Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jasperreports Library Community Edition MEDIUM 6.5
CVE-2017-5529

JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any acces…

Fix: after 6.4.0
Fix from $1,600 2017-06-29
Windows 10 MEDIUM 5.5
CVE-2017-8575

The kernel in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an authenticated attacker to obtain information via a speci…

Patch available
Fix from $1,600 2017-06-29
Ignite HIGH 7.5
CVE-2017-7686

Apache Ignite 1.0.0-RC3 to 2.0 uses an update notifier component to update the users about new project releases that include additional functionality…

Mitigation only
Fix from $1,950 2017-06-28
Debian Linux HIGH 7.5
CVE-2017-9993EPSS 16%

FFmpeg before 2.8.12, 3.0.x and 3.1.x before 3.1.9, 3.2.x before 3.2.6, and 3.3.x before 3.3.2 does not properly restrict HTTP Live Streaming filenam…

Fix: 2.8.12 / 3.1.9+
Fix from $1,950 2017-06-28
Logstash HIGH 7.5
CVE-2015-5378

Logstash 1.5.x before 1.5.3 and 1.4.x before 1.4.4 allows remote attackers to read communications between Logstash Forwarder agent and Logstash serve…

No fix yet
Fix from $1,950 2017-06-27
Tivoli Monitoring MEDIUM 5.3
CVE-2016-6083

IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.

Patch available
Fix from $1,600 2017-06-27
Openvpn HIGH 7.4
CVE-2017-7520

OpenVPN versions before 2.4.3 and before 2.3.17 are vulnerable to denial-of-service and/or possibly sensitive memory leak triggered by man-in-the-mid…

Fix: after 2.3.16
Fix from $1,950 2017-06-27
Automatic Bug Reporting Tool MEDIUM 5.5
CVE-2015-1870

The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which all…

Fix: after 2.1.11
Fix from $1,600 2017-06-26
Debian Linux MEDIUM 5.5
CVE-2017-9868

In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic infor…

Fix: after 1.4.12
Fix from $1,600 2017-06-25
Sterling B2b Integrator MEDIUM 5.5
CVE-2016-5893

IBM Sterling B2B Integrator Standard Edition 5.2 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force I…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 6.5
CVE-2017-1131

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information by using unsupported, specially cr…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 6.5
CVE-2017-1193

IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2017-1302

IBM Sterling B2B Integrator Standard Edition 5.2 could allow a local user view sensitive information due to improper access controls. IBM X-Force ID:…

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2017-1349

IBM Sterling B2B Integrator Standard Edition 5.2 stores potentially sensitive information from HTTP sessions that could be read by a local user. IBM …

Patch available
Fix from $1,600 2017-06-23
Sterling B2b Integrator MEDIUM 6.5
CVE-2016-9982

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to impro…

Patch available
Fix from $1,600 2017-06-22
Sterling B2b Integrator MEDIUM 5.3
CVE-2016-9983

IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have ac…

Patch available
Fix from $1,600 2017-06-22
Vtscada HIGH 7.5
CVE-2017-6045

An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application…

Fix: after 11.2.23
Fix from $1,950 2017-06-21
Captivate HIGH 7.5
CVE-2017-3087

Adobe Captivate versions 9 and earlier have an information disclosure vulnerability resulting from abuse of the quiz reporting feature in Captivate.

Fix: after 9.0
Fix from $1,950 2017-06-20
Advanced Settings Utility HIGH 7.5
CVE-2017-3743

If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utili…

Fix: after 10.2
Fix from $1,950 2017-06-20
Linux Kernel MEDIUM 5.5
CVE-2017-1000380

sound/core/timer.c in the Linux kernel before 4.11.5 is vulnerable to a data race in the ALSA /dev/snd/timer driver resulting in local users being ab…

Fix: after 4.11.4
Fix from $1,600 2017-06-17
Logstash HIGH 7.5
CVE-2016-1000221

Logstash prior to version 2.3.4, Elasticsearch Output plugin would log to file HTTP authorization headers which could contain sensitive information.

Fix: after 2.3.3
Fix from $1,950 2017-06-16
Output Plugin MEDIUM 6.5
CVE-2016-10362

Prior to Logstash version 5.0.1, Elasticsearch Output plugin when updating connections after sniffing, would log to file HTTP basic auth credentials.

Fix: after 5.0.0
Fix from $1,600 2017-06-16
X Pack MEDIUM 5.9
CVE-2017-8449

X-Pack Security 5.2.x would allow access to more fields than the user should have seen if the field level security rules used a mix of grant and excl…

Fix: after 5.2.2
Fix from $1,600 2017-06-16
X Pack HIGH 7.5
CVE-2017-8450

X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document an…

Mitigation only
Fix from $1,950 2017-06-16
Yp Core Pyro HIGH 7.5
CVE-2017-9731

In meta/classes/package_ipk.bbclass in Poky in poky-pyro 17.0.0 for Yocto Project through YP Core - Pyro 2.3, attackers can obtain sensitive informat…

Patch available
Fix from $1,950 2017-06-16
Avira Mobile Security HIGH 7.5
CVE-2015-7732

The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.

Mitigation only
Fix from $1,950 2017-06-15
Api Connect HIGH 7.5
CVE-2017-1379

IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Porta…

Patch available
Fix from $1,950 2017-06-15
Office MEDIUM 6.5
CVE-2017-8531EPSS 7%

Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1…

Patch available
Fix from $1,600 2017-06-15
Office MEDIUM 6.5
CVE-2017-8532EPSS 7%

Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1…

Patch available
Fix from $1,600 2017-06-15
Office MEDIUM 6.5
CVE-2017-8533EPSS 8%

Graphics in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1…

Patch available
Fix from $1,600 2017-06-15