Vulnerability index

Browse CVEs

5,206 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness NULL Pointer DereferenceCWE-476 × clear
Linux Kernel CRITICAL 9.8
CVE-2015-0573

drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contribut…

Fix: after 3.19.8
Fix from $2,300 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-5354

The USB subsystem in Wireshark 1.12.x before 1.12.12 and 2.x before 2.0.4 mishandles class types, which allows remote attackers to cause a denial of …

Patch available
Fix from $1,600 2016-08-07
Wireshark MEDIUM 5.9
CVE-2016-6504EPSS 7%

epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a ptvc data structure, which al…

No fix yet
Fix from $1,600 2016-08-06
Debian Linux HIGH 7.8
CVE-2016-3070

The trace_writeback_dirty_page implementation in include/trace/events/writeback.h in the Linux kernel before 4.4 improperly interacts with mm/migrate…

Fix: after 4.3.6
Fix from $1,950 2016-08-06
Android CRITICAL 9.8
CVE-2016-3821

libmedia in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 has certain incorrect declarat…

Patch available
Fix from $2,300 2016-08-05
Kerberos 5 MEDIUM 6.5
CVE-2016-3120

The validate_as_request function in kdc_util.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.13.6 and 1.4.x before 1.14.…

Patch available
Fix from $1,600 2016-08-01
Mac Os X MEDIUM 5.5
CVE-2016-4649

Audio in Apple OS X before 10.11.6 allows local users to cause a denial of service (NULL pointer dereference) via unspecified vectors.

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os HIGH 7.8
CVE-2016-4627

IOAcceleratorFamily in Apple iOS before 9.3.3, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or cause a denial of…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Iphone Os HIGH 7.8
CVE-2016-4626

IOHIDFamily in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to gain privileges or caus…

Fix: 2.2.2 / 9.2.2+
Fix from $1,950 2016-07-22
Iphone Os MEDIUM 6.5
CVE-2016-4605

Calendar in Apple iOS before 9.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a crafted i…

Fix: after 9.3.2
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.5
CVE-2016-1865

The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local users to cause a denial of servic…

Fix: 2.2.2 / 9.2.2+
Fix from $1,600 2016-07-22
Ntp HIGH 7.5
CVE-2016-4957EPSS 45%

ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exi…

Patch available
Fix from $1,950 2016-07-05
Ubuntu Linux MEDIUM 5.0
CVE-2016-2391

The ohci_bus_start function in the USB OHCI emulation support (hw/usb/hcd-ohci.c) in QEMU allows local guest OS administrators to cause a denial of s…

Fix: after 2.5.1.1
Fix from $1,600 2016-06-16
Ubuntu Linux HIGH 7.5
CVE-2016-4450EPSS 16%

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference an…

Fix: 1.10.1+
Fix from $1,950 2016-06-07
Mac Os X MEDIUM 5.5
CVE-2016-1814

IOAcceleratorFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to cause a denial of service (NULL pointer…

Fix: 9.2.1 / 9.3.2+
Fix from $1,600 2016-05-20
Watchos HIGH 7.8
CVE-2016-1813

The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 al…

Fix: 2.2.1 / 9.2.1+
Fix from $1,950 2016-05-20
Watchos MEDIUM 6.5
CVE-2016-1811

ImageIO in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows remote attackers to cause a denial of serv…

Fix: 2.2.1 / 9.2.1+
Fix from $1,600 2016-05-20
Watchos HIGH 7.8
CVE-2016-1803EPSS 5%

CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers to execute arbitrary code in…

Fix: 2.2.1 / 9.2.1+
Fix from $1,950 2016-05-20
Linux Kernel MEDIUM 6.0
CVE-2015-8551

The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrat…

Fix: after 4.3.6
Fix from $1,600 2016-04-13
Nginx HIGH 7.5
CVE-2016-0742EPSS 82%

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and work…

Fix: 1.8.1 / 1.9.10+
Fix from $1,950 2016-02-15
Linux Kernel CRITICAL 9.8
CVE-2015-8787EPSS 9%

The nf_nat_redirect_ipv4 function in net/netfilter/nf_nat_redirect.c in the Linux kernel before 4.4 allows remote attackers to cause a denial of serv…

Fix: 4.1.31 / 4.4+
Fix from $2,300 2016-02-08
Iphone Os HIGH 7.8
CVE-2015-7068

IOKit SCSI in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows attackers to execute arbitrary code in a priv…

Fix: 2.1 / 9.1+
Fix from $1,950 2015-12-11
Acrobat MEDIUM 5.0
CVE-2015-4444

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Acrobat MEDIUM 5.0
CVE-2015-4443

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Windows 7 HIGH 7.2
CVE-2015-1721

The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window…

Patch available
Fix from $1,950 2015-06-10
Ubuntu Linux HIGH 7.8
CVE-2015-4047EPSS 10%

racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a serie…

Fix: after 12.1.4
Fix from $1,950 2015-05-29
Enterprise Communications Broker MEDIUM 5.0
CVE-2014-9708EPSS 56%

Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header…

Fix: 4.6.6 / 5.2.1+
Fix from $1,600 2015-03-31
Windows 7 MEDIUM 5.6
CVE-2015-0095

The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Window…

Patch available
Fix from $1,600 2015-03-11
Windows 7 MEDIUM 6.9
CVE-2015-0003

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,600 2015-02-11
Ubuntu Linux HIGH 7.5
CVE-2014-9660EPSS 5%

The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attack…

Patch available
Fix from $1,950 2015-02-08