Vulnerability index

Browse CVEs

48 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
MySQL MEDIUM 6.5
CVE-2017-3273

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.6.34 and earlier …

Fix: after 5.7.16
Fix from $1,600 2017-01-27
MySQL MEDIUM 6.5
CVE-2017-3256

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.7.16 and …

Fix: after 5.7.16
Fix from $1,600 2017-01-27
MySQL MEDIUM 6.5
CVE-2017-3258

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.53 and earlier,…

Fix: 5.5.54 / 10.0.29+
Fix from $1,600 2017-01-27
Vm Server MEDIUM 5.9
CVE-2017-3242

Vulnerability in the Oracle VM Server for Sparc component of Oracle Sun Systems Products Suite (subcomponent: LDOM Manager). Supported versions that …

Patch available
Fix from $1,600 2017-01-27
Solaris CRITICAL 9.8
CVE-2016-5691EPSS 5%

The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validati…

Fix: after 6.9.4-4
Fix from $2,300 2016-12-13
Linux HIGH 7.5
CVE-2016-2776EPSS 89%

buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which al…

Fix: after 9.9.9
Fix from $1,950 2016-09-28
Linux MEDIUM 5.5
CVE-2016-6197

fs/overlayfs/dir.c in the OverlayFS filesystem implementation in the Linux kernel before 4.6 does not properly verify the upper dentry before proceed…

Fix: after 4.5.7
Fix from $1,600 2016-08-06
Linux MEDIUM 5.0
CVE-2015-8000EPSS 55%

db.c in named in ISC BIND 9.x before 9.9.8-P2 and 9.10.x before 9.10.3-P2 allows remote attackers to cause a denial of service (REQUIRE assertion fai…

Patch available
Fix from $1,600 2015-12-16
Openjdk HIGH 10.0
CVE-2014-8873

A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, …

Mitigation only
Fix from $1,950 2015-11-09
Linux MEDIUM 6.8
CVE-2015-3330EPSS 14%

The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTT…

Patch available
Fix from $1,600 2015-06-09
Linux HIGH 7.5
CVE-2004-2771EPSS 7%

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands…

Fix: after 12.5
Fix from $1,950 2014-12-24
Identity Manager MEDIUM 5.8
CVE-2014-2880EPSS 8%

Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows re…

No fix yet
Fix from $1,600 2014-04-17
Linux MEDIUM 5.0
CVE-2013-5211EPSS 98%

The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via …

Fix: 4.2.7+
Fix from $1,600 2014-01-02
Glassfish Server MEDIUM 5.0
CVE-2011-5035EPSS 68%

Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 and 8.2, and possibly other pr…

Fix: after 3.1.1
Fix from $1,600 2011-12-30
Mysql Connector\/net MEDIUM 5.8
CVE-2009-4833

MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform…

Fix: after 6.0.3
Fix from $1,600 2010-04-29
Database Server MEDIUM 6.4
CVE-2007-5507

The GIOP service in TNS Listener in the Oracle Net Services component in Oracle Database 9.0.1.5+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows …

Mitigation only
Fix from $1,600 2007-10-17
Jinitiator HIGH 9.3
CVE-2007-4467EPSS 21%

Multiple stack-based buffer overflows in the Oracle JInitiator ActiveX control (beans.ocx) 1.1.8.16 and earlier, as used by Oracle Forms applications…

Mitigation only
Fix from $1,950 2007-08-31
Web Listener HIGH 7.5
CVE-1999-1547EPSS 10%

Oracle Web Listener 2.1 allows remote attackers to bypass access restrictions by replacing a character in the URL with its HTTP-encoded (hex) equival…

No fix yet
Fix from $1,950 1999-11-25