DACenter Versions 1.4 and older. A specially crafted project file may cause the program to crash because of Uncontrol… Dacenter after 1.4 Fix from $1,6002017-02-13 HIGH 7.5 CVE-2016-6173 NSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer wi… Nsd after 4.1.10 Fix from $1,9502017-02-09 HIGH 7.5 CVE-2016-7448 The Utah RLE reader in GraphicsMagick before 1.3.25 allows remote attackers to cause a denial of service (CPU consumption or large memory allocations… Debian Linux after 1.3.24 Fix from $1,9502017-02-06 HIGH 7.8 CVE-2016-10153 The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users t… Linux Kernel Patch available Fix from $1,9502017-02-06 MEDIUM 6.5 CVE-2016-6188 Memory leak in SOGo 2.3.7 allows remote attackers to cause a denial of service (memory consumption) via a large number of attempts to upload a large … Sogo Patch available Fix from $1,6002017-02-03 MEDIUM 5.5 CVE-2016-6235 The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) … Lepton Patch available Fix from $1,6002017-02-02 HIGH 7.5 CVE-2016-8919 IBM WebSphere Application Server may be vulnerable to a denial of service, caused by allowing serialized objects from untrusted sources to run and ca… Websphere Application Server Patch available Fix from $1,9502017-02-01 HIGH 8.6 CVE-2016-9225 A vulnerability in the data plane IP fragment handler of the Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security module could allow an … Asa Cx Context Aware Security Software Mitigation only Fix from $1,9502017-02-01 HIGH 8.6 CVE-2017-3790 A vulnerability in the received packet parser of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) software could allow… Expressway Mitigation only Fix from $1,9502017-02-01 MEDIUM 5.5 CVE-2016-5434 libalpm, as used in pacman 5.0.1, allows remote attackers to cause a denial of service (infinite loop or out-of-bounds read) via a crafted signature … Pacman Patch available Fix from $1,6002017-01-30 HIGH 7.5 CVE-2016-7544 Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in… Crypto\+\+ Patch available Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-10186 An issue was discovered on the D-Link DWR-932B router. /var/miniupnpd.conf has no deny rules. Dwr 932b Firmware No fix yet Fix from $1,9502017-01-30 HIGH 7.5 CVE-2016-5822 Huawei Oceanstor 5800 before V300R002C10SPC100 allows remote attackers to cause a denial of service (CPU consumption) via a large number of crafted H… Oceanstor 5800 V3 Mitigation only Fix from $1,9502017-01-27 MEDIUM 5.3 CVE-2016-9216 An IKE Packet Parsing Denial of Service Vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an unauthenticated, remote attac… Asr 5000 Series Software Mitigation only Fix from $1,6002017-01-26 HIGH 7.5 CVE-2016-6160 tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to … Tcpreplay after 4.1.1 Fix from $1,9502017-01-23 HIGH 7.5 CVE-2015-8858 The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka… Uglifyjs after 2.5.0 Fix from $1,9502017-01-23 MEDIUM 5.5 CVE-2016-8883 The jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.8 allows remote attackers to cause a denial of service (assertion failure) via a … Jasper after 1.900.7 Fix from $1,6002017-01-13 HIGH 7.5 CVE-2016-9312EPSS 31% ntpd in NTP before 4.2.8p9, when running on Windows, allows remote attackers to cause a denial of service via a large UDP packet. Ntp after 4.2.8 Fix from $1,9502017-01-13 MEDIUM 5.5 CVE-2016-8463 A denial of service vulnerability in the Qualcomm FUSE file system could enable a remote attacker to use a specially crafted file to cause a device h… Linux Kernel Patch available Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2016-6764 A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu… Android Mitigation only Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2016-6767 A denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issu… Android Mitigation only Fix from $1,6002017-01-12 HIGH 7.5 CVE-2016-6580 A HTTP/2 implementation built using any version of the Python priority library prior to version 1.2.0 could be targeted by a malicious peer by having… Python Priority Library Mitigation only Fix from $1,9502017-01-10 HIGH 7.5 CVE-2016-6581 A HTTP/2 implementation built using any version of the Python HPACK library between v1.0.0 and v2.2.0 could be targeted for a denial of service attac… Hpack Mitigation only Fix from $1,9502017-01-10 HIGH 7.5 CVE-2016-6894 Arista EOS 4.15 before 4.15.8M, 4.16 before 4.16.7M, and 4.17 before 4.17.0F on DCS-7050 series devices allow remote attackers to cause a denial of s… Dcs 7050t Eos Software after 4.15 Fix from $1,9502017-01-04 MEDIUM 6.5 CVE-2016-6595 The SwarmKit toolkit 1.12.0 for Docker allows remote authenticated users to cause a denial of service (prevention of cluster joins) via a long sequen… Docker Mitigation only Fix from $1,6002017-01-04 MEDIUM 5.5 CVE-2016-6881 The zlib_refill function in libavformat/swfdec.c in FFmpeg before 3.1.3 allows remote attackers to cause an infinite loop denial of service via a cra… Ffmpeg after 3.1.2 Fix from $1,6002016-12-23 MEDIUM 5.5 CVE-2016-7122 The avi_read_nikon function in libavformat/avidec.c in FFmpeg before 3.1.4 is vulnerable to infinite loop when it decodes an AVI file that has a craf… Ffmpeg after 3.1.3 Fix from $1,6002016-12-23 MEDIUM 5.5 CVE-2016-9561 The che_configure function in libavcodec/aacdec_template.c in FFmpeg before 3.2.1 allows remote attackers to cause a denial of service (allocation of… Ffmpeg after 3.2 Fix from $1,6002016-12-23