Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Capi Release HIGH 7.5
CVE-2017-8037

In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an…

Mitigation only
Fix from $1,950 2017-08-21
Android HIGH 7.5
CVE-2017-9679

In all Qualcomm products with Android releases from CAF using the Linux kernel, if a userspace string is not NULL-terminated, kernel memory contents …

Mitigation only
Fix from $1,950 2017-08-18
Android HIGH 7.5
CVE-2017-9680

In all Qualcomm products with Android releases from CAF using the Linux kernel, if a pointer argument coming from userspace is invalid, a driver may …

Mitigation only
Fix from $1,950 2017-08-18
Android MEDIUM 5.5
CVE-2017-8254

In all Qualcomm products with Android releases from CAF using the Linux kernel, an audio client pointer is dereferenced before being checked if it is…

Patch available
Fix from $1,600 2017-08-18
Helpdesk Pro MEDIUM 5.3
CVE-2015-4071EPSS 10%

The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target tick…

Fix: after 1.3.0
Fix from $1,600 2017-08-18
Ganeti HIGH 7.5
CVE-2015-7945EPSS 9%

The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11.8, 2.12.x before 2.12.6, 2.1…

Fix: after 2.9.6
Fix from $1,950 2017-08-18
Websphere Application Server MEDIUM 5.9
CVE-2017-1501

IBM WebSphere Application Server 8.0, 8.5, and 9.0 could provide weaker than expected security after using the Admin Console to update the web servic…

Patch available
Fix from $1,600 2017-08-18
Ultra Services Framework HIGH 7.5
CVE-2017-6771

A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensi…

Mitigation only
Fix from $1,950 2017-08-17
Ultra Services Platform MEDIUM 6.5
CVE-2017-6778

A vulnerability in the Elastic Services Controller (ESC) web interface of the Cisco Ultra Services Platform could allow an authenticated, remote atta…

Mitigation only
Fix from $1,600 2017-08-17
Small Business Rv340 Firmware MEDIUM 5.3
CVE-2017-6784

A vulnerability in the web interface of the Cisco RV340, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attack…

Mitigation only
Fix from $1,600 2017-08-17
Elastic Services Controller MEDIUM 6.3
CVE-2017-6786

A vulnerability in Cisco Elastic Services Controller could allow an authenticated, local, unprivileged attacker to access sensitive information, incl…

Mitigation only
Fix from $1,600 2017-08-17
Xen MEDIUM 6.5
CVE-2017-12855

Xen maintains the _GTF_{read,writ}ing bits as appropriate, to inform the guest that a grant is in use. A guest is expected not to modify the grant de…

Mitigation only
Fix from $1,600 2017-08-15
Emptoris Strategic Supply Management MEDIUM 5.9
CVE-2016-6029

IBM Emptoris Strategic Supply Management Platform 10.0 and 10.1 could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-08-14
Fortimanager Firmware HIGH 7.5
CVE-2015-3614

Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspeci…

Mitigation only
Fix from $1,950 2017-08-11
Experience Manager HIGH 7.5
CVE-2017-3107EPSS 7%

Adobe Experience Manager 6.3 and earlier has a misconfiguration vulnerability.

Fix: after 6.3
Fix from $1,950 2017-08-11
Experience Manager HIGH 7.5
CVE-2017-3110EPSS 5%

Adobe Experience Manager 6.1 and earlier has a sensitive data exposure vulnerability.

Fix: after 6.1
Fix from $1,950 2017-08-11
Acrobat MEDIUM 6.5
CVE-2017-3115EPSS 6%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an information d…

Fix: 11.0.21 / 15.006.30355+
Fix from $1,600 2017-08-11
Acrobat MEDIUM 6.5
CVE-2017-3118EPSS 9%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has a security bypas…

Fix: 11.0.21 / 15.006.30355+
Fix from $1,600 2017-08-11
Digital Editions HIGH 7.5
CVE-2017-11272EPSS 13%

Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.

Fix: after 4.5.5
Fix from $1,950 2017-08-11
Acrobat MEDIUM 6.5
CVE-2017-11232EPSS 8%

Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable u…

Fix: after 17.011.30066
Fix from $1,600 2017-08-11
Android MEDIUM 5.5
CVE-2017-8258

An array out-of-bounds access in all Qualcomm products with Android releases from CAF using the Linux kernel can potentially occur in a camera driver.

Patch available
Fix from $1,600 2017-08-11
Android MEDIUM 5.5
CVE-2017-8269

Userspace-controlled non null terminated parameter for IPA WAN ioctl in all Qualcomm products with Android releases from CAF using the Linux kernel c…

Patch available
Fix from $1,600 2017-08-11
Fortios HIGH 7.5
CVE-2017-3130

An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting…

Mitigation only
Fix from $1,950 2017-08-10
Android MEDIUM 5.5
CVE-2017-0738

A information disclosure vulnerability in the Android media framework (audioserver). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0…

Patch available
Fix from $1,600 2017-08-09
Android MEDIUM 5.5
CVE-2017-0739

A information disclosure vulnerability in the Android media framework (libhevc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.…

Patch available
Fix from $1,600 2017-08-09
Mod Nss HIGH 7.5
CVE-2015-3277

The mod_nss module before 1.0.11 in Fedora allows remote attackers to obtain cipher lists due to incorrect parsing of multi-keyword cipherstring.

Fix: after 1.0.10
Fix from $1,950 2017-08-09
Zenworks Configuration Management MEDIUM 6.5
CVE-2015-0783

The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename var…

Mitigation only
Fix from $1,600 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0784EPSS 7%

Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLo…

Mitigation only
Fix from $1,950 2017-08-09
Zenworks Configuration Management HIGH 7.5
CVE-2015-0785EPSS 7%

com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary…

Mitigation only
Fix from $1,950 2017-08-09
Edge MEDIUM 6.5
CVE-2017-8652EPSS 23%

Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to disclose information due to the way that…

Patch available
Fix from $1,600 2017-08-08