Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fusioncompute MEDIUM 6.5
CVE-2016-6827

Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive inform…

Mitigation only
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.8
CVE-2016-5972

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Security Privileged Identity Manager Virtual Appliance HIGH 7.1
CVE-2016-5971

IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or …

Fix: after 2.0.2
Fix from $1,950 2016-09-26
Security Privileged Identity Manager Virtual Appliance MEDIUM 6.5
CVE-2016-5970

Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authentica…

Fix: after 2.0.2
Fix from $1,600 2016-09-26
Spectrum Control MEDIUM 6.5
CVE-2016-5946

Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticat…

Patch available
Fix from $1,600 2016-09-26
Connections MEDIUM 6.5
CVE-2016-2999

IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unsp…

Fix: after 5.5.0.0
Fix from $1,600 2016-09-26
Chrome MEDIUM 6.5
CVE-2016-5172

The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive informat…

Fix: after 53.0.2785.101
Fix from $1,600 2016-09-25
Iphone Os MEDIUM 5.5
CVE-2016-4771

The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathna…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Safari MEDIUM 6.5
CVE-2016-4758

WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, whic…

Fix: after 12.4.3
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4755

Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4752

The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensi…

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.3
CVE-2016-4745

The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes …

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.5
CVE-2016-4742

NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Mac Os X MEDIUM 5.3
CVE-2016-4713

CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access.

Fix: after 10.11.6
Fix from $1,600 2016-09-25
Iphone Os HIGH 7.5
CVE-2016-4711

CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a …

Fix: after 10.11.6
Fix from $1,950 2016-09-25
Iphone Os MEDIUM 6.5
CVE-2016-4708

CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attack…

Fix: 3.0 / 10.0+
Fix from $1,600 2016-09-25
Firefox MEDIUM 6.5
CVE-2016-5282

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa…

Fix: after 48.0.2
Fix from $1,600 2016-09-22
Fortiwan MEDIUM 6.5
CVE-2016-4968

The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administra…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Fortiwan MEDIUM 6.5
CVE-2016-4967

Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the devic…

Fix: after 4.2.4
Fix from $1,600 2016-09-21
Avamar Server HIGH 8.6
CVE-2016-0904

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers…

Fix: after 7.3.0
Fix from $1,950 2016-09-21
Avamar Server CRITICAL 9.1
CVE-2016-0903

Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remot…

Fix: after 7.3.0
Fix from $2,300 2016-09-21
Eh6108h\+ Firmware HIGH 7.5
CVE-2016-6537

AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTT…

Mitigation only
Fix from $1,950 2016-09-19
iOS HIGH 7.5
CVE-2016-6415 KEVEPSS 87%

The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and…

Fix: 5.3.0+
Fix from $1,950 2016-09-19
Tracer Sc MEDIUM 5.3
CVE-2016-0870

The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.

Fix: after 4.2.1134
Fix from $1,600 2016-09-19
Iphone Os MEDIUM 5.3
CVE-2016-4746

The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain se…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Watchos MEDIUM 5.5
CVE-2016-4719

The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attack…

Fix: after 9.3.5
Fix from $1,600 2016-09-18
Rabbitmq HIGH 7.5
CVE-2016-0929

The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might al…

Mitigation only
Fix from $1,950 2016-09-18
Documentum D2 MEDIUM 5.3
CVE-2016-6644

EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of …

Fix: after 4.6
Fix from $1,600 2016-09-17
Crypto\+\+ MEDIUM 5.9
CVE-2016-7420

Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are…

Fix: after 5.6.4
Fix from $1,600 2016-09-16
Air Sdk \& Compiler HIGH 7.5
CVE-2016-6936

Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attacke…

Mitigation only
Fix from $1,950 2016-09-16