Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Bigfix Webreports MEDIUM 5.9
CVE-2016-0397

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows remote attackers to obtain sensitive information by snif…

Mitigation only
Fix from $1,600 2016-08-30
Bigfix MEDIUM 5.5
CVE-2016-0292

WebReports in IBM BigFix Platform (formerly Tivoli Endpoint Manager) 9.x before 9.5.2 allows local users to discover the cleartext system password by…

Mitigation only
Fix from $1,600 2016-08-30
Xp 9000 Command View HIGH 7.5
CVE-2016-4378

The (1) Device Manager, (2) Tiered Storage Manager, (3) Replication Manager, (4) Replication Monitor, and (5) Hitachi Automation Director (HAD) compo…

Fix: after 8.4.0
Fix from $1,950 2016-08-26
Safe Browser MEDIUM 5.9
CVE-2016-6231

Kaspersky Safe Browser iOS before 1.7.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensi…

Fix: after 1.6.0
Fix from $1,600 2016-08-25
Unified Communications Manager HIGH 7.5
CVE-2016-6364

The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restri…

Mitigation only
Fix from $1,950 2016-08-23
Webex Meetings Server HIGH 7.5
CVE-2016-1484

Cisco WebEx Meetings Server 2.6 allows remote attackers to bypass intended access restrictions and obtain sensitive application information via unspe…

Mitigation only
Fix from $1,950 2016-08-23
Connected Streaming Analytics MEDIUM 6.5
CVE-2016-1477

Cisco Connected Streaming Analytics 1.1.1 allows remote authenticated users to discover a notification service password by reading administrative pag…

Mitigation only
Fix from $1,600 2016-08-23
Foreman MEDIUM 5.3
CVE-2016-5390

Foreman before 1.11.4 and 1.12.x before 1.12.1 allow remote authenticated users with the view_hosts permission containing a filter to obtain sensitiv…

Fix: 1.11.4 / 1.12.1+
Fix from $1,600 2016-08-19
Foreman MEDIUM 5.3
CVE-2016-4995

Foreman before 1.11.4 and 1.12.x before 1.12.1 does not properly restrict access to preview provisioning templates, which allows remote authenticated…

Fix: 1.11.4 / 1.12.1+
Fix from $1,600 2016-08-19
Edge MEDIUM 5.3
CVE-2016-3329EPSS 14%

Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to determine the existence of files via a crafted webpage, aka "Internet Exp…

Mitigation only
Fix from $1,600 2016-08-09
Edge MEDIUM 5.3
CVE-2016-3327EPSS 14%

Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Brows…

Mitigation only
Fix from $1,600 2016-08-09
Edge MEDIUM 5.3
CVE-2016-3326EPSS 16%

Microsoft Internet Explorer 9 through 11 and Edge allow remote attackers to obtain sensitive information via a crafted web page, aka "Microsoft Brows…

Mitigation only
Fix from $1,600 2016-08-09
Onenote MEDIUM 5.5
CVE-2016-3315EPSS 30%

Microsoft OneNote 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to obtain sensitive information via a craf…

Mitigation only
Fix from $1,600 2016-08-09
Windows 10 CRITICAL 9.1
CVE-2016-3312EPSS 10%

ActiveSyncProvider in Microsoft Windows 10 Gold and 1511 allows attackers to discover credentials by leveraging failure of Universal Outlook to obtai…

Mitigation only
Fix from $2,300 2016-08-09
Experience Manager MEDIUM 5.3
CVE-2016-4253

The Backup functionality in Adobe Experience Manager 5.6.1, 6.0, 6.1, and 6.2 allows attackers to obtain sensitive information via unspecified vector…

Patch available
Fix from $1,600 2016-08-09
Experience Manager MEDIUM 5.3
CVE-2016-4169

Adobe Experience Manager 6.0, 6.1, and 6.2 allow attackers to obtain sensitive audit log event information via unspecified vectors.

Patch available
Fix from $1,600 2016-08-09
Tivoli Storage Flashcopy Manager For Sql Server MEDIUM 6.2
CVE-2016-3059

IBM Tivoli Storage Manager for Databases: Data Protection for Microsoft SQL Server (aka IBM Spectrum Protect for Databases) 6.3 before 6.3.1.7 and 6.…

Fix: after 6.4.1.8
Fix from $1,600 2016-08-08
Linux Kernel MEDIUM 5.5
CVE-2015-8944

The ioresources_init function in kernel/resource.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 6 and 7 (2013) devi…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Linux Kernel MEDIUM 5.5
CVE-2014-9900

The ethtool_get_wol function in net/core/ethtool.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devi…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9899

drivers/usb/host/ehci-msm2.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices omits certain minimum calculations before cop…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9898

arch/arm/mach-msm/qdsp6v2/ultrasound/usf.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9897

sound/soc/msm/qdsp6v2/msm-lsm-client.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not validate certain user-spac…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9896

drivers/char/adsprpc.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices does not properly validate parameters …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Linux Kernel MEDIUM 5.5
CVE-2014-9895

drivers/media/media-device.c in the Linux kernel before 3.11, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9894

drivers/misc/qseecom.c in the Qualcomm components in Android before 2016-08-05 on Nexus 7 (2013) devices does not ensure that certain name strings en…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2014-9893

drivers/video/msm/mdss/mdss_mdp_pp.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 devices does not properly determine the size …

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Linux Kernel MEDIUM 5.5
CVE-2014-9892

The snd_compr_tstamp function in sound/core/compress_offload.c in the Linux kernel through 4.7, as used in Android before 2016-08-05 on Nexus 5 and 7…

Fix: after 6.0.1
Fix from $1,600 2016-08-06
Android MEDIUM 5.5
CVE-2016-3852

The MediaTek Wi-Fi driver in Android before 2016-08-05 on Android One devices allows attackers to obtain sensitive information via a crafted applicat…

Fix: after 6.0.1
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3837

service/jni/com_android_server_wifi_WifiNative.cpp in Wi-Fi in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attac…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3836

The SurfaceFlinger service in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allows attackers to obtain sensitive informat…

Patch available
Fix from $1,600 2016-08-05