Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Enterprise Linux Desktop HIGH 7.5
CVE-2016-5416

389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server …

Mitigation only
Fix from $1,950 2017-06-08
Pulp MEDIUM 5.5
CVE-2016-3111

pulp.spec in the installation process for Pulp 2.8.3 generates the RSA key pairs used to validate messages between the pulp server and pulp consumers…

Fix: after 2.8.2-1
Fix from $1,600 2017-06-08
Oceanstor Uds Firmware HIGH 7.5
CVE-2015-2251

The DeviceManager in Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to obtain sensitive information…

Mitigation only
Fix from $1,950 2017-06-08
Oceanstor Uds Firmware MEDIUM 5.0
CVE-2015-2253

The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive inform…

Mitigation only
Fix from $1,600 2017-06-08
Security Privileged Identity Manager MEDIUM 5.3
CVE-2016-5959

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores sensitive information in URL parameters. This may lead to information disclosure if u…

Patch available
Fix from $1,600 2017-06-07
Security Privileged Identity Manager MEDIUM 5.5
CVE-2016-5960

IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Forc…

Mitigation only
Fix from $1,600 2017-06-07
Tivoli Storage Manager MEDIUM 5.5
CVE-2016-8939

IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) clients/agents store password information in the Windows Registry in a manner which can…

Mitigation only
Fix from $1,600 2017-06-07
Cognos Business Intelligence Server MEDIUM 5.3
CVE-2016-9710

IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially…

Patch available
Fix from $1,600 2017-06-07
Ironic MEDIUM 6.5
CVE-2015-7514

OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.

Patch available
Fix from $1,600 2017-06-07
Personify360 E Business HIGH 7.5
CVE-2017-7313

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, m…

Fix: after 7.6.1
Fix from $1,950 2017-06-07
Spice Gtk MEDIUM 6.5
CVE-2016-3066

The spice-gtk widget allows remote authenticated users to obtain information from the host clipboard.

Mitigation only
Fix from $1,600 2017-06-06
Android MEDIUM 5.5
CVE-2014-9947

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure vulnerability could potentially exist.

Patch available
Fix from $1,600 2017-06-06
Android MEDIUM 5.5
CVE-2014-9951

In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentia…

Patch available
Fix from $1,600 2017-06-06
B305hw2 Firmware MEDIUM 5.3
CVE-2017-8840

Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw…

Patch available
Fix from $1,600 2017-06-05
Lenovo Service Bridge HIGH 7.5
CVE-2016-8230

In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and produc…

Mitigation only
Fix from $1,950 2017-06-04
Junos Space MEDIUM 5.9
CVE-2017-2309

On Juniper Networks Junos Space versions prior to 16.1R1 when certificate based authentication is enabled for the Junos Space cluster, some restricte…

Fix: after 16.1
Fix from $1,600 2017-05-30
Junos HIGH 7.5
CVE-2017-2304

Juniper Networks QFX3500, QFX3600, QFX5100, QFX5200, EX4300 and EX4600 devices running Junos OS 14.1X53 prior to 14.1X53-D40, 15.1X53 prior to 15.1X5…

Mitigation only
Fix from $1,950 2017-05-30
Fortiportal HIGH 7.5
CVE-2017-7338

A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the F…

Fix: after 4.0.0
Fix from $1,950 2017-05-27
Maximo Asset Management MEDIUM 5.3
CVE-2017-1292

IBM Maximo Asset Management 7.5 and 7.6 generates error messages that could reveal sensitive information that could be used in further attacks agains…

Patch available
Fix from $1,600 2017-05-26
Oncommand Unified Manager Core Package HIGH 7.5
CVE-2017-7439

NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving e…

Patch available
Fix from $1,950 2017-05-26
Vanilla HIGH 7.5
CVE-2016-10073EPSS 84%

The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the email domain in sent messages and…

Fix: after 2.3.0
Fix from $1,950 2017-05-23
Ghostscript MEDIUM 5.5
CVE-2016-7977

Ghostscript before 9.21 might allow remote attackers to bypass the SAFER mode protection mechanism and consequently read arbitrary files via the use …

Fix: after 9.20
Fix from $1,600 2017-05-23
Roundcube Webmail MEDIUM 6.5
CVE-2015-5382

program/steps/addressbook/photo.inc in Roundcube Webmail before 1.0.6 and 1.1.x before 1.1.2 allows remote authenticated users to read arbitrary file…

Fix: after 1.0.5
Fix from $1,600 2017-05-23
Roundcube Webmail HIGH 7.5
CVE-2015-5383

Roundcube Webmail 1.1.x before 1.1.2 allows remote attackers to obtain sensitive information by reading files in the (1) config, (2) temp, or (3) log…

Patch available
Fix from $1,950 2017-05-23
Wlan Acu2 Firmware HIGH 7.5
CVE-2015-6586

The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive in…

Mitigation only
Fix from $1,950 2017-05-23
Linux Kernel MEDIUM 5.5
CVE-2017-9150

The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting th…

Fix: after 4.10.9
Fix from $1,600 2017-05-22
Metadata Anonymisation Toolkit HIGH 7.5
CVE-2017-9149

Metadata Anonymisation Toolkit (MAT) 0.6 and 0.6.1 silently fails to perform "Clean metadata" actions upon invocation from the Nautilus contextual me…

Patch available
Fix from $1,950 2017-05-22
Iphone Os MEDIUM 5.5
CVE-2017-6987

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: after 10.12.4
Fix from $1,600 2017-05-22
Iphone Os MEDIUM 5.5
CVE-2017-2507

An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. w…

Fix: 3.2.2 / 10.2.1+
Fix from $1,600 2017-05-22
Remote Expert Manager MEDIUM 5.3
CVE-2017-6642

A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensiti…

No fix yet
Fix from $1,600 2017-05-22