Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Multiflex M10a Controller Firmware MEDIUM 6.5
CVE-2017-14009

An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Passwor…

Mitigation only
Fix from $1,600 2017-10-17
Linux Kernel MEDIUM 5.5
CVE-2017-15537

The x86/fpu (Floating Point Unit) subsystem in the Linux kernel before 4.13.5, when a processor supports the xsave feature but not the xsaves feature…

Fix: after 4.13.4
Fix from $1,600 2017-10-17
Workspaces Vapp HIGH 7.5
CVE-2017-9368

An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side…

Fix: after 1.11.2
Fix from $1,950 2017-10-16
Fiyo Cms HIGH 7.5
CVE-2014-9147EPSS 11%

Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

Fix: after 2.0.1.8
Fix from $1,950 2017-10-16
Junos Space CRITICAL 9.8
CVE-2016-1265

A remote unauthenticated network based attacker with access to Junos Space may execute arbitrary code on Junos Space or gain access to devices manage…

Fix: after 15.1r2
Fix from $2,300 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-8693

The Microsoft Graphics Component on Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an information disclosure vulnera…

Patch available
Fix from $1,600 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11797EPSS 6%

ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles object…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Chakracore HIGH 7.5
CVE-2017-11801EPSS 6%

ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles object…

Fix: after 1.7.2
Fix from $1,950 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-11814

The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2017-10-13
Windows 10 MEDIUM 5.3
CVE-2017-11815EPSS 13%

The Microsoft Server Block Message (SMB) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,600 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-11816EPSS 20%

The Microsoft Windows Graphics Device Interface (GDI) on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 201…

Patch available
Fix from $1,600 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-11765

The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2017-10-13
Windows 10 HIGH 7.5
CVE-2017-11772EPSS 8%

The Microsoft Windows Search component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,950 2017-10-13
Outlook HIGH 7.5
CVE-2017-11776EPSS 9%

Microsoft Outlook 2016 allows an attacker to obtain the email content of a user, due to how Outlook 2016 discloses user email content, aka "Microsoft…

Patch available
Fix from $1,950 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-11784

The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2017-10-13
Windows 10 MEDIUM 5.5
CVE-2017-11785

The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, …

Patch available
Fix from $1,600 2017-10-13
Silverstripe MEDIUM 5.3
CVE-2017-12849

Response discrepancy in the login and password reset forms in SilverStripe CMS before 3.5.5 and 3.6.x before 3.6.1 allows remote attackers to enumera…

Fix: after 3.5.4
Fix from $1,600 2017-10-12
Graphicsmagick MEDIUM 6.5
CVE-2017-15277EPSS 19%

ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has ne…

Patch available
Fix from $1,600 2017-10-12
Tiandy Ip Camera Firmware HIGH 7.5
CVE-2017-15236

Tiandy IP cameras 5.56.17.120 do not properly restrict a certain proprietary protocol, which allows remote attackers to read settings via a crafted r…

No fix yet
Fix from $1,950 2017-10-11
Financial Transaction Manager MEDIUM 6.5
CVE-2017-1538

IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an…

No fix yet
Fix from $1,600 2017-10-10
Android HIGH 7.5
CVE-2017-11051

In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, information disclosure is possible in…

Mitigation only
Fix from $1,950 2017-10-10
Salt 2015 MEDIUM 6.3
CVE-2015-6918

salt before 2015.5.5 leaks git usernames and passwords to the log.

Fix: after 5.4
Fix from $1,600 2017-10-10
Transitmaster HIGH 7.5
CVE-2017-14943

Trapeze TransitMaster is vulnerable to information disclosure (emails / hashed passwords) via a modified userID field in JSON data to ManageSubscribe…

Mitigation only
Fix from $1,950 2017-10-10
Asterisk HIGH 7.5
CVE-2017-14603

In Asterisk 11.x before 11.25.3, 13.x before 13.17.2, and 14.x before 14.6.2 and Certified Asterisk 11.x before 11.6-cert18 and 13.x before 13.13-cer…

Mitigation only
Fix from $1,950 2017-10-10
Infocus Mondopad MEDIUM 5.5
CVE-2017-14971

Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document cont…

No fix yet
Fix from $1,600 2017-10-09
Http.rb MEDIUM 5.9
CVE-2015-1828

The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a…

Fix: after 0.7.2
Fix from $1,600 2017-10-06
Officescan MEDIUM 5.3
CVE-2017-14085EPSS 6%

Information disclosure vulnerabilities in Trend Micro OfficeScan 11.0 and XG may allow unauthenticated users who can access the OfficeScan server to …

Patch available
Fix from $1,600 2017-10-06
Pcd Controllers Firmware MEDIUM 5.3
CVE-2017-9628

An Information Exposure issue was discovered in Saia Burgess Controls PCD Controllers with PCD firmware versions prior to 1.28.16 or 1.24.69. In cert…

Fix: after 1.28.11
Fix from $1,600 2017-10-05
Libcurl MEDIUM 6.5
CVE-2017-1000099

When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doin…

Patch available
Fix from $1,600 2017-10-05
Libcurl MEDIUM 6.5
CVE-2017-1000100

When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is trunca…

Patch available
Fix from $1,600 2017-10-05