Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Qradar Incident Forensics MEDIUM 5.3
CVE-2016-9720

IBM QRadar 7.2 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM Referen…

Patch available
Fix from $1,600 2017-03-07
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2016-9725

IBM QRadar Incident Forensics 7.2 allows for Cross-Origin Resource Sharing (CORS), which is a mechanism that allows web sites to request resources fr…

Patch available
Fix from $1,600 2017-03-07
Hue MEDIUM 5.3
CVE-2016-4947

Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.

Fix: after 3.9.0
Fix from $1,600 2017-03-07
Manager HIGH 7.5
CVE-2016-4949

Cloudera Manager 5.5 and earlier allows remote attackers to obtain sensitive information via a (1) stderr.log or (2) stdout.log value in the filename…

Fix: after 5.5.0
Fix from $1,950 2017-03-07
Manager HIGH 7.5
CVE-2016-4950

Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.

Fix: after 5.5.0
Fix from $1,950 2017-03-07
Debian Linux MEDIUM 5.5
CVE-2013-5653

The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted p…

Patch available
Fix from $1,600 2017-03-07
Good Control Server HIGH 7.5
CVE-2016-3127

An information disclosure vulnerability in the logging implementation of BlackBerry Good Control Server versions earlier than 2.3.53.62 allows remote…

Fix: after 2.2.511.26
Fix from $1,950 2017-03-03
Matrixssl MEDIUM 5.9
CVE-2016-6882

MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information …

Fix: after 3.8.6
Fix from $1,600 2017-03-03
Matrixssl MEDIUM 5.9
CVE-2016-6883EPSS 14%

MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.

Fix: after 3.8.2
Fix from $1,600 2017-03-03
Dropbear Ssh MEDIUM 5.5
CVE-2016-7409

The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument…

Fix: after 2016.73
Fix from $1,600 2017-03-03
Ontap Select Deploy Administration Utility HIGH 7.5
CVE-2017-5995

The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified …

Mitigation only
Fix from $1,950 2017-03-01
Sinumerik Integrate Access Mymachine\/ethernet HIGH 7.4
CVE-2017-2685

Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (ex…

Mitigation only
Fix from $1,950 2017-03-01
Yandex Browser MEDIUM 6.5
CVE-2016-8507

Yandex Browser for iOS before 16.10.0.2357 does not properly restrict processing of facetime:// URLs, which allows remote attackers to initiate facet…

Fix: 16.10.0.2357+
Fix from $1,600 2017-03-01
A64 HIGH 7.5
CVE-2017-5925

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors…

No fix yet
Fix from $1,950 2017-02-27
A64 HIGH 7.5
CVE-2017-5926

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. …

No fix yet
Fix from $1,950 2017-02-27
A64 HIGH 7.5
CVE-2017-5927

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. …

No fix yet
Fix from $1,950 2017-02-27
Plone MEDIUM 5.3
CVE-2016-4042

Plone 3.3 through 5.1a1 allows remote attackers to obtain information about the ID of sensitive content via unspecified vectors.

Mitigation only
Fix from $1,600 2017-02-24
Wolfssl MEDIUM 5.5
CVE-2017-6076

In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to …

Fix: 3.10.2+
Fix from $1,600 2017-02-24
Websmart Dgs 1510 Series Firmware HIGH 7.5
CVE-2017-6206EPSS 16%

D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31…

Fix: after 1.31.b001
Fix from $1,950 2017-02-23
Websphere Mq MEDIUM 5.9
CVE-2016-3052

Under non-standard configurations, IBM WebSphere MQ might send password data in clear text over the network. This data could be intercepted using man…

Fix: after 8.0.0.5
Fix from $1,600 2017-02-22
Xen MEDIUM 6.5
CVE-2016-9384

Xen 4.7 allows local guest OS users to obtain sensitive host information by loading a 32-bit ELF symbol table.

Patch available
Fix from $1,600 2017-02-22
Secure Access Control System HIGH 7.5
CVE-2017-3841

A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sens…

Mitigation only
Fix from $1,950 2017-02-22
Intrusion Prevention System Device Manager MEDIUM 5.3
CVE-2017-3842

A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, r…

Mitigation only
Fix from $1,600 2017-02-22
Vce Vision Intelligent Operations HIGH 7.5
CVE-2015-4057

The "Plug-in for VMware vCenter" in VCE Vision Intelligent Operations before 2.6.5 sends a cleartext HTTP response upon a request for the Settings sc…

Fix: after 2.6.4
Fix from $1,950 2017-02-21
Interscan Web Security Virtual Appliance HIGH 7.8
CVE-2016-9314

Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) version 6…

Fix: after 6.5
Fix from $1,950 2017-02-21
Form Builder CRITICAL 9.8
CVE-2017-6070

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template p…

Fix: after 1.12.2
Fix from $2,300 2017-02-21
Form Builder MEDIUM 5.3
CVE-2017-6071

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.

Fix: after 1.12.2
Fix from $1,600 2017-02-21
Form Builder MEDIUM 5.3
CVE-2017-6072

CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin.

Fix: after 1.12.2
Fix from $1,600 2017-02-21
Windows 10 MEDIUM 5.5
CVE-2017-0038EPSS 82%

gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows …

Patch available
Fix from $1,600 2017-02-20
Big Ip Access Policy Manager MEDIUM 5.3
CVE-2016-6249

F5 BIG-IP 12.0.0 and 11.5.0 - 11.6.1 REST requests which timeout during user account authentication may log sensitive attributes such as passwords in…

Mitigation only
Fix from $1,600 2017-02-20