Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-3835

The secure-session feature in the mm-video-v4l2 venc component in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, an…

Patch available
Fix from $1,600 2016-08-05
Android MEDIUM 5.5
CVE-2016-3834

The camera APIs in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-08-01 allow attackers to bypass intended acc…

Patch available
Fix from $1,600 2016-08-05
Openshift MEDIUM 6.5
CVE-2016-5392

The API server in Kubernetes, as used in Red Hat OpenShift Enterprise 3.2, in a multi tenant environment allows remote authenticated users with knowl…

Mitigation only
Fix from $1,600 2016-08-05
Hana Sps09 MEDIUM 5.5
CVE-2016-6149

SAP HANA SPS09 1.00.091.00.14186593 allows local users to obtain sensitive information by leveraging the EXPORT statement to export files, aka SAP Se…

No fix yet
Fix from $1,600 2016-08-05
Hana Db MEDIUM 5.3
CVE-2016-6145

The SQL interface in SAP HANA DB 1.00.091.00.1418659308 provides different error messages for failed login attempts depending on whether the username…

No fix yet
Fix from $1,600 2016-08-05
Hana Db MEDIUM 5.5
CVE-2016-3640

The Extended Application Services (aka XS or XS Engine) in SAP HANA DB 1.00.091.00.1418659308 allows local users to obtain sensitive password informa…

Mitigation only
Fix from $1,600 2016-08-05
Linux MEDIUM 5.5
CVE-2016-5265

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Unive…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Firefox MEDIUM 6.5
CVE-2016-5260

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which mig…

Fix: after 47.0.1
Fix from $1,600 2016-08-05
Traffix Signaling Delivery Controller HIGH 7.5
CVE-2015-5738

The RSA-CRT implementation in the Cavium Software Development Kit (SDK) 2.x, when used on OCTEON II CN6xxx Hardware on Linux to support TLS with Perf…

Fix: after 4.4.0
Fix from $1,950 2016-07-26
Chrome HIGH 8.8
CVE-2016-5134

net/proxy/proxy_service.cc in the Proxy Auto-Config (PAC) feature in Google Chrome before 52.0.2743.82 does not ensure that URL information is restri…

Fix: after 51.0.2704.106
Fix from $1,950 2016-07-23
Simatic Wincc HIGH 7.5
CVE-2016-5744

Siemens SIMATIC WinCC 7.0 through SP3 and 7.2 allows remote attackers to read arbitrary WinCC station files via crafted packets.

Mitigation only
Fix from $1,950 2016-07-22
Mac Os X MEDIUM 5.5
CVE-2016-4648

Audio in Apple OS X before 10.11.6 allows local users to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bound…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Mac Os X MEDIUM 6.5
CVE-2016-4646

Audio in Apple OS X before 10.11.6 mishandles a size value, which allows remote attackers to obtain sensitive information or cause a denial of servic…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.3
CVE-2016-4635

FaceTime in Apple iOS before 9.3.3 and OS X before 10.11.6 allows man-in-the-middle attackers to spoof relayed-call termination, and obtain sensitive…

Fix: after 10.11.5
Fix from $1,600 2016-07-22
Iphone Os MEDIUM 5.5
CVE-2016-4628

IOAcceleratorFamily in Apple iOS before 9.3.3 and watchOS before 2.2.2 allows local users to obtain sensitive information from kernel memory or cause…

Fix: after 9.3.2
Fix from $1,600 2016-07-22
Maximo Asset Management MEDIUM 5.3
CVE-2016-0393

IBM Maximo Asset Management 7.5 before 7.5.0.10-TIV-MBS-IFIX002 and 7.6 before 7.6.0.5-TIV-MAMMT-FP001 allows remote attackers to obtain sensitive UR…

Mitigation only
Fix from $1,600 2016-07-17
Personal Communications MEDIUM 6.2
CVE-2016-0321

IBM Personal Communications (aka PCOMM) 6.x before 6.0.17 and 12.x before 12.0.0.1 does not properly restrict credential extraction, which allows loc…

Mitigation only
Fix from $1,600 2016-07-17
Rational Team Concert MEDIUM 6.5
CVE-2016-2865

The GIT Integration component in IBM Rational Team Concert (RTC) 5.x before 5.0.2 iFix14 and 6.x before 6.0.1 iFix5 and Rational Collaborative Lifecy…

Patch available
Fix from $1,600 2016-07-15
Security Identity Manager Adapter MEDIUM 6.2
CVE-2016-0338

IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.1 before 7.0.1-ISS-SIM-FP0003 allows local users to discover cleartext p…

Mitigation only
Fix from $1,600 2016-07-15
Tivoli Directory Server HIGH 7.5
CVE-2015-1977

Directory traversal vulnerability in the Web Administration tool in IBM Tivoli Directory Server (ITDS) before 6.1.0.74-ISS-ISDS-IF0074, 6.2.x before …

Mitigation only
Fix from $1,950 2016-07-15
Lighthouse Sms MEDIUM 5.3
CVE-2016-5797

Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username ex…

Fix: after 5.1
Fix from $1,600 2016-07-15
Asr 5000 MEDIUM 6.5
CVE-2016-1452

Cisco ASR 5000 devices with software 18.3 through 20.0.0 allow remote attackers to make configuration changes over SNMP by leveraging knowledge of th…

Mitigation only
Fix from $1,600 2016-07-15
Leap HIGH 8.4
CVE-2016-3100

kinit in KDE Frameworks before 5.23.0 uses weak permissions (644) for /tmp/xauth-xxx-_y, which allows local users to obtain X11 cookies of other user…

Fix: after 5.22.0
Fix from $1,950 2016-07-13
Edge MEDIUM 5.3
CVE-2016-3277EPSS 32%

Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsof…

Mitigation only
Fix from $1,600 2016-07-13
Edge MEDIUM 5.3
CVE-2016-3273EPSS 14%

The XSS Filter in Microsoft Internet Explorer 9 through 11 and Microsoft Edge does not properly restrict JavaScript code, which allows remote attacke…

Mitigation only
Fix from $1,600 2016-07-13
Edge MEDIUM 6.5
CVE-2016-3271EPSS 21%

The VBScript engine in Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Script…

Mitigation only
Fix from $1,600 2016-07-13
Windows 10 MEDIUM 5.0
CVE-2016-3256

Microsoft Windows 10 Gold and 1511 allows local users to bypass the Secure Kernel Mode protection mechanism and obtain sensitive information via a cr…

Mitigation only
Fix from $1,600 2016-07-13
.net Framework HIGH 7.5
CVE-2016-3255EPSS 25%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to read arbitrary files via XML data containing an extern…

Mitigation only
Fix from $1,950 2016-07-13
Openstack HIGH 7.5
CVE-2016-4985

The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive informati…

Fix: after 4.2.4
Fix from $1,950 2016-07-12
Android MEDIUM 5.5
CVE-2016-3816

The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted applic…

Fix: after 6.0.1
Fix from $1,600 2016-07-11