Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Bitcoin Knots MEDIUM 6.2
CVE-2016-8889

In Bitcoin Knots v0.11.0.ljr20150711 through v0.13.0.knots20160814 (fixed in v0.13.1.knots20161027), the debug console stores sensitive information i…

Patch available
Fix from $1,600 2016-10-28
Botan MEDIUM 6.2
CVE-2016-8871

In Botan 1.11.29 through 1.11.32, RSA decryption with certain padding options had a detectable timing channel which could given sufficient queries be…

Mitigation only
Fix from $1,600 2016-10-28
Moodle HIGH 7.5
CVE-2016-7919

Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Admini…

No fix yet
Fix from $1,950 2016-10-28
Meeting Server HIGH 7.5
CVE-2016-6446

A vulnerability in Web Bridge for Cisco Meeting Server could allow an unauthenticated, remote attacker to retrieve memory from a connected server. Mo…

Mitigation only
Fix from $1,950 2016-10-27
Data Integrator MEDIUM 5.7
CVE-2016-5602

Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0, and 12.…

Patch available
Fix from $1,600 2016-10-25
Jdk MEDIUM 5.9
CVE-2016-5597

Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vec…

Patch available
Fix from $1,600 2016-10-25
Common Applications MEDIUM 5.3
CVE-2016-5575

Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12…

Patch available
Fix from $1,600 2016-10-25
Hospitality Opera 5 Property Services HIGH 7.7
CVE-2016-5565

Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5…

Patch available
Fix from $1,950 2016-10-25
Agile Product Lifecycle Management MEDIUM 5.3
CVE-2016-5524

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,600 2016-10-25
Agile Product Lifecycle Management MEDIUM 5.3
CVE-2016-5510

Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect c…

Patch available
Fix from $1,600 2016-10-25
Database Server MEDIUM 5.5
CVE-2016-5505

Unspecified vulnerability in the RDBMS Programmable Interface component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows local users to affect …

Patch available
Fix from $1,600 2016-10-25
Discoverer HIGH 7.5
CVE-2016-5500

Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality…

Patch available
Fix from $1,950 2016-10-25
Discoverer HIGH 7.5
CVE-2016-5495

Unspecified vulnerability in the Oracle Discoverer component in Oracle Fusion Middleware 11.1.1.7.0 allows remote attackers to affect confidentiality…

Patch available
Fix from $1,950 2016-10-25
Business Intelligence Publisher HIGH 7.7
CVE-2016-3473EPSS 14%

Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 a…

Patch available
Fix from $1,950 2016-10-25
Wireless H500 MEDIUM 5.3
CVE-2016-1000214

Ruckus Wireless H500 web management interface authentication bypass

Mitigation only
Fix from $1,600 2016-10-25
Security Guardium HIGH 7.8
CVE-2016-0247

IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartex…

Patch available
Fix from $1,950 2016-10-22
Edge MEDIUM 5.3
CVE-2016-3391EPSS 8%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow context-dependent attackers to discover credentials by leveraging access to a memory d…

Mitigation only
Fix from $1,600 2016-10-14
Edge MEDIUM 5.3
CVE-2016-3267EPSS 16%

Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to determine the existence of unspecified files via a crafted web …

Mitigation only
Fix from $1,600 2016-10-14
Live Meeting MEDIUM 5.5
CVE-2016-3263EPSS 32%

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…

Mitigation only
Fix from $1,600 2016-10-14
Live Meeting MEDIUM 5.5
CVE-2016-3262EPSS 32%

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…

Mitigation only
Fix from $1,600 2016-10-14
.net Framework MEDIUM 5.5
CVE-2016-3209EPSS 54%

Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows S…

Mitigation only
Fix from $1,600 2016-10-14
Windows 10 MEDIUM 5.0
CVE-2016-0079EPSS 5%

The kernel in Microsoft Windows 10 Gold, 1511, and 1607 allows local users to gain privileges via a crafted application that makes an API call to acc…

No fix yet
Fix from $1,600 2016-10-14
Windows 10 MEDIUM 5.5
CVE-2016-0075EPSS 7%

The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain …

No fix yet
Fix from $1,600 2016-10-14
Windows 10 MEDIUM 5.0
CVE-2016-0073EPSS 5%

The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to gain …

No fix yet
Fix from $1,600 2016-10-14
Windows 10 MEDIUM 5.5
CVE-2016-0070EPSS 11%

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows R…

Mitigation only
Fix from $1,600 2016-10-14
Sapconsole HIGH 7.8
CVE-2016-3946

SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note …

Mitigation only
Fix from $1,950 2016-10-13
Integrated Performance Primitives MEDIUM 5.5
CVE-2016-8100

Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-c…

Fix: after 9.0.3
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6689

Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka in…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6688

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…

Fix: after 7.0
Fix from $1,600 2016-10-10
Android MEDIUM 5.5
CVE-2016-6687

The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, aka i…

Fix: after 7.0
Fix from $1,600 2016-10-10