Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ubuntu Linux HIGH 8.4
CVE-2016-3714 KEVEPSS 97%

The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1…

Fix: after 6.9.3-9
Fix from $1,950 2016-05-05
Linux CRITICAL 9.8
CVE-2016-3427 KEVEPSS 92%

Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confi…

Fix: 2.1.22 / 2.2.18+
Fix from $2,300 2016-04-21
Windows 10 1507 HIGH 7.8
CVE-2016-0167 KEVEPSS 6%

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

Patch available
Fix from $1,950 2016-04-12
Windows 10 1507 HIGH 7.8
CVE-2016-0165 KEVEPSS 14%

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

Patch available
Fix from $1,950 2016-04-12
Windows 10 1507 HIGH 7.8
CVE-2016-0151 KEVEPSS 63%

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 …

Patch available
Fix from $1,950 2016-04-12
Netweaver Application Server Java HIGH 7.5
CVE-2016-3976 KEVEPSS 47%

Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary files via a ..\ (dot dot backsla…

Fix: after 7.50
Fix from $1,950 2016-04-07
Flash Player Desktop Runtime CRITICAL 9.8
CVE-2016-1019 KEVEPSS 22%

Adobe Flash Player 21.0.0.197 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code…

Fix: after 21.0.0.197
Fix from $2,300 2016-04-07
Debian Linux HIGH 8.8
CVE-2016-1646 KEVEPSS 48%

The Array.prototype.concat implementation in builtins.cc in Google V8, as used in Google Chrome before 49.0.2623.108, does not properly consider elem…

Fix: 49.0.2623.108+
Fix from $1,950 2016-03-29
Flash Player HIGH 8.8
CVE-2016-1010 KEVEPSS 20%

Integer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577 on Linux…

Fix: after 20.2.2.306
Fix from $1,950 2016-03-12
Windows 10 1507 HIGH 7.8
CVE-2016-0099 KEVEPSS 37%

The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold …

Patch available
Fix from $1,950 2016-03-09
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-2388 KEVEPSS 52%

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req…

Fix: after 7.50
Fix from $1,600 2016-02-16
Netweaver Application Server Java CRITICAL 9.8
CVE-2016-2386 KEVEPSS 71%

SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands via unspec…

Mitigation only
Fix from $2,300 2016-02-16
Rails HIGH 7.5
CVE-2016-0752 KEVEPSS 96%

Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x bef…

Fix: 3.2.22.1 / 4.1.14.1+
Fix from $1,950 2016-02-16
Flash Player HIGH 8.8
CVE-2016-0984 KEVEPSS 55%

Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 …

Fix: after 20.0.0.286
Fix from $1,950 2016-02-10
Windows 7 HIGH 7.8
CVE-2016-0040 KEVEPSS 25%

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted …

Patch available
Fix from $1,950 2016-02-10
Silverlight HIGH 8.8
CVE-2016-0034 KEVEPSS 59%

Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or ca…

Fix: 5.1.41212.0+
Fix from $1,950 2016-01-13
Sterling B2b Integrator CRITICAL 9.8
CVE-2015-7450 KEVEPSS 98%

Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote …

Fix: after 10.0.0.2
Fix from $2,300 2016-01-02
Enterprise Linux Desktop HIGH 8.8
CVE-2015-8651 KEVEPSS 68%

Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Ad…

Fix: 11.2.202.559 / 18.0.0.324+
Fix from $1,950 2015-12-28
Screenos CRITICAL 9.8
CVE-2015-7755 KEVEPSS 61%

Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r14b, 6.3.0r15 before 6.3.0r15…

Mitigation only
Fix from $2,300 2015-12-19
Windows 10 1507 HIGH 7.8
CVE-2015-6175 KEVEPSS 5%

The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Priv…

Patch available
Fix from $1,950 2015-12-09
Jenkins HIGH 7.5
CVE-2015-5317 KEVEPSS 22%

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information…

Fix: after 3.1
Fix from $1,950 2015-11-25
Virtual Desktop Infrastructure CRITICAL 9.8
CVE-2015-4852 KEVEPSS 96%

The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers to execute arbitrary commands…

Fix: after 3.5.2
Fix from $2,300 2015-11-18
Satellite MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…

Patch available
Fix from $1,600 2015-10-22
Enterprise Linux Desktop HIGH 7.8
CVE-2015-7645 KEVEPSS 68%

Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attac…

Fix: after 18.0.0.252
Fix from $1,950 2015-10-15
Windows 10 1507 HIGH 8.2
CVE-2015-2546 KEVEPSS 11%

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012…

Patch available
Fix from $1,950 2015-09-09
Office HIGH 7.8
CVE-2015-2545 KEVEPSS 80%

Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted EPS image, aka "Micros…

Patch available
Fix from $1,950 2015-09-09
Internet Explorer HIGH 8.8
CVE-2015-2502 KEVEPSS 39%

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a cra…

Patch available
Fix from $1,950 2015-08-19
Windows 10 MEDIUM 6.6
CVE-2015-1769 KEV

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and…

Patch available
Fix from $1,600 2015-08-15
Office HIGH 7.8
CVE-2015-1642 KEVEPSS 53%

Microsoft Office 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office Mem…

Patch available
Fix from $1,950 2015-08-15
Firefox HIGH 8.8
CVE-2015-4495 KEVEPSS 69%

The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same…

Fix: 2.2 / 38.1.1+
Fix from $1,950 2015-08-08