search menu icon-carat-right cmu-wordmark

CERT Coordination Center

CERT/CC Vulnerability Notes Database


Published Public Updated ID CVSS Title
2017-05-02 2017-05-01 2017-12-21 VU#491375 5.5 Intel Active Management Technology (AMT) does not properly enforce access control
2017-11-29 2017-11-13 2017-11-30 VU#113765 4.6 Apple MacOS High Sierra disabled account authentication bypass
2017-11-21 2017-11-21 2017-11-21 VU#681983 1.3 Install Norton Security for Mac does not verify SSL certificates
2017-11-15 2017-11-14 2017-11-20 VU#421280 5.5 Microsoft Office Equation Editor stack buffer overflow
2016-11-21 2016-11-21 2017-11-20 VU#633847 6.1 NTP.org ntpd contains multiple denial of service vulnerabilities
2017-11-17 2017-11-16 2017-11-20 VU#817544 0 Windows 8 and later fail to properly randomize every application if system-wide mandatory ASLR is enabled via EMET or Windows Defender Exploit Guard
2017-10-16 2017-10-16 2017-11-16 VU#228519 5.7 Wi-Fi Protected Access (WPA) handshake traffic can be manipulated to induce nonce and session key reuse
2017-11-03 2017-11-01 2017-11-09 VU#739007 6.2 IEEE P1735 implementations may have weak cryptographic protections
2017-09-12 2017-09-12 2017-11-08 VU#240311 6.2 Multiple Bluetooth implementation vulnerabilities affect many devices
2017-10-16 2017-10-16 2017-11-08 VU#307015 6.9 Infineon RSA library does not properly generate RSA key pairs
2017-11-02 2017-10-03 2017-11-06 VU#446847 5.2 Savitech USB audio drivers install a new root CA certificate
2017-07-20 2017-07-20 2017-10-30 VU#586501 0 Inmarsat AmosConnect8 Mail Client Vulnerable to SQL Injection and Backdoor Account
2013-11-22 2013-11-21 2017-10-18 VU#893462 1.8 Thomson Reuters Velocity Analytics Vhayu Analytic Server version 6.9.4 build 2995 contains a code injection vulnerability
2017-07-27 2017-07-27 2017-10-18 VU#793496 3.6 Open Shortest Path First (OSPF) protocol implementations may improperly determine LSA recency
2017-09-08 2017-09-08 2017-10-12 VU#166743 3.8 Das U-Boot AES-CBC encryption implementation contains multiple vulnerabilities

Sponsored by CISA.