Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Android MEDIUM 5.5
CVE-2016-2415

exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.…

Mitigation only
Fix from $1,600 2016-04-18
Openstack HIGH 7.5
CVE-2015-5271

The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)…

Patch available
Fix from $1,950 2016-04-15
iOS MEDIUM 5.3
CVE-2016-1378

Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to…

Mitigation only
Fix from $1,600 2016-04-14
Fedora MEDIUM 5.9
CVE-2016-0787

The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in…

Fix: after 1.6.0
Fix from $1,600 2016-04-13
Enterprise Linux MEDIUM 5.9
CVE-2016-0739

libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange me…

Fix: after 0.7.2
Fix from $1,600 2016-04-13
Big Ip Edge Gateway MEDIUM 5.9
CVE-2016-3686

The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers t…

Mitigation only
Fix from $1,600 2016-04-13
Big Iq Security HIGH 7.4
CVE-2016-2084

F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2…

Mitigation only
Fix from $1,950 2016-04-13
Debian Linux HIGH 7.5
CVE-2016-2055EPSS 18%

xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration director…

Patch available
Fix from $1,950 2016-04-13
Xenserver HIGH 8.6
CVE-2015-8555

Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended…

Patch available
Fix from $1,950 2016-04-13
Enterprise Linux MEDIUM 6.5
CVE-2015-8553

Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi…

Patch available
Fix from $1,600 2016-04-13
Robohelp HIGH 7.5
CVE-2016-1035

Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors.

Mitigation only
Fix from $1,950 2016-04-12
Bsafe Crypto C Micro Edition MEDIUM 5.9
CVE-2016-0887

EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE…

Fix: 2.8.9 / 4.1.5+
Fix from $1,600 2016-04-12
Windows 10 HIGH 7.1
CVE-2016-0090

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory vi…

Mitigation only
Fix from $1,950 2016-04-12
Windows 10 HIGH 7.1
CVE-2016-0089

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS …

Mitigation only
Fix from $1,950 2016-04-12
Debian Linux MEDIUM 5.3
CVE-2016-3170

The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensi…

Patch available
Fix from $1,600 2016-04-12
Qpid Proton MEDIUM 6.5
CVE-2016-2166

The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i…

Fix: after 0.12.0
Fix from $1,600 2016-04-12
Nova MEDIUM 5.3
CVE-2016-2140

The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images i…

Fix: 12.0.3 / 2015.1.4+
Fix from $1,600 2016-04-12
Debian Linux MEDIUM 5.3
CVE-2015-8537

app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive info…

Fix: after 2.6.8
Fix from $1,600 2016-04-12
Kubernetes MEDIUM 5.3
CVE-2015-7528

Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.

Fix: after 1.2.0
Fix from $1,600 2016-04-11
Cloudforms Management Engine MEDIUM 5.1
CVE-2015-7502

Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P…

Mitigation only
Fix from $1,600 2016-04-11
Mantisbt MEDIUM 5.3
CVE-2014-9759

Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obta…

Patch available
Fix from $1,600 2016-04-11
Openmeetings HIGH 7.5
CVE-2016-2164EPSS 7%

The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the…

Fix: after 3.1.0
Fix from $1,950 2016-04-11
Openmeetings HIGH 7.5
CVE-2016-0783EPSS 7%

The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke…

Fix: after 3.1.0
Fix from $1,950 2016-04-11
Leap MEDIUM 6.2
CVE-2015-5969

The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 4…

Mitigation only
Fix from $1,600 2016-04-08
Openshift CRITICAL 9.8
CVE-2016-0791

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to…

Fix: after 1.649
Fix from $2,300 2016-04-07
Jenkins MEDIUM 5.3
CVE-2016-0790

Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to …

Fix: after 1.649
Fix from $1,600 2016-04-07
Erlang\/otp MEDIUM 5.9
CVE-2015-2774

Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attack…

Fix: after 18.0
Fix from $1,600 2016-04-07
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-3973

The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain…

Fix: after 7.50
Fix from $1,600 2016-04-07
Clustered Data Ontap MEDIUM 6.8
CVE-2016-1563

NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser…

Mitigation only
Fix from $1,600 2016-04-07
Eg2 Web Control HIGH 7.5
CVE-2016-0871

Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a…

Fix: after 4.04p
Fix from $1,950 2016-04-06