Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-3815

The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, …

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3814

The NVIDIA camera driver in Android before 2016-07-05 on Nexus 9 devices allows attackers to obtain sensitive information via a crafted application, …

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3813

The Qualcomm USB driver in Android before 2016-07-05 on Nexus 5, 5X, 6, and 6P devices allows attackers to obtain sensitive information via a crafted…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3812

The MediaTek video codec driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted ap…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3810

The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to obtain sensitive information via a crafted applicat…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android MEDIUM 5.5
CVE-2016-3809

The networking component in Android before 2016-07-05 on Android One, Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 7 (2013), Nexus 9, Nexus Player, an…

Fix: after 6.0.1
Fix from $1,600 2016-07-11
Android HIGH 7.7
CVE-2016-3765

decoder/impeg2d_bitstream.c in mediaserver in Android 6.x before 2016-07-01 allows attackers to obtain sensitive information from process memory or c…

Mitigation only
Fix from $1,950 2016-07-11
Android HIGH 7.5
CVE-2016-3753

mediaserver in Android 4.x before 4.4.4 allows remote attackers to obtain sensitive information via unspecified vectors, aka internal bug 27210135.

Mitigation only
Fix from $1,950 2016-07-11
I Access HIGH 7.8
CVE-2016-0287

IBM i Access 7.1 on Windows allows local users to discover registry passwords via unspecified vectors.

Mitigation only
Fix from $1,950 2016-07-08
Control Center MEDIUM 5.1
CVE-2016-0252

IBM Control Center 6.x before 6.0.0.1 iFix06 and Sterling Control Center 5.4.x before 5.4.2.1 iFix09 allow local users to decrypt the master key via …

Mitigation only
Fix from $1,600 2016-07-08
Websphere Application Server HIGH 7.5
CVE-2016-2923

IBM WebSphere Application Server (WAS) 8.5 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 does not include the HTTPOnly flag in a Set-Cooki…

Mitigation only
Fix from $1,950 2016-07-07
Websphere Application Server MEDIUM 5.3
CVE-2016-0389

Admin Center in IBM WebSphere Application Server (WAS) 8.5.5.2 through 8.5.5.9 Liberty before Liberty Fix Pack 16.0.0.2 allows remote attackers to ob…

Mitigation only
Fix from $1,600 2016-07-07
Opensuse MEDIUM 5.3
CVE-2016-5097

phpMyAdmin before 4.6.2 places tokens in query strings and does not arrange for them to be stripped before external navigation, which allows remote a…

Fix: after 4.6.1
Fix from $1,600 2016-07-05
Sicam Pas\/pqs MEDIUM 6.7
CVE-2016-5848

Siemens SICAM PAS before 8.07 does not properly restrict password data in the database, which makes it easier for local users to calculate passwords …

Fix: after 8.07
Fix from $1,600 2016-07-04
Rsa Archer Egrc MEDIUM 6.3
CVE-2016-0899

EMC RSA Archer GRC 5.5.x before 5.5.3.4 allows remote authenticated users to read the web.config.bak file, and obtain sensitive credential informatio…

Mitigation only
Fix from $1,600 2016-07-04
Epc3928 Firmware HIGH 8.1
CVE-2016-1337

Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requests during the early part of…

No fix yet
Fix from $1,950 2016-07-03
Leap HIGH 7.5
CVE-2016-5739

The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Co…

Patch available
Fix from $1,950 2016-07-03
phpMyAdmin MEDIUM 5.3
CVE-2016-5730

phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 allows remote attackers to obtain sensitive information via vectors …

Patch available
Fix from $1,600 2016-07-03
Nsx Edge MEDIUM 5.9
CVE-2016-2079

VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attacker…

Patch available
Fix from $1,600 2016-07-03
Node.js HIGH 7.5
CVE-2016-3956EPSS 7%

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, …

Fix: 2.15.1 / 3.8.3+
Fix from $1,950 2016-07-02
Integration Bus MEDIUM 5.3
CVE-2016-2961

The integration server in IBM Integration Bus 9 before 9.0.0.6 and 10 before 10.0.0.5 and WebSphere Message Broker 8 before 8.0.0.8 allows remote att…

Mitigation only
Fix from $1,600 2016-07-02
Urbancode Deploy MEDIUM 5.9
CVE-2016-0365

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1, when agent-relay Codestation artifact caching is enabled,…

Mitigation only
Fix from $1,600 2016-07-01
Endpoint Protection Manager MEDIUM 5.3
CVE-2016-5306

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for …

Fix: after 12.1.6
Fix from $1,600 2016-06-30
Endpoint Protection Manager HIGH 8.0
CVE-2016-3651

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover the PHP JSESSIONID value via unspecifie…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager HIGH 8.8
CVE-2016-3650

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to discover credentials via a brute-force attack.

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Endpoint Protection Manager HIGH 8.8
CVE-2016-3648

Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 allows remote authenticated users to bypass the Authentication Lock protection mechan…

Fix: after 12.1.6
Fix from $1,950 2016-06-30
Openstack HIGH 8.8
CVE-2016-4474

The image build process for the overcloud images in Red Hat OpenStack Platform 8.0 (Liberty) director and Red Hat Enterprise Linux OpenStack Platform…

Mitigation only
Fix from $1,950 2016-06-30
WordPress HIGH 7.5
CVE-2016-5835

WordPress before 4.5.3 allows remote attackers to obtain sensitive revision-history information by leveraging the ability to read a post, related to …

Fix: after 4.5.2
Fix from $1,950 2016-06-29
Security Guardium MEDIUM 6.5
CVE-2016-0298

Directory traversal vulnerability in IBM Security Guardium Database Activity Monitor 10 before 10.0p100 allows remote authenticated users to read arb…

Fix: after 10.0
Fix from $1,600 2016-06-29
Urbancode Deploy HIGH 7.7
CVE-2016-0267

IBM UrbanCode Deploy 6.0.x before 6.0.1.13, 6.1.x before 6.1.3.3, and 6.2.x before 6.2.1.1 allows remote authenticated users to obtain sensitive clea…

Mitigation only
Fix from $1,950 2016-06-29