Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Digital Editions HIGH 7.5
CVE-2016-7889EPSS 6%

Adobe Digital Editions versions 4.5.2 and earlier has an issue with parsing crafted XML entries that could lead to information disclosure.

Fix: after 4.5.2
Fix from $1,950 2016-12-15
Digital Editions MEDIUM 5.3
CVE-2016-7888

Adobe Digital Editions versions 4.5.2 and earlier has an important vulnerability that could lead to memory address leak.

Fix: after 4.5.2
Fix from $1,600 2016-12-15
Coldfusion Builder HIGH 7.5
CVE-2016-7887

Adobe ColdFusion Builder versions 2016 update 2 and earlier, 3.0.3 and earlier have an important vulnerability that could lead to information disclos…

Fix: after 3.0.3
Fix from $1,950 2016-12-15
iOS HIGH 7.5
CVE-2016-9201

A vulnerability in the Zone-Based Firewall feature of Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to pass tra…

Mitigation only
Fix from $1,950 2016-12-14
Firesight System Software MEDIUM 6.5
CVE-2016-6471

A vulnerability in the web-based management interface of Cisco Firepower Management Center running FireSIGHT System software could allow an authentic…

Mitigation only
Fix from $1,600 2016-12-14
Unified Communications Manager Im And Presence Service HIGH 7.5
CVE-2016-6464

A vulnerability in the web management interface of the Cisco Unified Communications Manager IM and Presence Service could allow an unauthenticated, r…

Mitigation only
Fix from $1,950 2016-12-14
Debian Linux MEDIUM 5.3
CVE-2016-6313

The mixing functions in the random number generator in Libgcrypt before 1.5.6, 1.6.x before 1.6.6, and 1.7.x before 1.7.3 and GnuPG before 1.4.21 mak…

Fix: after 1.5.3
Fix from $1,600 2016-12-13
Android MEDIUM 5.5
CVE-2016-6722

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x bef…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-12-13
Android MEDIUM 5.5
CVE-2016-6720

An information disclosure vulnerability in libstagefright in Mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x bef…

Fix: 4.4.4 / 5.0.2+
Fix from $1,600 2016-12-13
Powerkvm CRITICAL 9.1
CVE-2015-5073EPSS 8%

Heap-based buffer overflow in the find_fixedlength function in pcre_compile.c in PCRE before 8.38 allows remote attackers to cause a denial of servic…

Fix: after 8.37
Fix from $2,300 2016-12-13
phpMyAdmin MEDIUM 5.3
CVE-2016-9855

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9854

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9853

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9852

An issue was discovered in phpMyAdmin. By calling some scripts that are part of phpMyAdmin in an unexpected way, it is possible to trigger phpMyAdmin…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-9848

An issue was discovered in phpMyAdmin. phpinfo (phpinfo.php) shows PHP information including values of HttpOnly cookies. All 4.6.x versions (prior to…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-6627

An issue was discovered in phpMyAdmin. An attacker can determine the phpMyAdmin host location through the file url.php. All 4.6.x versions (prior to …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 5.3
CVE-2016-6613

An issue was discovered in phpMyAdmin. A user can specially craft a symlink on disk, to a file which phpMyAdmin is permitted to read but the user is …

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin MEDIUM 6.5
CVE-2016-6612

An issue was discovered in phpMyAdmin. A user can exploit the LOAD LOCAL INFILE functionality to expose files on the server to the database system. A…

Patch available
Fix from $1,600 2016-12-11
phpMyAdmin HIGH 8.1
CVE-2016-6606

An issue was discovered in cookie encryption in phpMyAdmin. The decryption of the username/password is vulnerable to a padding oracle attack. This ca…

Patch available
Fix from $1,950 2016-12-11
Debian Linux MEDIUM 6.0
CVE-2016-9103

The v9fs_xattrcreate function in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allows local guest OS administrators to obtain sensitive host heap memory …

Fix: after 2.7.1
Fix from $1,600 2016-12-09
Mapserver HIGH 7.5
CVE-2016-9839

In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.

Fix: after 7.0.2
Fix from $1,950 2016-12-08
Api Connect HIGH 7.5
CVE-2016-3012

IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which mig…

Fix: after 5.0.2.0
Fix from $1,950 2016-12-01
Ims Enterprise Suite HIGH 8.1
CVE-2016-2887

IBM IMS Enterprise Suite Data Provider before 3.2.0.1 for Microsoft .NET allows remote authenticated users to obtain sensitive information or modify …

Fix: after 3.2.0.0
Fix from $1,950 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2940

Multiple unspecified vulnerabilities in IBM BigFix Remote Control before 9.1.3 allow remote attackers to obtain sensitive information via unknown vec…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 6.5
CVE-2016-2937

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive information or spoof e-mail transmission via a crafted POST reques…

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Bigfix Remote Control MEDIUM 5.3
CVE-2016-2931

IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.

Fix: after 9.1.2
Fix from $1,600 2016-11-30
Host Access Management And Security Server MEDIUM 6.5
CVE-2016-5765

Administrative Server in Micro Focus Host Access Management and Security Server (MSS) and Reflection for the Web (RWeb) and Reflection Security Gatew…

Mitigation only
Fix from $1,600 2016-11-29
Linux Kernel MEDIUM 5.5
CVE-2016-9178

The __get_user_asm_ex macro in arch/x86/include/asm/uaccess.h in the Linux kernel before 4.7.5 does not initialize a certain integer variable, which …

Fix: after 4.7.4
Fix from $1,600 2016-11-28
Bigfix Remote Control MEDIUM 5.9
CVE-2016-2927

IBM BigFix Remote Control before 9.1.3 does not properly restrict the set of available encryption algorithms, which makes it easier for remote attack…

Fix: after 9.1.2
Fix from $1,600 2016-11-25
Android MEDIUM 5.5
CVE-2016-6753

An information disclosure vulnerability in kernel components, including the process-grouping subsystem and the networking subsystem, in Android befor…

Fix: after 7.0
Fix from $1,600 2016-11-25