Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Zarafa Collaboration Platform MEDIUM 5.5
CVE-2014-5450

Zarafa Collaboration Platform 4.1 uses world-readable permissions for /etc/zarafa/license, which allows local users to obtain sensitive information b…

Mitigation only
Fix from $1,600 2018-03-19
Razor MEDIUM 5.3
CVE-2018-8770EPSS 59%

Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, cont…

No fix yet
Fix from $1,600 2018-03-18
Android HIGH 7.8
CVE-2017-15833

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, untrusted pointer dereference in upda…

Patch available
Fix from $1,950 2018-03-16
Pivotal Application Service MEDIUM 6.5
CVE-2018-1200

Apps Manager for PCF (Pivotal Application Service 1.11.x before 1.11.26, 1.12.x before 1.12.14, and 2.0.x before 2.0.5) allows unprivileged remote fi…

Fix: 1.11.26 / 1.12.14+
Fix from $1,600 2018-03-16
Android HIGH 7.5
CVE-2017-14882

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific acti…

Patch available
Fix from $1,950 2018-03-15
Securmail MEDIUM 6.5
CVE-2018-7704

SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply action t…

Fix: 9.2.501+
Fix from $1,600 2018-03-15
Hana HIGH 8.4
CVE-2018-2402

In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & r…

Mitigation only
Fix from $1,950 2018-03-14
Pi Vision MEDIUM 5.3
CVE-2018-7496

An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy response he…

Fix: after 2017
Fix from $1,600 2018-03-14
Edge HIGH 7.5
CVE-2018-0879EPSS 8%

Microsoft Edge in Windows 10 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosur…

Patch available
Fix from $1,950 2018-03-14
Ajenti HIGH 7.5
CVE-2018-1000126

Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as we…

No fix yet
Fix from $1,950 2018-03-13
St14.2 MEDIUM 5.3
CVE-2017-16250

A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could…

Mitigation only
Fix from $1,600 2018-03-13
Security Guardium Database Activity Monitor MEDIUM 5.5
CVE-2016-0237

IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID:…

Mitigation only
Fix from $1,600 2018-03-12
Tomcat Jk Connector HIGH 7.5
CVE-2018-1323EPSS 46%

The IIS/ISAPI specific code in the Apache Tomcat JK ISAPI Connector 1.2.0 to 1.2.42 that normalised the requested path before matching it to the URI-…

Fix: after 1.2.42
Fix from $1,950 2018-03-12
Keycloak MEDIUM 5.9
CVE-2017-2585

Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, po…

Fix: 2.5.1+
Fix from $1,600 2018-03-12
Razor HIGH 7.5
CVE-2018-8056EPSS 13%

Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a …

No fix yet
Fix from $1,950 2018-03-11
Tivoli Business Service Manager HIGH 8.8
CVE-2016-0286

IBM Tivoli Business Service Manager 6.1.0 before 6.1.0-TIV-BSM-FP0004 and 6.1.1 before 6.1.1-TIV-BSM-FP0004 allows remote authenticated users to obta…

Patch available
Fix from $1,950 2018-03-09
Qradar Pulse MEDIUM 5.3
CVE-2017-1625

IBM Pulse for QRadar 1.0.0 - 1.0.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the…

Patch available
Fix from $1,600 2018-03-08
Application Performance Management MEDIUM 5.3
CVE-2018-1387

IBM Application Performance Management for Monitoring & Diagnostics (IBM Monitoring 8.1.3 and 8.1.4) may release sensitive personal data to the staff…

Patch available
Fix from $1,600 2018-03-08
Linux Kernel MEDIUM 5.5
CVE-2018-7755

An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a k…

Fix: after 4.15.7
Fix from $1,600 2018-03-08
Sentinel MEDIUM 5.3
CVE-2018-7675

In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does …

Fix: after 8.1
Fix from $1,600 2018-03-07
Hirschmann Rs20 0900mmm2tdau MEDIUM 6.5
CVE-2018-5467

An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS,…

Mitigation only
Fix from $1,600 2018-03-06
Z Blogphp MEDIUM 5.3
CVE-2018-7737EPSS 8%

In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintai…

No fix yet
Fix from $1,600 2018-03-06
Netscaler Application Delivery Controller Firmware HIGH 7.5
CVE-2018-6808

NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the …

Mitigation only
Fix from $1,950 2018-03-06
Android HIGH 7.5
CVE-2017-6280

NVIDIA driver contains a possible out-of-bounds read vulnerability due to a leak which may lead to information disclosure. This issue is rated as mod…

Mitigation only
Fix from $1,950 2018-03-06
Shield Tv Firmware MEDIUM 5.5
CVE-2017-6283

NVIDIA Security Engine contains a vulnerability in the RSA function where the keyslot read/write lock permissions are cleared on a chip reset which m…

Fix: after 6.2
Fix from $1,600 2018-03-06
Shield Tv Firmware MEDIUM 5.5
CVE-2017-6284

NVIDIA Security Engine contains a vulnerability in the Deterministic Random Bit Generator (DRBG) where the DRBG does not properly initialize and stor…

Fix: after 6.2
Fix from $1,600 2018-03-06
Mate 9 Firmware MEDIUM 5.5
CVE-2017-8165

Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user …

Mitigation only
Fix from $1,600 2018-03-05
Mate 9 Pro Firmware MEDIUM 5.5
CVE-2017-17139

Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) ha…

Mitigation only
Fix from $1,600 2018-03-05
Enjoy 5s Firmware MEDIUM 5.5
CVE-2017-17140

Huawei Enjoy 5s and Y6 Pro smartphones with software the versions before TAG-AL00C92B170; the versions before TIT-L01C576B121 have an information lea…

Mitigation only
Fix from $1,600 2018-03-05
Qfinder Pro HIGH 7.5
CVE-2017-7633

QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further …

Fix: after 6.1.0.0317
Fix from $1,950 2018-03-05