Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Siprotec Firmware MEDIUM 5.3
CVE-2016-4785

A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …

Mitigation only
Fix from $1,600 2016-05-31
Siprotec Firmware MEDIUM 5.3
CVE-2016-4784

A vulnerability has been identified in firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP …

Mitigation only
Fix from $1,600 2016-05-31
Bt 5 Series Cellular Router Firmware CRITICAL 9.8
CVE-2016-4521

Sixnet BT-5xxx and BT-6xxx M2M devices before 3.8.21 and 3.9.x before 3.9.8 have hardcoded credentials, which allows remote attackers to obtain acces…

Fix: after 3.9.7
Fix from $2,300 2016-05-31
Miineport E2 1242 Firmware HIGH 7.5
CVE-2016-2295

Moxa MiiNePort_E1_4641 devices with firmware 1.1.10 Build 09120714, MiiNePort_E1_7080 devices with firmware 1.1.10 Build 09120714, MiiNePort_E2_1242 …

Mitigation only
Fix from $1,950 2016-05-31
Alertwerks Servsensor Junior Firmware MEDIUM 6.5
CVE-2016-2311

Black Box AlertWerks ServSensor with firmware before SP473, AlertWerks ServSensor Junior with firmware before SP473, AlertWerks ServSensor Junior wit…

Mitigation only
Fix from $1,600 2016-05-30
Service Manager HIGH 7.5
CVE-2016-2025

HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vector…

Patch available
Fix from $1,950 2016-05-30
Restful Interface Tool MEDIUM 5.5
CVE-2016-2023

HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors.

Patch available
Fix from $1,600 2016-05-30
Ucs Invicta C3124sa Appliance HIGH 7.5
CVE-2016-1404

Cisco UCS Invicta 4.3, 4.5, and 5.0.1 on Invicta appliances and Invicta Scaling System uses the same hardcoded GnuPG encryption key across different …

Mitigation only
Fix from $1,950 2016-05-29
Webex Meeting Center HIGH 7.5
CVE-2016-1410

Cisco WebEx Meeting Center Original Release Base allows remote attackers to obtain sensitive information about username validity by (1) attending or …

Mitigation only
Fix from $1,950 2016-05-28
Mobile Security HIGH 7.4
CVE-2016-3664

Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in…

Fix: after 3.1
Fix from $1,950 2016-05-23
Ubuntu Linux HIGH 7.8
CVE-2016-4913

The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 cha…

Fix: 3.2.81 / 3.10.102+
Fix from $1,950 2016-05-23
Linux Kernel HIGH 7.5
CVE-2016-4580

The x25_negotiate_facilities function in net/x25/x25_facilities.c in the Linux kernel before 4.5.5 does not properly initialize a certain data struct…

Fix: after 4.5.4
Fix from $1,950 2016-05-23
Linux Kernel MEDIUM 5.5
CVE-2016-4578

sound/core/timer.c in the Linux kernel through 4.6 does not initialize certain r1 data structures, which allows local users to obtain sensitive infor…

Fix: after 4.6
Fix from $1,600 2016-05-23
Linux Kernel MEDIUM 5.5
CVE-2016-4569

The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows l…

Fix: after 4.6
Fix from $1,600 2016-05-23
Ubuntu Linux HIGH 7.5
CVE-2016-4485

The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers t…

Fix: after 4.5.4
Fix from $1,950 2016-05-23
Ubuntu Linux MEDIUM 6.2
CVE-2016-4482

The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows …

Fix: after 4.6
Fix from $1,600 2016-05-23
Safemode HIGH 8.1
CVE-2016-3693

The Safemode gem before 1.2.4 for Ruby, when initialized with a delegate object that is a Rails controller, allows context-dependent attackers to obt…

Fix: after 1.2.3
Fix from $1,950 2016-05-20
Safari MEDIUM 6.5
CVE-2016-1858

WebKit, as used in Apple iOS before 9.3.2, Safari before 9.1.1, and tvOS before 9.2.1, improperly tracks taint attributes, which allows remote attack…

Fix: 2.12.0 / 9.1.1+
Fix from $1,600 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1853

Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support.

Fix: after 10.11.4
Fix from $1,950 2016-05-20
Iphone Os MEDIUM 5.5
CVE-2016-1802

CCCrypt in CommonCrypto in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 mishandles return values during k…

Fix: 2.2.1 / 9.2.1+
Fix from $1,600 2016-05-20
Mac Os X HIGH 7.5
CVE-2016-1801

The CFNetwork Proxies subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 mishandles URLs in http and https requests, whi…

Fix: 9.2.1 / 9.3.2+
Fix from $1,950 2016-05-20
Openshift MEDIUM 6.5
CVE-2016-3724

Jenkins before 2.3 and LTS before 1.651.2 allow remote authenticated users with extended read access to obtain sensitive password information by read…

Fix: after 1.651.1
Fix from $1,600 2016-05-17
Jboss Middleware HIGH 7.5
CVE-2016-3674EPSS 8%

Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) Stand…

Fix: 1.4.9+
Fix from $1,950 2016-05-17
Websphere Application Server MEDIUM 5.9
CVE-2016-0306

IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.41, 8.0 before 8.0.0.13, and 8.5 before 8.5.5.10, when FIPS 140-2 is enabled, misconfigures T…

Mitigation only
Fix from $1,600 2016-05-17
PHP MEDIUM 5.3
CVE-2015-3412

PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers …

Fix: after 5.4.39
Fix from $1,600 2016-05-16
B2b Advanced Communications HIGH 7.5
CVE-2016-0341

IBM Multi-Enterprise Integration Gateway 1.0 through 1.0.0.1 and B2B Advanced Communications 1.0.0.2 through 1.0.0.4 do not require HTTPS, which migh…

Mitigation only
Fix from $1,950 2016-05-15
Web\'log Basic 100 CRITICAL 9.8
CVE-2016-2298EPSS 24%

Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vecto…

Mitigation only
Fix from $2,300 2016-05-14
System Management Homepage HIGH 7.1
CVE-2016-2015

HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors.

Fix: after 7.5.4.3
Fix from $1,950 2016-05-14
Mac Os X HIGH 7.5
CVE-2016-1208

The server in Apple FileMaker before 14.0.4 on OS X allows remote attackers to read PHP source code via unspecified vectors.

Fix: after 14.0.3
Fix from $1,950 2016-05-14
Openafs MEDIUM 5.3
CVE-2016-4536

The client in OpenAFS before 1.6.17 does not properly initialize the (1) AFSStoreStatus, (2) AFSStoreVolumeStatus, (3) VldbListByAttributes, and (4) …

Fix: after 1.6.16
Fix from $1,600 2016-05-13