Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
U Verse Firmware HIGH 8.1
CVE-2017-10793

The AT&T U-verse 9.2.2h0d83 firmware for the Arris NVG589, NVG599, and unspecified other devices, when IP Passthrough mode is not used, configures an…

No fix yet
Fix from $1,950 2017-09-03
Asterisk HIGH 7.5
CVE-2017-14099

In res/res_rtp_asterisk.c in Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17…

Patch available
Fix from $1,950 2017-09-02
Rtpproxy MEDIUM 6.5
CVE-2017-14114

RTPproxy through 2.2.alpha.20160822 has a NAT feature that results in not properly determining the IP address and port number of the legitimate recip…

Fix: after 2.2
Fix from $1,600 2017-09-02
Debian Linux MEDIUM 5.9
CVE-2017-12872

The (1) Htpasswd authentication source in the authcrypt module and (2) SimpleSAML_Session class in SimpleSAMLphp 1.14.11 and earlier allow remote att…

Fix: after 1.14.11
Fix from $1,600 2017-09-01
Oncommand Unified Manager For Clustered Data Ontap HIGH 7.5
CVE-2017-14053

NetApp OnCommand Unified Manager for Clustered Data ONTAP before 7.2P1 does not set the secure flag for an unspecified cookie in an HTTPS session, wh…

Fix: after 7.2
Fix from $1,950 2017-09-01
Simplesamlphp MEDIUM 5.9
CVE-2017-12870

SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt …

Fix: after 1.14.12
Fix from $1,600 2017-09-01
Soplanning HIGH 7.5
CVE-2014-8675EPSS 13%

Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtai…

Fix: after 1.32
Fix from $1,950 2017-08-31
Hadoop MEDIUM 5.5
CVE-2016-5001

This is an information disclosure vulnerability in Apache Hadoop before 2.6.4 and 2.7.x before 2.7.2 in the short-circuit reads feature of HDFS. A lo…

Fix: after 2.6.3
Fix from $1,600 2017-08-30
Logo\!8 Bm Fs 05 Firmware HIGH 7.5
CVE-2017-12734

A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V1.81.2). An attacker with network access to the integrated…

Fix: after 1.81.1
Fix from $1,950 2017-08-30
Ivms 4200 HIGH 7.8
CVE-2017-13774

Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors.

Fix: after 2.6.2.6
Fix from $1,950 2017-08-30
Debian Linux HIGH 7.5
CVE-2017-0379

Libgcrypt before 1.8.1 does not properly consider Curve25519 side-channel attacks, which makes it easier for attackers to discover a secret key, rela…

Fix: after 1.8.0
Fix from $1,950 2017-08-29
Sametime MEDIUM 5.3
CVE-2016-2964

IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the applica…

Patch available
Fix from $1,600 2017-08-29
Googlemaps MEDIUM 5.3
CVE-2013-7431

Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.

Fix: after 3.0
Fix from $1,600 2017-08-29
Atlas HIGH 7.5
CVE-2017-3154

Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information.

Mitigation only
Fix from $1,950 2017-08-29
Sametime MEDIUM 5.3
CVE-2016-2971

IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. …

Mitigation only
Fix from $1,600 2017-08-29
Ox 330p Firmware HIGH 7.5
CVE-2015-7255

ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which …

Mitigation only
Fix from $1,950 2017-08-29
Curam Social Program Management MEDIUM 6.5
CVE-2017-1110

IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the i…

Patch available
Fix from $1,600 2017-08-29
Quantastor MEDIUM 5.3
CVE-2017-9978

On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on…

Fix: after 4.3.0
Fix from $1,600 2017-08-28
Indoor Module Firmware HIGH 7.5
CVE-2015-1600

Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.

Fix: after 100.0
Fix from $1,950 2017-08-28
Emacs HIGH 7.5
CVE-2014-9483

Emacs 24.4 allows remote attackers to bypass security restrictions.

No fix yet
Fix from $1,950 2017-08-28
Unified Communications Software HIGH 8.8
CVE-2017-12857

Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affecte…

Fix: after 5.5.1
Fix from $1,950 2017-08-25
Dns 327l Firmware MEDIUM 5.3
CVE-2014-7860EPSS 10%

The web/web_file/fb_publish.php script in D-Link DNS-320L before 1.04b12 and DNS-327L before 1.03b04 Build0119 does not authenticate requests, which …

Fix: after 1.03b04
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 5.5
CVE-2017-13693

The acpi_ds_create_operands() function in drivers/acpi/acpica/dsutils.c in the Linux kernel through 4.12.9 does not flush the operand cache and cause…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 5.5
CVE-2017-13694

The acpi_ps_complete_final_op() function in drivers/acpi/acpica/psobject.c in the Linux kernel through 4.12.9 does not flush the node and node_ext ca…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Linux Kernel MEDIUM 5.5
CVE-2017-13695

The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kern…

Fix: after 4.12.9
Fix from $1,600 2017-08-25
Galaxy S4 Firmware HIGH 7.5
CVE-2015-1800

The samsung_extdisp driver in the Samsung S4 (GT-I9500) I9500XXUEMK8 kernel 3.4 and earlier allows attackers to potentially obtain sensitive informat…

No fix yet
Fix from $1,950 2017-08-24
Crucible HIGH 7.5
CVE-2017-9512

The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive in…

Fix: after 4.4.0
Fix from $1,950 2017-08-24
Imagemagick HIGH 7.5
CVE-2017-13143

In ImageMagick before 6.9.7-6 and 7.x before 7.0.4-6, the ReadMATImage function in coders/mat.c uses uninitialized data, which might allow remote att…

Fix: after 6.9.7-5
Fix from $1,950 2017-08-23
Enterprise Virtualization MEDIUM 5.5
CVE-2016-6310

oVirt Engine discloses the ENGINE_HTTPS_PKI_TRUST_STORE_PASSWORD in /var/log/ovirt-engine/engine.log file in RHEV before 4.0.

Fix: after 3.6
Fix from $1,600 2017-08-22
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2016-6311

Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.

Mitigation only
Fix from $1,600 2017-08-22