Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Openpages Grc Platform MEDIUM 5.3
CVE-2017-1333

IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used …

Patch available
Fix from $1,600 2017-11-01
Jazz Reporting Service MEDIUM 5.0
CVE-2017-1340

IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder inte…

Patch available
Fix from $1,600 2017-11-01
Debian Linux MEDIUM 6.5
CVE-2017-16353EPSS 14%

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil…

No fix yet
Fix from $1,600 2017-11-01
Catalyst Plugin Static Simple HIGH 7.5
CVE-2017-16248

The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in…

Fix: 0.34+
Fix from $1,950 2017-11-01
Vim MEDIUM 5.5
CVE-2017-1000382

VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may…

Fix: after 8.0.1187
Fix from $1,600 2017-10-31
Emacs MEDIUM 5.5
CVE-2017-1000383

GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files …

Fix: after 25.3.0
Fix from $1,600 2017-10-31
Foxit Reader MEDIUM 6.5
CVE-2017-10942

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Foxit Reader MEDIUM 6.5
CVE-2017-10943

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Foxit Reader MEDIUM 6.5
CVE-2017-10944

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio…

Patch available
Fix from $1,600 2017-10-31
Network Data Loss Prevention MEDIUM 5.9
CVE-2017-3934

Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-i…

Fix: after 9.3.0
Fix from $1,600 2017-10-31
Network Data Loss Prevention HIGH 7.5
CVE-2017-3935

Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the res…

Fix: after 9.3.0
Fix from $1,950 2017-10-31
Wicket HIGH 7.5
CVE-2014-3526

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo…

Fix: 1.5.12+
Fix from $1,950 2017-10-30
Xen CRITICAL 9.1
CVE-2017-15597

An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page refer…

Fix: after 4.9.0
Fix from $2,300 2017-10-30
Pandora Fms MEDIUM 6.5
CVE-2017-15937

Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies…

Mitigation only
Fix from $1,600 2017-10-27
Chrome MEDIUM 6.5
CVE-2017-5117

Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially se…

Fix: 61.0.3163.79+
Fix from $1,600 2017-10-27
Chrome MEDIUM 5.5
CVE-2017-5082

Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacke…

Fix: 59.0.3071.92+
Fix from $1,600 2017-10-27
Bigfix Platform MEDIUM 5.3
CVE-2017-1220

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to m…

Patch available
Fix from $1,600 2017-10-26
Bigfix Platform MEDIUM 5.3
CVE-2017-1225

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure…

Patch available
Fix from $1,600 2017-10-26
Bigfix Platform MEDIUM 5.3
CVE-2017-1230

IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpr…

Patch available
Fix from $1,600 2017-10-26
Liberty HIGH 7.5
CVE-2017-1583

IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by impro…

Mitigation only
Fix from $1,950 2017-10-24
Cf Release HIGH 8.8
CVE-2015-5173

Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have u…

Fix: 1.7.0 / 2.5.2+
Fix from $1,950 2017-10-24
Iphone Os HIGH 7.5
CVE-2017-7116

An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue inv…

Fix: after 10.3.3
Fix from $1,950 2017-10-23
Iphone Os MEDIUM 5.5
CVE-2017-7131

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Bluetooth" component. It allows attackers to ob…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Iphone Os MEDIUM 5.3
CVE-2017-7140

An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Keyboard Suggestions" component. It allows atta…

Fix: after 10.3.3
Fix from $1,600 2017-10-23
Mac Os X MEDIUM 5.3
CVE-2017-7141

An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Mail" component. It allows remote attacker…

Fix: after 10.12.6
Fix from $1,600 2017-10-23
Safari MEDIUM 5.3
CVE-2017-7142

An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the "WebKit Storage" component. It allows attacke…

Fix: after 10.1.2
Fix from $1,600 2017-10-23
Safari HIGH 7.5
CVE-2017-7090

An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.…

Fix: after 12.6.2
Fix from $1,950 2017-10-23
Vip HIGH 8.1
CVE-2017-13127

The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogu…

Mitigation only
Fix from $1,950 2017-10-20
Kx Hjb1000 Firmware MEDIUM 5.3
CVE-2017-2131

Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configu…

Mitigation only
Fix from $1,600 2017-10-20
Job Manager HIGH 7.5
CVE-2015-6668EPSS 10%

The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory st…

Fix: after 0.7.24
Fix from $1,950 2017-10-19