Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Windows 10 HIGH 8.8
CVE-2015-2426 KEVEPSS 87%

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7…

Patch available
Fix from $1,950 2015-07-20
Ubuntu Linux CRITICAL 9.8
CVE-2015-2590 KEVEPSS 25%

Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentialit…

Patch available
Fix from $2,300 2015-07-16
Windows 7 HIGH 7.8
CVE-2015-2387 KEVEPSS 35%

ATMFD.DLL in the Adobe Type Manager Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows …

Patch available
Fix from $1,950 2015-07-14
Internet Explorer HIGH 8.8
CVE-2015-2425 KEVEPSS 45%

Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web s…

Patch available
Fix from $1,950 2015-07-14
Excel Viewer HIGH 8.8
CVE-2015-2424 KEVEPSS 38%

Microsoft PowerPoint 2007 SP3, Word 2007 SP3, PowerPoint 2010 SP2, Word 2010 SP2, PowerPoint 2013 SP1, Word 2013 SP1, and PowerPoint 2013 RT SP1 allo…

Patch available
Fix from $1,950 2015-07-14
Internet Explorer HIGH 8.8
CVE-2015-2419 KEVEPSS 45%

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption)…

Patch available
Fix from $1,950 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5123 KEVEPSS 18%

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Wind…

Fix: after 18.0.0.203
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5122 KEVEPSS 94%

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on W…

Fix: after 18.0.0.204
Fix from $2,300 2015-07-14
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-5119 KEVEPSS 99%

Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x…

Fix: after 18.0.0.194
Fix from $2,300 2015-07-08
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3113 KEVEPSS 100%

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.46…

Fix: 11.2.202.468 / 13.0.0.296+
Fix from $2,300 2015-06-23
Windows 7 HIGH 8.8
CVE-2015-2360 KEVEPSS 15%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows…

Patch available
Fix from $1,950 2015-06-10
Office HIGH 8.8
CVE-2015-1770 KEVEPSS 35%

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Unin…

Patch available
Fix from $1,950 2015-06-10
Udp CRITICAL 9.1
CVE-2015-4068 KEVEPSS 64%

Directory traversal vulnerability in Arcserve UDP before 5.0 Update 4 allows remote attackers to obtain sensitive information or cause a denial of se…

Fix: 5.0+
Fix from $2,300 2015-05-29
.net Framework HIGH 7.8
CVE-2015-1671 KEVEPSS 55%

The Windows DirectWrite library, as used in Microsoft .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2; Office 2007 SP3 and 2010 SP2; Liv…

Patch available
Fix from $1,950 2015-05-13
Dir 905l Firmware CRITICAL 9.8
CVE-2014-8361 KEVEPSS 100%

The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in th…

Fix: 1.15b01+
Fix from $2,300 2015-05-01
Tl Wr741nd Firmware HIGH 7.5
CVE-2015-3035 KEVEPSS 84%

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with fir…

Fix: 150302 / 150304+
Fix from $1,950 2015-04-22
Windows 2003 Server HIGH 7.8
CVE-2015-1701 KEVEPSS 56%

Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local users to gain privileges via …

Patch available
Fix from $1,950 2015-04-21
Enterprise Linux Desktop CRITICAL 9.8
CVE-2015-3043 KEVEPSS 74%

Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to…

Fix: 11.2.202.457 / 13.0.0.281+
Fix from $2,300 2015-04-14
Office HIGH 7.8
CVE-2015-1641 KEVEPSS 93%

Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word for Mac 2011, Office Compatibility Pack SP3, Word Auto…

Patch available
Fix from $1,950 2015-04-14
Windows 7 CRITICAL 9.8
CVE-2015-1635 KEVEPSS 100%

HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers …

Patch available
Fix from $2,300 2015-04-14
Mac Os X HIGH 7.8
CVE-2015-1130 KEVEPSS 10%

The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and obtain admin privileges via un…

Fix: 10.10.3+
Fix from $1,950 2015-04-10
Prime Data Center Network Manager HIGH 7.5
CVE-2015-0666 KEVEPSS 40%

Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to …

Fix: after 7.0
Fix from $1,950 2015-04-03
Dir 645 Firmware HIGH 8.8
CVE-2015-2051 KEVEPSS 97%

The D-Link DIR-645 Wired/Wireless Router Rev. Ax with firmware 1.04b12 and earlier allows remote attackers to execute arbitrary commands via a GetDev…

Fix: 1.05b01+
Fix from $1,950 2015-02-23
Elasticsearch CRITICAL 9.8
CVE-2015-1427 KEVEPSS 100%

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism a…

Fix: 1.3.8 / 1.4.3+
Fix from $2,300 2015-02-17
Internet Explorer MEDIUM 6.5
CVE-2015-0071 KEVEPSS 34%

Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Internet Explor…

Patch available
Fix from $1,600 2015-02-11
Flash Player CRITICAL 9.8
CVE-2015-0313 KEVEPSS 96%

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.…

Fix: 11.2.202.442 / 13.0.0.269+
Fix from $2,300 2015-02-02
Flash Player CRITICAL 9.8
CVE-2015-0311 KEVEPSS 86%

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.2…

Fix: 16.0.0.287+
Fix from $2,300 2015-01-23
Flash Player HIGH 7.8
CVE-2015-0310 KEVEPSS 15%

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly r…

Fix: 11.2.202.438 / 13.0.0.262+
Fix from $1,950 2015-01-23
Windows 7 HIGH 7.8
CVE-2015-0016 KEVEPSS 76%

Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 S…

Patch available
Fix from $1,950 2015-01-13
Dir 600 Firmware HIGH 8.0
CVE-2014-100005 KEVEPSS 42%

Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR-600 router (rev. Bx) with firmware before 2.17b02 allow remote attackers to …

Fix: after 2.16ww
Fix from $1,950 2015-01-13