Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fl Switch 3005 Firmware MEDIUM 5.3
CVE-2017-16741

An Information Exposure issue was discovered in PHOENIX CONTACT FL SWITCH 3xxx, 4xxx, and 48xxx Series products running firmware Version 1.0 to 1.32.…

Fix: after 1.32
Fix from $1,600 2018-01-12
Adsl Dsl5018en \(1t1r\) Firmware CRITICAL 9.8
CVE-2014-6437EPSS 16%

Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information via vectors i…

No fix yet
Fix from $2,300 2018-01-12
Etherpad HIGH 7.5
CVE-2015-2298

node/utils/ExportEtherpad.js in Etherpad 1.5.x before 1.5.2 might allow remote attackers to obtain sensitive information by leveraging an improper su…

Patch available
Fix from $1,950 2018-01-12
Junos Space MEDIUM 6.5
CVE-2018-0013

A local file inclusion vulnerability in Juniper Networks Junos Space Network Management Platform may allow an authenticated user to retrieve files fr…

Patch available
Fix from $1,600 2018-01-10
Screenos MEDIUM 6.5
CVE-2018-0014

Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from p…

Mitigation only
Fix from $1,600 2018-01-10
Android HIGH 7.5
CVE-2017-11066

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing ubi image an uninitial…

Patch available
Fix from $1,950 2018-01-10
Android CRITICAL 9.8
CVE-2017-11079

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing sparse image, uninit…

Patch available
Fix from $2,300 2018-01-10
Android HIGH 7.5
CVE-2017-14869

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while performing update of FOTA parti…

Patch available
Fix from $1,950 2018-01-10
Android HIGH 7.5
CVE-2017-14870

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while updating the recovery message f…

Patch available
Fix from $1,950 2018-01-10
Android HIGH 7.5
CVE-2017-15850

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, userspace can read values from audio …

Patch available
Fix from $1,950 2018-01-10
Codders Dataset HIGH 7.8
CVE-2014-4991

(1) lib/dataset/database/mysql.rb and (2) lib/dataset/database/postgresql.rb in the codders-dataset gem 1.3.2.1 for Ruby place credentials on the mys…

No fix yet
Fix from $1,950 2018-01-10
Cap Strap HIGH 7.8
CVE-2014-4992

lib/cap-strap/helpers.rb in the cap-strap gem 0.1.5 for Ruby places credentials on the useradd command line, which allows local users to obtain sensi…

No fix yet
Fix from $1,950 2018-01-10
Backup Agoddard HIGH 7.8
CVE-2014-4993

(1) lib/backup/cli/utility.rb in the backup-agoddard gem 3.0.28 and (2) lib/backup/cli/utility.rb in the backup_checksum gem 3.0.23 for Ruby place cr…

No fix yet
Fix from $1,950 2018-01-10
Vladtheenterprising HIGH 7.0
CVE-2014-4995

Race condition in lib/vlad/dba/mysql.rb in the VladTheEnterprising gem 0.2 for Ruby allows local users to obtain sensitive information by reading the…

Mitigation only
Fix from $1,950 2018-01-10
Point Cli HIGH 7.8
CVE-2014-4997

lib/commands/setup.rb in the point-cli gem 0.0.1 for Ruby places credentials on the curl command line, which allows local users to obtain sensitive i…

No fix yet
Fix from $1,950 2018-01-10
Lean Ruport HIGH 7.8
CVE-2014-4998

test/tc_database.rb in the lean-ruport gem 0.3.8 for Ruby places the mysql user password on the mysqldump command line, which allows local users to o…

No fix yet
Fix from $1,950 2018-01-10
Kajam HIGH 7.8
CVE-2014-4999

vendor/plugins/dataset/lib/dataset/database/mysql.rb in the kajam gem 1.0.3.rc2 for Ruby places the mysql user password on the (1) mysqldump command …

No fix yet
Fix from $1,950 2018-01-10
Lawn Login HIGH 7.8
CVE-2014-5000

The login function in lib/lawn.rb in the lawn-login gem 0.0.7 for Ruby places credentials on the curl command line, which allows local users to obtai…

No fix yet
Fix from $1,950 2018-01-10
Kcapifony HIGH 7.8
CVE-2014-5001

lib/ksymfony1.rb in the kcapifony gem 2.1.6 for Ruby places database user passwords on the (1) mysqldump, (2) pg_dump, (3) mysql, and (4) psql comman…

No fix yet
Fix from $1,950 2018-01-10
Brbackup HIGH 7.8
CVE-2014-5004

lib/brbackup.rb in the brbackup gem 0.1.1 for Ruby places the database password on the mysql command line, which allows local users to obtain sensiti…

Mitigation only
Fix from $1,950 2018-01-10
Freeipa HIGH 7.5
CVE-2017-12169

It was found that FreeIPA 4.2.0 and later could disclose password hashes to users having the 'System: Read Stage Users' permission. A remote, authent…

Mitigation only
Fix from $1,950 2018-01-10
Geode HIGH 7.1
CVE-2017-12622

When an Apache Geode cluster before v1.3.0 is operating in secure mode and an authenticated user connects to a Geode cluster using the gfsh tool with…

Fix: 1.3.0+
Fix from $1,950 2018-01-10
Geode HIGH 7.5
CVE-2017-9795

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,950 2018-01-10
Geode MEDIUM 5.3
CVE-2017-9796

When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execut…

Fix: 1.3.0+
Fix from $1,600 2018-01-10
Shanghai Onstar MEDIUM 5.9
CVE-2017-12697

A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnera…

Mitigation only
Fix from $1,600 2018-01-09
Sling Jcr Contentloader HIGH 7.5
CVE-2012-3353

The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the con…

Mitigation only
Fix from $1,950 2018-01-09
S9300 Firmware MEDIUM 5.9
CVE-2014-5394

Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.

Mitigation only
Fix from $1,600 2018-01-08
Sea Tel 121 Firmware HIGH 7.5
CVE-2018-5266

Cobham Sea Tel 121 build 222701 devices allow remote attackers to obtain potentially sensitive information about valid usernames by reading the login…

No fix yet
Fix from $1,950 2018-01-08
Workstation HIGH 7.1
CVE-2017-4948

VMware Workstation (14.x before 14.1.0 and 12.x) and Horizon View Client (4.x before 4.7.0) contain an out-of-bounds read vulnerability in TPView.dll…

Fix: 4.7+
Fix from $1,950 2018-01-05
Chakracore MEDIUM 5.3
CVE-2018-0800EPSS 7%

Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scriptin…

Fix: after 1.7.6
Fix from $1,600 2018-01-04