Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Monitoring And Debugging Dashboard MEDIUM 5.3
CVE-2018-12523EPSS 7%

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.

No fix yet
Fix from $1,600 2018-06-18
Monitoring And Debugging Dashboard MEDIUM 5.3
CVE-2018-12524EPSS 7%

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.

No fix yet
Fix from $1,600 2018-06-18
Monitoring And Debugging Dashboard MEDIUM 5.3
CVE-2018-12525EPSS 7%

An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.

No fix yet
Fix from $1,600 2018-06-18
Passenger HIGH 8.8
CVE-2018-12027

An Insecure Permissions vulnerability in SpawningKit in Phusion Passenger 5.3.x before 5.3.2 causes information disclosure in the following situation…

Fix: 5.3.2+
Fix from $1,950 2018-06-17
Secure Boot Stick Firmware MEDIUM 5.9
CVE-2018-12329

Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

No fix yet
Fix from $1,600 2018-06-17
Secure Boot Stick Firmware CRITICAL 9.8
CVE-2018-12336

Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH acc…

Mitigation only
Fix from $2,300 2018-06-17
Open Xchange Appsuite MEDIUM 6.5
CVE-2018-5751EPSS 9%

The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev…

Fix: after 7.6.3
Fix from $1,600 2018-06-16
The Olive Tree Ftp Server CRITICAL 9.8
CVE-2018-12481

The Olive Tree Ftp Server application 1.32 for Android has a "Sensitive Data on the Clipboard" vulnerability, as demonstrated by reading the "User pa…

Mitigation only
Fix from $2,300 2018-06-15
Epolicy Orchestrator MEDIUM 6.5
CVE-2018-6672

Information disclosure vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.0 through 5.3.3 and 5.9.0 through 5.9.1 allows authenticated users to v…

Fix: after 5.9.1
Fix from $1,600 2018-06-15
Botan MEDIUM 5.9
CVE-2018-12435

Botan 2.5.0 through 2.6.0 before 2.7.0 allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or …

Fix: after 2.7.0
Fix from $1,600 2018-06-15
Windows 10 MEDIUM 5.5
CVE-2018-8239EPSS 58%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Infor…

Patch available
Fix from $1,600 2018-06-14
Excel MEDIUM 5.5
CVE-2018-8246EPSS 18%

An information disclosure vulnerability exists when Microsoft Excel improperly discloses the contents of its memory, aka "Microsoft Excel Information…

Patch available
Fix from $1,600 2018-06-14
Windows 10 HIGH 8.0
CVE-2018-8209

An information disclosure vulnerability exists when Windows allows a normal user to access the Wireless LAN profile of an administrative user, aka "W…

Patch available
Fix from $1,950 2018-06-14
Debian Linux MEDIUM 5.3
CVE-2018-12227

An issue was discovered in Asterisk Open Source 13.x before 13.21.1, 14.x before 14.7.7, and 15.x before 15.4.1 and Certified Asterisk 13.18-cert bef…

Fix: 13.21.1 / 14.7.7+
Fix from $1,600 2018-06-12
Ubuntu Linux HIGH 7.5
CVE-2018-5181

If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local fi…

Fix: 60.0+
Fix from $1,950 2018-06-11
Ubuntu Linux HIGH 7.5
CVE-2018-5182

If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local…

Fix: 60.0+
Fix from $1,950 2018-06-11
Enterprise Linux Desktop HIGH 7.5
CVE-2018-5157

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow th…

Mitigation only
Fix from $1,950 2018-06-11
Debian Linux MEDIUM 5.9
CVE-2018-5131

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache hea…

Fix: 52.7.0 / 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5132

The Find API for WebExtensions can search some privileged pages, such as "about:debugging", if these pages are open in a tab. This could allow a mali…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 6.5
CVE-2018-5133

If the "app.support.baseURL" preference is changed by a malicious local program to contain HTML and script content, this content is not sanitized. It…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2018-5134

WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that …

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2018-5137

A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a…

Fix: 59.0+
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5140

Image for moz-icons can be accessed through the "moz-icon:" protocol through script in web content even when otherwise prohibited. This could allow f…

Fix: 59.0+
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5106

Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5114

If an existing cookie is changed to be "HttpOnly" while a document is open, the original value remains accessible through script until that document …

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox HIGH 7.5
CVE-2018-5115

If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded for…

Fix: after 57.0.4
Fix from $1,950 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5118

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue wa…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2018-5119

The reader view will display cross-origin content when CORS headers are set to prohibit the loading of cross-origin content by a site. This could all…

Fix: after 57.0.4
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7831

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy o…

Fix: after 56.0.2
Fix from $1,600 2018-06-11
Firefox MEDIUM 5.3
CVE-2017-7842

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One o…

Fix: after 56.0.2
Fix from $1,600 2018-06-11