The Vulnerability Notes Database provides information about software vulnerabilities. Vulnerability Notes include summaries, technical details, remediation information, and lists of affected vendors. Most Vulnerability Notes are the result of private coordination and disclosure efforts. For more comprehensive coverage of public vulnerability reports, consider the National Vulnerability Database (NVD).
You can search the Vulnerability Notes Database or browse by several views. Help is available on database fields and customizing search queries. For example, you can search for specific information, such as the ten most recently updated vulnerabilities, a list of vulnerabilities that affect control systems, or a list of vulnerabilities discovered using the Basic Fuzzing Framework (BFF).
We also provide an archive of all public vulnerability information from our database.
To communicate with us about a specific vulnerability, please send email with the appropriate VU# number(s) in the subject line. To protect sensitive, non-public vulnerability information, please encrypt mail to the CERT PGP key.
We appreciate your comments and suggestions.
Recent Vulnerability Notes
- 26 May 2016VU#482135MEDHOST Perioperative Information Management System contains hard-coded database credentialsCVE-2016-4328
- 19 May 2016VU#204232Up.time agent for Linux does not authenticate a user before allowing read access to the file systemCVE-2015-8268
- 17 May 2016VU#586503Chef Manage deserializes cookie data insecurelyCVE-2016-4326
- 13 May 2016VU#785823Lantronix xPrintServer contains multiple vulnerabilitiesMultiple CVEs
- 04 May 2016VU#250519ImageMagick does not properly validate input before processing images using a delegateCVE-2016-3714
- 04 May 2016VU#369800Little CMS 2 DefaultICCintents double-free vulnerabilityCVE-2013-7455
- 02 May 2016VU#862384libarchive contains a heap-based buffer overflow due to improper input validationCVE-2016-1541
- 29 Apr 2016VU#505560Accellion File Transfer Appliance (FTA) contains multiple vulnerabilitiesMultiple CVEs
- 27 Apr 2016VU#718152NTP.org ntpd contains multiple vulnerabilitiesMultiple CVEs
- 25 Apr 2016VU#229047Allround Automations PL/SQL Developer v11 performs updates over HTTPCVE-2016-2346