Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Tealeaf Customer Experience On Cloud Network Capture Add On MEDIUM 5.9
CVE-2016-5900

IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure …

Patch available
Fix from $1,600 2017-02-08
Client Application Access MEDIUM 5.9
CVE-2016-0270

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which mak…

Patch available
Fix from $1,600 2017-02-08
Alteon MEDIUM 5.9
CVE-2016-10212

Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a …

Fix: after 30.2.1.1
Fix from $1,600 2017-02-08
Advanced Core Operating System MEDIUM 5.9
CVE-2016-10213

A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to …

Fix: after 2.7.2
Fix from $1,600 2017-02-08
Fortios MEDIUM 5.9
CVE-2016-8492

The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPS…

Fix: after 4.3.18
Fix from $1,600 2017-02-08
Netscaler Application Delivery Controller Firmware MEDIUM 5.9
CVE-2017-5933

Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GC…

Fix: after 11.1.51.21
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0420

An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate a…

Mitigation only
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0421

An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that …

Mitigation only
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0424

An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its p…

Mitigation only
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0425

An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. Th…

Mitigation only
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0426

An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels.…

Mitigation only
Fix from $1,600 2017-02-08
Linux Kernel MEDIUM 5.5
CVE-2017-0448

An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio…

Fix: after 7.1.1
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0413

An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isol…

Mitigation only
Fix from $1,600 2017-02-08
Android MEDIUM 5.5
CVE-2017-0414

An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isol…

Mitigation only
Fix from $1,600 2017-02-08
Snapdrive HIGH 7.5
CVE-2015-8544

NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified ve…

Fix: after 7.1.3
Fix from $1,950 2017-02-07
Simplesamlphp MEDIUM 5.3
CVE-2016-3124

The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.

Fix: after 1.14.0
Fix from $1,600 2017-02-07
Clustered Data Ontap HIGH 7.5
CVE-2016-4341

NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors.

Fix: after 8.3.2
Fix from $1,950 2017-02-07
Data Ontap MEDIUM 5.9
CVE-2016-6495

NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP acces…

Fix: after 8.2.4
Fix from $1,600 2017-02-07
Security Key Lifecycle Manager MEDIUM 6.2
CVE-2016-6092

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.

Patch available
Fix from $1,600 2017-02-07
FreeBSD MEDIUM 5.5
CVE-2015-5677

bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secr…

Patch available
Fix from $1,600 2017-02-07
Openafs MEDIUM 5.3
CVE-2016-9772

OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2…

Fix: after 1.6.19
Fix from $1,600 2017-02-06
Zoneminder MEDIUM 5.5
CVE-2017-5595

A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being p…

Fix: after 1.30.0
Fix from $1,600 2017-02-06
Linux Kernel MEDIUM 5.5
CVE-2017-5550

Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information f…

Fix: after 4.9.4
Fix from $1,600 2017-02-06
Powerpath Virtual Appliance MEDIUM 6.4
CVE-2016-0890

EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclos…

No fix yet
Fix from $1,600 2017-02-03
Dashboard Application Services Hub MEDIUM 5.9
CVE-2016-5935

IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL cer…

Mitigation only
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.3
CVE-2016-6099

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further atta…

Patch available
Fix from $1,600 2017-02-02
Security Key Lifecycle Manager MEDIUM 5.9
CVE-2016-6116

IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable …

Patch available
Fix from $1,600 2017-02-02
License Metric Tool MEDIUM 5.3
CVE-2016-8977

IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount…

Mitigation only
Fix from $1,600 2017-02-01
Infosphere Datastage MEDIUM 5.3
CVE-2016-8982

IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav…

Patch available
Fix from $1,600 2017-02-01
Urbancode Deploy MEDIUM 5.5
CVE-2016-2941

IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by…

Mitigation only
Fix from $1,600 2017-02-01