Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Tuxedo MEDIUM 5.3
CVE-2017-10266

Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.…

Patch available
Fix from $1,600 2017-11-14
Tuxedo HIGH 7.5
CVE-2017-10267

Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 11.1.1, 12.1.…

Patch available
Fix from $1,950 2017-11-14
Android HIGH 7.5
CVE-2017-6275

An information disclosure vulnerability exists in the Thermal Driver, where a missing bounds checking in the thermal driver could allow a read from a…

Mitigation only
Fix from $1,950 2017-11-14
Bigfix Platform MEDIUM 5.9
CVE-2017-1229

IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) could allow a remote attacker to obtain sensitive information, caused by the failure to properly…

Mitigation only
Fix from $1,600 2017-11-13
Mac Os X HIGH 7.1
CVE-2017-13831

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "ImageIO" component. It allows remote att…

Fix: after 10.13.0
Fix from $1,950 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13836

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13840

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13841

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13842

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Iphone Os MEDIUM 5.5
CVE-2017-7113

An issue was discovered in certain Apple products. iOS before 11.1 is affected. The issue involves the "UIKit" component. It allows attackers to bypa…

Fix: 11.1+
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13810

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows local users…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13818

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13821

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "CFString" component. It allows attackers…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13822

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Quick Look" component. It allows attacke…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13823

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "QuickTime" component. It allows attacker…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Mac Os X MEDIUM 5.5
CVE-2017-13782

An issue was discovered in certain Apple products. macOS before 10.13.1 is affected. The issue involves the "Kernel" component. It allows attackers t…

Fix: after 10.13.0
Fix from $1,600 2017-11-13
Clustered Data Ontap MEDIUM 5.7
CVE-2017-5201

NetApp Clustered Data ONTAP before 8.3.2P8 and 9.0 before P2 allow remote authenticated users to obtain sensitive cluster and tenant information via …

Fix: 8.3.2+
Fix from $1,600 2017-11-10
Backup Agent MEDIUM 5.3
CVE-2017-16673

Datto Backup Agent 1.0.6.0 and earlier does not authenticate incoming connections. This allows an attacker to impersonate a Datto Backup Appliance to…

Fix: after 1.0.6.0
Fix from $1,600 2017-11-09
Servicedesk HIGH 7.5
CVE-2017-11511

The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath par…

Mitigation only
Fix from $1,950 2017-11-08
Frrouting HIGH 7.5
CVE-2017-15865

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtai…

Fix: 2.0.2+
Fix from $1,950 2017-11-08
Gluster Storage MEDIUM 5.9
CVE-2017-15085

It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,600 2017-11-08
Gluster Storage HIGH 7.5
CVE-2017-15087

It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.

Mitigation only
Fix from $1,950 2017-11-08
Circle With Disney Firmware MEDIUM 5.3
CVE-2017-12083

An exploitable information disclosure vulnerability exists in the apid daemon of the Circle with Disney running firmware 2.0.1. A specially crafted s…

No fix yet
Fix from $1,600 2017-11-07
Openemr HIGH 7.5
CVE-2017-16540

OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR s…

Fix: 5.0.0+
Fix from $1,950 2017-11-04
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-16541

Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vec…

Fix: 7.0.9+
Fix from $1,600 2017-11-04
Moby MEDIUM 5.9
CVE-2017-16539

The DefaultLinuxSpec function in oci/defaults.go in Docker Moby through 17.03.2-ce does not block /proc/scsi pathnames, which allows attackers to tri…

Fix: after 17.03.2
Fix from $1,600 2017-11-04
Mahara HIGH 7.5
CVE-2017-1000133

Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to a user - in some circumstances causing another user's…

Patch available
Fix from $1,950 2017-11-03
Mahara HIGH 7.5
CVE-2017-1000151

Mahara 15.04 before 15.04.9 and 15.10 before 15.10.5 and 16.04 before 16.04.3 are vulnerable to passwords or other sensitive information being passed…

Patch available
Fix from $1,950 2017-11-03
Webex Meetings Server MEDIUM 5.3
CVE-2017-12295

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An att…

Mitigation only
Fix from $1,600 2017-11-02
Openpages Grc Platform MEDIUM 5.3
CVE-2017-1148

IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including…

Patch available
Fix from $1,600 2017-11-01