Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Jboss Wildfly Application Server HIGH 7.5
CVE-2016-0793EPSS 16%

Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on …

No fix yet
Fix from $1,950 2016-04-01
Mac Os X Server MEDIUM 5.3
CVE-2016-1787

Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Safari MEDIUM 5.4
CVE-2016-1786

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1785

The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, w…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Safari MEDIUM 6.5
CVE-2016-1779

WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Open Edx MEDIUM 6.5
CVE-2015-2286

lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allow…

Fix: after 2015-01-27
Fix from $1,600 2016-03-19
System Management Homepage MEDIUM 6.5
CVE-2016-1994

HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors.

Fix: after 7.5.3.1
Fix from $1,600 2016-03-18
Enterprise Security Manager MEDIUM 6.5
CVE-2016-1992

HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecifie…

Fix: after 6.9.0
Fix from $1,600 2016-03-17
Firefox MEDIUM 6.5
CVE-2016-1967

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 44.0.2
Fix from $1,600 2016-03-13
Android MEDIUM 5.5
CVE-2016-0831

The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 201…

Mitigation only
Fix from $1,600 2016-03-12
Android HIGH 7.5
CVE-2016-0829

The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 …

Mitigation only
Fix from $1,950 2016-03-12
Android HIGH 7.5
CVE-2016-0828

The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x bef…

Mitigation only
Fix from $1,950 2016-03-12
Android MEDIUM 5.3
CVE-2016-0825

The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leve…

Mitigation only
Fix from $1,600 2016-03-12
Android MEDIUM 5.3
CVE-2016-0824

libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified …

Mitigation only
Fix from $1,600 2016-03-12
Prime Lan Management Solution HIGH 7.1
CVE-2016-1360

Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows…

Mitigation only
Fix from $1,950 2016-03-12
Telvent Rtu Firmware MEDIUM 5.3
CVE-2015-6485

Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3…

Mitigation only
Fix from $1,600 2016-03-12
Dpc3939 Wireless Residential Voice Gateway Firmware HIGH 7.5
CVE-2016-1325

The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request…

Mitigation only
Fix from $1,950 2016-03-09
Chrome MEDIUM 5.3
CVE-2016-2845

The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in th…

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
Chrome MEDIUM 6.5
CVE-2016-1637

The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calcul…

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
Futuresmart Firmware MEDIUM 5.9
CVE-2016-2244

HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information vi…

Fix: after 3.7
Fix from $1,600 2016-03-04
Cisco Policy Suite MEDIUM 5.3
CVE-2016-1357

The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote…

Mitigation only
Fix from $1,600 2016-03-03
OpenSSL MEDIUM 5.9
CVE-2016-0800EPSS 82%

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…

Mitigation only
Fix from $1,600 2016-03-01
Secure Firewall Management Center MEDIUM 5.3
CVE-2016-1342

The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2016-02-26
Moodle HIGH 7.5
CVE-2015-5267

lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to imp…

Fix: after 2.6.11
Fix from $1,950 2016-02-22
Fedora MEDIUM 5.3
CVE-2016-2044

libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a cr…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2042

phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) librarie…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2039

libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token v…

Patch available
Fix from $1,600 2016-02-20
Fedora MEDIUM 5.3
CVE-2016-2038

phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafte…

Patch available
Fix from $1,600 2016-02-20
Hirschmann Firmware MEDIUM 5.3
CVE-2016-2509

The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP co…

Fix: after 09.0.05
Fix from $1,600 2016-02-18
Encryption Management Server HIGH 7.5
CVE-2015-8148

The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about admi…

Fix: after 3.3.2
Fix from $1,950 2016-02-18