Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Modem Firmware HIGH 7.5
CVE-2017-17463

Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and p…

Mitigation only
Fix from $1,950 2017-12-08
Linux Kernel HIGH 7.5
CVE-2017-1000410

The Linux kernel version 3.3-rc1 and later is affected by a vulnerability lies in the processing of incoming L2CAP commands - ConfigRequest, and Conf…

Fix: 4.15+
Fix from $1,950 2017-12-07
Sterling File Gateway MEDIUM 6.5
CVE-2017-1487

IBM Sterling File Gateway 2.2 could allow an authenticated attacker to obtain sensitive information such as login ids on the system. IBM X-Force ID: …

Mitigation only
Fix from $1,600 2017-12-07
Auth0.js HIGH 7.5
CVE-2017-17068

A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to ac…

Fix: 8.12+
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13157

An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13158

An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13159

An information disclosure vulnerability in the Android system (activitymanagerservice). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Mitigation only
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13164

An information disclosure vulnerability in the kernel binder driver. Product: Android. Versions: Android kernel. Android ID A-36007193.

Patch available
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13169

An information disclosure vulnerability in the kernel camera server. Product: Android. Versions: Android kernel. Android ID A-37512375.

No fix yet
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-13175

An information disclosure vulnerability in the NVIDIA libwilhelm. Product: Android. Versions: Android kernel. Android ID A-64339309. References: N-CV…

No fix yet
Fix from $1,950 2017-12-06
Android CRITICAL 9.1
CVE-2017-0879

An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-650250…

Patch available
Fix from $2,300 2017-12-06
Android CRITICAL 9.1
CVE-2017-13149

An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-657198…

No fix yet
Fix from $2,300 2017-12-06
Android CRITICAL 9.1
CVE-2017-13150

An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID A-383281…

No fix yet
Fix from $2,300 2017-12-06
Android HIGH 7.5
CVE-2017-13152

An information disclosure vulnerability in the Android media framework (libmedia drm). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1…

Patch available
Fix from $1,950 2017-12-06
Android HIGH 7.5
CVE-2017-11031

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the VIDIOC_G_SDE_ROTATOR_FENCE ioctl …

Mitigation only
Fix from $1,950 2017-12-05
Photo Station HIGH 7.5
CVE-2017-12079

Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allow…

Fix: 6.3-2970 / 6.8.1-3458+
Fix from $1,950 2017-12-04
Photo Station MEDIUM 5.3
CVE-2017-12080

An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remot…

Fix: 6.3-2970 / 6.8.1-3458+
Fix from $1,600 2017-12-04
Fiyo Cms HIGH 7.5
CVE-2017-17104

Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].

Patch available
Fix from $1,950 2017-12-04
Cubeone Firmware CRITICAL 9.8
CVE-2017-13664

Password file exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to execute arbitrary commands with administrat…

Fix: after 2.2.4.8
Fix from $2,300 2017-12-01
Xclarity Administrator MEDIUM 5.3
CVE-2017-3764

A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated u…

Fix: 1.4.0+
Fix from $1,600 2017-11-30
Secure Access Control System MEDIUM 5.3
CVE-2017-12354

A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensit…

Mitigation only
Fix from $1,600 2017-11-30
Xen MEDIUM 6.5
CVE-2017-17046

An issue was discovered in Xen through 4.9.x on the ARM platform allowing guest OS users to obtain sensitive information from DRAM after a reboot, be…

Fix: after 4.9.1
Fix from $1,600 2017-11-28
Pebble Firmware MEDIUM 6.1
CVE-2016-10702

Pebble Smartwatch devices through 4.3 mishandle UUID storage, which allows attackers to read an arbitrary application's flash storage, and access an …

Fix: after 4.3
Fix from $1,600 2017-11-28
Linux Kernel MEDIUM 5.5
CVE-2017-16994

The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to ob…

Fix: 4.14.2+
Fix from $1,600 2017-11-27
Eds G512e Firmware CRITICAL 9.8
CVE-2017-13701

An issue was discovered on MOXA EDS-G512E 5.1 build 16072215 devices. The backup file contains sensitive information in a insecure way. There is no s…

Mitigation only
Fix from $2,300 2017-11-23
Mtk Platform Smart Phone Firmware MEDIUM 5.5
CVE-2017-8183

MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a any memory …

Mitigation only
Fix from $1,600 2017-11-22
Uma MEDIUM 5.3
CVE-2017-8121

The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive in…

Mitigation only
Fix from $1,600 2017-11-22
Uma MEDIUM 6.5
CVE-2017-8130

The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive in…

No fix yet
Fix from $1,600 2017-11-22
Hedex Lite MEDIUM 5.5
CVE-2017-8136

HedEx Earlier than V200R006C00 versions has an arbitrary file download vulnerability. An attacker could exploit it to download arbitrary files on a t…

Mitigation only
Fix from $1,600 2017-11-22
Files HIGH 7.8
CVE-2017-2715

The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper desig…

Fix: after 7.1.1.309
Fix from $1,950 2017-11-22