Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mac Os X MEDIUM 5.5
CVE-2018-4084

An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to…

Fix: 10.13.3+
Fix from $1,600 2018-04-03
Safari MEDIUM 6.5
CVE-2017-2493

An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affec…

Fix: 6.2 / 10.1+
Fix from $1,600 2018-04-03
Mac Os X MEDIUM 5.5
CVE-2017-13839

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local user…

Mitigation only
Fix from $1,600 2018-04-03
Android MEDIUM 5.5
CVE-2017-17769

Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.

No fix yet
Fix from $1,600 2018-03-30
Authentication Agent For Web MEDIUM 5.5
CVE-2018-1234

RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows …

Fix: after 8.0.1
Fix from $1,600 2018-03-30
Android HIGH 7.5
CVE-2017-11087

libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larg…

Mitigation only
Fix from $1,950 2018-03-30
Android HIGH 7.5
CVE-2017-14875

In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a hea…

Patch available
Fix from $1,950 2018-03-30
Android MEDIUM 5.3
CVE-2017-14891

In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the sta…

Patch available
Fix from $1,600 2018-03-30
Android HIGH 7.8
CVE-2017-15852

Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.

Mitigation only
Fix from $1,950 2018-03-30
Logstash MEDIUM 6.5
CVE-2018-3817

When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.

Fix: 5.6.6 / 6.1.2+
Fix from $1,600 2018-03-30
Android MEDIUM 6.5
CVE-2017-9681

In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel me…

Mitigation only
Fix from $1,600 2018-03-30
Cf Release CRITICAL 9.6
CVE-2016-6658

Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho…

Fix: 1.6.49 / 1.7.31+
Fix from $2,300 2018-03-29
Cf Deployment HIGH 8.8
CVE-2018-1191

Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to…

Fix: 1.9.0 / 1.11.0+
Fix from $1,950 2018-03-29
Review Board MEDIUM 6.5
CVE-2014-5028

The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass in…

Fix: 1.7.27 / 2.0.4+
Fix from $1,600 2018-03-29
Hw0021 Firmware CRITICAL 9.8
CVE-2017-11510

An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an…

No fix yet
Fix from $2,300 2018-03-28
Identity Manager MEDIUM 5.9
CVE-2018-7676

The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.

Fix: after 4.6
Fix from $1,600 2018-03-28
Projectdox MEDIUM 6.5
CVE-2014-5130

Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct acce…

No fix yet
Fix from $1,600 2018-03-27
Projectdox MEDIUM 6.5
CVE-2014-5131

Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.

No fix yet
Fix from $1,600 2018-03-27
Qts MEDIUM 5.3
CVE-2017-7630

QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver…

Mitigation only
Fix from $1,600 2018-03-27
Atom C MEDIUM 5.6
CVE-2018-9056

Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v…

No fix yet
Fix from $1,600 2018-03-27
Spark Hybrid Calendar Service HIGH 7.5
CVE-2017-12310

A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive …

Mitigation only
Fix from $1,950 2018-03-27
Capacity Management Analytics HIGH 7.8
CVE-2015-7432

IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. …

Patch available
Fix from $1,950 2018-03-26
Capacity Management Analytics HIGH 7.8
CVE-2015-7433

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install ma…

Patch available
Fix from $1,950 2018-03-26
Capacity Management Analytics HIGH 7.8
CVE-2015-7434

IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install ma…

Patch available
Fix from $1,950 2018-03-26
Dsmall HIGH 7.5
CVE-2018-9014

dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.

Mitigation only
Fix from $1,950 2018-03-25
Cognos Analytics MEDIUM 5.3
CVE-2016-9711

IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker i…

Mitigation only
Fix from $1,600 2018-03-22
P9 Firmware MEDIUM 5.5
CVE-2017-17319

Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not properly prote…

Mitigation only
Fix from $1,600 2018-03-20
Ubuntu Linux HIGH 7.5
CVE-2018-1000135

GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DN…

Fix: after 1.10.2
Fix from $1,950 2018-03-20
Truecrypt HIGH 7.1
CVE-2014-2885

Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLeng…

Mitigation only
Fix from $1,950 2018-03-19
Big Ip Local Traffic Manager MEDIUM 5.9
CVE-2014-4024

SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 1…

Fix: after 11.5.1
Fix from $1,600 2018-03-19