Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Pipeline Input Step HIGH 7.5
CVE-2017-1000108

The Pipeline: Input Step Plugin by default allowed users with Item/Read access to a pipeline to interact with the step to provide input. This has bee…

Mitigation only
Fix from $1,950 2017-10-05
Deploy MEDIUM 5.5
CVE-2017-1000113

The Deploy to container Plugin stored passwords unencrypted as part of its configuration. This allowed users with Jenkins master local file system ac…

Fix: after 1.12
Fix from $1,600 2017-10-05
Docker Commons MEDIUM 6.5
CVE-2017-1000094

Docker Commons Plugin provides a list of applicable credential IDs to allow users configuring a job to select the one they'd like to use to authentic…

Fix: after 1.9
Fix from $1,600 2017-10-05
Linux Kernel MEDIUM 5.5
CVE-2017-14991

The sg_ioctl function in drivers/scsi/sg.c in the Linux kernel before 4.13.4 allows local users to obtain sensitive information from uninitialized ke…

Fix: after 4.13.3
Fix from $1,600 2017-10-04
Bcm4355c0 Firmware HIGH 7.5
CVE-2017-11122

On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56, an attacker can trigger an information leak due to insufficient length validation, related to IC…

Fix: after 10.3.3
Fix from $1,950 2017-10-04
Integration Bus MEDIUM 5.3
CVE-2017-1126

IBM WebSphere Message Broker (IBM Integration Bus 9.0 and 10.0) could allow an unauthorized user to obtain sensitive information about software versi…

Patch available
Fix from $1,600 2017-10-04
Android HIGH 7.5
CVE-2017-0814

An information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62800…

Patch available
Fix from $1,950 2017-10-04
Android MEDIUM 5.5
CVE-2017-0815

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0…

Patch available
Fix from $1,600 2017-10-04
Android MEDIUM 5.5
CVE-2017-0816

An information disclosure vulnerability in the Android media framework (libeffects). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0…

Patch available
Fix from $1,600 2017-10-04
Android HIGH 7.5
CVE-2017-0817

An information disclosure vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1,…

Patch available
Fix from $1,950 2017-10-04
Android HIGH 7.5
CVE-2017-0823

An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2.…

Patch available
Fix from $1,950 2017-10-04
Android HIGH 7.5
CVE-2017-0825

An information disclosure vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37305633. References: …

Fix: after 8.0
Fix from $1,950 2017-10-04
Android HIGH 7.5
CVE-2017-0808

An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-623…

Patch available
Fix from $1,950 2017-10-04
Geode MEDIUM 6.5
CVE-2017-9797

When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send m…

Fix: after 1.2.0
Fix from $1,600 2017-10-03
Ubuntu Linux MEDIUM 5.9
CVE-2017-14494EPSS 68%

dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6…

Fix: after 2.77
Fix from $1,600 2017-10-03
Skybox Manager Client Application MEDIUM 5.5
CVE-2017-14770

Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated…

Fix: after 8.5.500
Fix from $1,600 2017-10-03
Wicket MEDIUM 5.3
CVE-2014-0043

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular cla…

Mitigation only
Fix from $1,600 2017-10-03
Jasperreports MEDIUM 6.5
CVE-2017-14941

Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Da…

Mitigation only
Fix from $1,600 2017-10-02
Linux Kernel MEDIUM 5.5
CVE-2017-14954

The waitid implementation in kernel/exit.c in the Linux kernel through 4.13.4 accesses rusage data structures in unintended cases, which allows local…

Fix: after 4.13.4
Fix from $1,600 2017-10-02
Checkmk MEDIUM 5.9
CVE-2017-14955EPSS 12%

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to…

No fix yet
Fix from $1,600 2017-10-02
Arcsight Enterprise Security Manager MEDIUM 5.3
CVE-2017-13990

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disc…

Mitigation only
Fix from $1,600 2017-09-30
Arcsight Enterprise Security Manager MEDIUM 5.3
CVE-2017-13991

An information leakage vulnerability in ArcSight ESM and ArcSight ESM Express, any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1, allows disc…

Mitigation only
Fix from $1,600 2017-09-30
Toolkit HIGH 8.1
CVE-2014-2029

The automatic version check functionality in the tools in Percona Toolkit 2.1 allows man-in-the-middle attackers to obtain sensitive information or e…

Patch available
Fix from $1,950 2017-09-29
Toolkit MEDIUM 5.9
CVE-2015-1027

The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man …

Fix: after 2.2.12
Fix from $1,600 2017-09-29
Laravel MEDIUM 5.9
CVE-2017-14775

Laravel before 5.5.10 mishandles the remember_me token verification process because DatabaseUserProvider does not have constant-time token comparison.

Fix: after 5.5.9
Fix from $1,600 2017-09-28
U.motion Builder MEDIUM 5.3
CVE-2017-9960

An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system respons…

Fix: after 1.2.1
Fix from $1,600 2017-09-26
Dropbox Sdk MEDIUM 5.3
CVE-2014-8889EPSS 6%

Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download atta…

No fix yet
Fix from $1,600 2017-09-26
Openstage 60 Firmware MEDIUM 5.9
CVE-2015-8251

OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G…

Mitigation only
Fix from $1,600 2017-09-25
Identity Manager CRITICAL 9.8
CVE-2017-9393

CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaus…

Mitigation only
Fix from $2,300 2017-09-22
Aspcms MEDIUM 6.5
CVE-2017-14653

member/Orderinfo.asp in ASP4CMS AspCMS 2.7.2 allows remote authenticated users to read arbitrary order information via a modified OrderNo parameter.

Patch available
Fix from $1,600 2017-09-22