Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Netweaver Application Server Java MEDIUM 5.3
CVE-2016-2388 KEVEPSS 52%

The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req…

Fix: after 7.50
Fix from $1,600 2016-02-16
Universal Small Cell Firmware MEDIUM 5.8
CVE-2016-1321

Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to…

Mitigation only
Fix from $1,600 2016-02-15
Websphere Commerce MEDIUM 5.3
CVE-2015-7444

The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to…

Patch available
Fix from $1,600 2016-02-15
OpenSSL MEDIUM 5.9
CVE-2015-3197EPSS 11%

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…

Patch available
Fix from $1,600 2016-02-15
Qradar Security Information And Event Manager MEDIUM 5.3
CVE-2015-2005

IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attacker…

Mitigation only
Fix from $1,600 2016-02-15
Debian Linux HIGH 8.1
CVE-2016-1526

The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before…

Fix: after 38.5.1
Fix from $1,950 2016-02-13
Smartgrid Lighthouse Sensor Management System MEDIUM 5.3
CVE-2016-0864

Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitiv…

Fix: after 5.0
Fix from $1,600 2016-02-13
Experience Manager HIGH 7.5
CVE-2016-0958

Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object.

Patch available
Fix from $1,950 2016-02-10
Sling HIGH 7.5
CVE-2016-0956EPSS 46%

The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen…

Patch available
Fix from $1,950 2016-02-10
Moveit Dmz MEDIUM 5.3
CVE-2015-7680

Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allo…

Fix: after 8.1
Fix from $1,600 2016-02-10
Moveit Dmz MEDIUM 6.5
CVE-2015-7675

The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authoriz…

Fix: after 8.1
Fix from $1,600 2016-02-10
.net Framework HIGH 7.5
CVE-2016-0047EPSS 21%

WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process …

Mitigation only
Fix from $1,950 2016-02-10
Opensolaris MEDIUM 5.3
CVE-2016-1319

Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communication…

Fix: 2.50+
Fix from $1,600 2016-02-09
Telepresence Video Communication Server Software MEDIUM 5.3
CVE-2016-1316

Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se…

Mitigation only
Fix from $1,600 2016-02-09
Linux Kernel MEDIUM 6.8
CVE-2016-0723

Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information…

Fix: after 4.4.1
Fix from $1,600 2016-02-08
Android HIGH 7.5
CVE-2016-0811

Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows …

Mitigation only
Fix from $1,950 2016-02-07
Moduweb Vision CRITICAL 9.8
CVE-2015-7915

Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffin…

Fix: after 1.5.5
Fix from $2,300 2016-02-06
Snmp\/web Adapter Firmware MEDIUM 6.5
CVE-2016-0862EPSS 10%

General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive…

Fix: after 4.7
Fix from $1,600 2016-02-05
Iphone Os MEDIUM 5.4
CVE-2016-1730

WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal.

Fix: after 9.2
Fix from $1,600 2016-02-01
Firefox MEDIUM 5.3
CVE-2016-1939

Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati…

Fix: after 43.0.4
Fix from $1,600 2016-01-31
Plantvisor Enhanced HIGH 7.5
CVE-2016-0867

CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request.

Mitigation only
Fix from $1,950 2016-01-30
Libmatroska MEDIUM 5.3
CVE-2015-8792

The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process h…

Fix: after 1.4.3
Fix from $1,600 2016-01-29
Go HIGH 7.5
CVE-2015-8618

The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes …

Patch available
Fix from $1,950 2016-01-27
Spectrum Scale MEDIUM 5.9
CVE-2015-7488

IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover…

Mitigation only
Fix from $1,600 2016-01-27
Shareit HIGH 8.0
CVE-2016-1489

Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) ob…

Fix: after 3.0.18_ww
Fix from $1,950 2016-01-26
Chrome MEDIUM 6.5
CVE-2016-1618

Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi…

Fix: after 47.0.2526.106
Fix from $1,600 2016-01-25
Security Network Protection Firmware MEDIUM 5.9
CVE-2016-0201

GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collisio…

Patch available
Fix from $1,600 2016-01-18
Jazz Reporting Service HIGH 7.5
CVE-2015-7470

Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-…

Patch available
Fix from $1,950 2016-01-17
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2016-1295

Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt…

Mitigation only
Fix from $1,600 2016-01-16
Netweaver MEDIUM 5.3
CVE-2016-1910EPSS 6%

The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290.

No fix yet
Fix from $1,600 2016-01-15