Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simatic Cp 1543 1 Firmware HIGH 7.5
CVE-2016-8562 KEV

A vulnerability has been identified in SIMATIC CP 1543-1 (All versions < V2.0.28), SIPLUS NET CP 1543-1 (All versions < V2.0.28). Under special condi…

Fix: 2.0.28+
Fix from $1,950 2016-11-18
Ubuntu Linux HIGH 7.0
CVE-2016-5195 KEVEPSS 84%

Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of…

Fix: 3.2.83 / 3.4.113+
Fix from $1,950 2016-11-10
Windows 10 1507 HIGH 8.8
CVE-2016-7256 KEVEPSS 65%

atmfd.dll in the Windows font library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server …

Patch available
Fix from $1,950 2016-11-10
Windows 10 1507 HIGH 7.8
CVE-2016-7255 KEVEPSS 81%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Patch available
Fix from $1,950 2016-11-10
Edge HIGH 8.8
CVE-2016-7201 KEVEPSS 80%

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corru…

Patch available
Fix from $1,950 2016-11-10
Edge HIGH 8.8
CVE-2016-7200 KEVEPSS 82%

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corru…

Patch available
Fix from $1,950 2016-11-10
Enterprise Linux Desktop HIGH 8.8
CVE-2016-7855 KEVEPSS 25%

Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to …

Fix: after 23.0.0.185
Fix from $1,950 2016-11-01
Office HIGH 7.8
CVE-2016-7193 KEVEPSS 58%

Microsoft Word 2007 SP2, Office 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack…

Patch available
Fix from $1,950 2016-10-14
Windows 10 1507 HIGH 7.8
CVE-2016-3393 KEVEPSS 69%

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…

Patch available
Fix from $1,950 2016-10-14
Internet Explorer MEDIUM 6.5
CVE-2016-3298 KEVEPSS 23%

Microsoft Internet Explorer 9 through 11 and the Internet Messaging API in Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 a…

Patch available
Fix from $1,600 2016-10-14
iOS HIGH 7.5
CVE-2016-6415 KEVEPSS 87%

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and…

Fix: 5.3.0+
Fix from $1,950 2016-09-19
Internet Explorer MEDIUM 6.5
CVE-2016-3351 KEVEPSS 26%

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Micro…

Patch available
Fix from $1,600 2016-09-14
Iphone Os HIGH 8.8
CVE-2016-4657 KEVEPSS 64%

WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web…

Fix: 9.3.5+
Fix from $1,950 2016-08-25
Iphone Os HIGH 7.8
CVE-2016-4656 KEVEPSS 21%

The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corrupti…

Fix: 9.3.5+
Fix from $1,950 2016-08-25
Iphone Os MEDIUM 5.5
CVE-2016-4655 KEVEPSS 30%

The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.

Fix: 9.3.5+
Fix from $1,600 2016-08-25
Adaptive Security Appliance Software HIGH 7.8
CVE-2016-6367 KEVEPSS 23%

Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges v…

Fix: 8.4 / 9.0+
Fix from $1,950 2016-08-18
Pix Firewall Software HIGH 8.8
CVE-2016-6366 KEVEPSS 88%

Buffer overflow in Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3 on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Fi…

Fix: 9.0.4.40 / 9.1.7+
Fix from $1,950 2016-08-18
Windows 10 1507 HIGH 7.8
CVE-2016-3309 KEVEPSS 21%

The kernel-mode drivers in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and …

Patch available
Fix from $1,950 2016-08-09
Virtualization Manager HIGH 7.8
CVE-2016-3643 KEV

SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by…

Fix: after 6.3.1
Fix from $1,950 2016-06-17
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4171 KEVEPSS 20%

Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier allows remote attackers to execute arbitrary code via unknown vectors, as expl…

Fix: after 21.0.0.242
Fix from $2,300 2016-06-16
Visio HIGH 7.8
CVE-2016-3235 KEVEPSS 43%

Microsoft Visio 2007 SP3, Visio 2010 SP2, Visio 2013 SP1, Visio 2016, Visio Viewer 2007 SP3, and Visio Viewer 2010 mishandle library loading, which a…

Patch available
Fix from $1,950 2016-06-16
Vtscada HIGH 7.5
CVE-2016-4523 KEVEPSS 31%

The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bo…

Fix: 11.2.02+
Fix from $1,950 2016-06-09
Aurora CRITICAL 9.8
CVE-2016-4437 KEVEPSS 93%

Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code…

Fix: 0.18.1 / 1.2.5+
Fix from $2,300 2016-06-07
Activemq CRITICAL 9.8
CVE-2016-3088 KEVEPSS 99%

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT fol…

Fix: 5.14.0+
Fix from $2,300 2016-06-01
Netweaver Application Server Java CRITICAL 10.0
CVE-2010-5326 KEVEPSS 17%

The Invoker Servlet on SAP NetWeaver Application Server Java platforms, possibly before 7.3, does not require authentication, which allows remote att…

Fix: after 7.30
Fix from $2,300 2016-05-13
Enterprise Linux Desktop CRITICAL 9.8
CVE-2016-4117 KEVEPSS 94%

Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May …

Fix: after 21.0.0.226
Fix from $2,300 2016-05-11
Jscript HIGH 7.5
CVE-2016-0189 KEVEPSS 94%

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attack…

Patch available
Fix from $1,950 2016-05-11
Windows 7 HIGH 7.8
CVE-2016-0185 KEVEPSS 70%

Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary code via a crafted Media Cen…

Patch available
Fix from $1,950 2016-05-11
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3718 KEVEPSS 77%

The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (…

Patch available
Fix from $1,600 2016-05-05
Enterprise Linux Desktop MEDIUM 5.5
CVE-2016-3715 KEVEPSS 75%

The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image.

Patch available
Fix from $1,600 2016-05-05