Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Nova MEDIUM 5.9
CVE-2015-8749

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the conne…

Fix: 12.0.1 / 2015.1.3+
Fix from $1,600 2016-01-15
Ubuntu Linux MEDIUM 5.5
CVE-2016-1897EPSS 15%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the concat protocol in an HTTP Live Streaming (H…

No fix yet
Fix from $1,600 2016-01-15
Ubuntu Linux MEDIUM 5.5
CVE-2016-1898EPSS 13%

FFmpeg 2.x allows remote attackers to conduct cross-origin attacks and read arbitrary files by using the subfile protocol in an HTTP Live Streaming (…

No fix yet
Fix from $1,600 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0853

Advantech WebAccess before 8.1 allows remote attackers to obtain sensitive information via crafted input.

Fix: after 8.0
Fix from $1,950 2016-01-15
Web Viewer HIGH 7.5
CVE-2015-8280EPSS 6%

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to discover credentials by reading detailed error messages.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Webaccess MEDIUM 5.3
CVE-2015-3943

Advantech WebAccess before 8.1 allows remote attackers to read sensitive cleartext information about e-mail project accounts via unspecified vectors.

Fix: after 8.0
Fix from $1,600 2016-01-15
Linux MEDIUM 6.5
CVE-2016-0777EPSS 63%

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive infor…

Fix: after 15.07
Fix from $1,600 2016-01-14
Vcn500 MEDIUM 6.5
CVE-2015-8335

Huawei VCN500 with software before V100R002C00SPC201 logs passwords in cleartext, which allows remote authenticated users to obtain sensitive informa…

Mitigation only
Fix from $1,600 2016-01-11
Integration Bus MEDIUM 5.3
CVE-2015-7399

IBM WebSphere Message Broker 7 before 7.0.0.8 and 8 before 8.0.0.6 and IBM Integration Bus 9 before 9.0.0.3 and 10 before 10.0.0.0 allow remote attac…

Mitigation only
Fix from $1,600 2016-01-11
Owncloud HIGH 8.5
CVE-2016-1499

ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a dir…

Fix: after 8.0.9
Fix from $1,950 2016-01-08
Ucmdb Browser HIGH 8.4
CVE-2015-6862

HPE UCMDB Browser before 4.02 allows remote attackers to obtain sensitive information or bypass intended access restrictions via unspecified vectors.

Patch available
Fix from $1,950 2016-01-08
Sterling B2b Integrator MEDIUM 5.5
CVE-2015-7437

Queue Watcher in IBM Sterling B2B Integrator 5.2 allows local users to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,600 2016-01-02
Spectrum Protect For Virtual Environments HIGH 8.5
CVE-2015-7429

The Data Protection extension in the VMware GUI in IBM Tivoli Storage Manager for Virtual Environments: Data Protection for VMware (aka Spectrum Prot…

Mitigation only
Fix from $1,950 2016-01-02
Rational Clearquest MEDIUM 5.1
CVE-2015-4996

IBM Rational ClearQuest 7.1.x and 8.0.0.x before 8.0.0.17 and 8.0.1.x before 8.0.1.10 allows local users to spoof database servers and discover crede…

Mitigation only
Fix from $1,600 2016-01-02
Spectrum Scale MEDIUM 6.5
CVE-2015-7456

IBM Spectrum Scale 4.1.1 before 4.1.1.4, and 4.2.0.0, allows remote authenticated users to discover object-storage admin passwords via unspecified ve…

Mitigation only
Fix from $1,600 2016-01-01
Websphere Portal MEDIUM 5.3
CVE-2015-7447

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF20, and 8.5.0 before …

Mitigation only
Fix from $1,600 2015-12-31
Orientdb MEDIUM 5.9
CVE-2015-2913

server/network/protocol/http/OHttpSessionManager.java in the Studio component in OrientDB Server Community Edition before 2.0.15 and 2.1.x before 2.1…

Patch available
Fix from $1,600 2015-12-31
Uptime Infrastructure Monitor MEDIUM 5.3
CVE-2015-2896

The up.time client in Idera Uptime Infrastructure Monitor through 7.6 allows remote attackers to obtain potentially sensitive version, OS, process, a…

Fix: after 7.6
Fix from $1,600 2015-12-31
Zxhn H108n R1a Firmware MEDIUM 6.5
CVE-2015-8703

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE and ZXV10 W300 devices W300V1.0.0f_ER1_PE allow remote authenticated users to bypass inte…

Mitigation only
Fix from $1,600 2015-12-30
Zxhn H108n R1a Firmware HIGH 7.5
CVE-2015-7248EPSS 7%

ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password hashes by reading the cgi-bin/w…

No fix yet
Fix from $1,950 2015-12-30
Samba HIGH 7.5
CVE-2015-5330EPSS 6%

ldb before 1.1.24, as used in the AD LDAP server in Samba 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before 4.3.3, mishandles string lengths, w…

Mitigation only
Fix from $1,950 2015-12-29
Debian Linux MEDIUM 5.3
CVE-2015-5299EPSS 14%

The shadow_copy2_get_shadow_copy_data function in modules/vfs_shadow_copy2.c in Samba 3.x and 4.x before 4.1.22, 4.2.x before 4.2.7, and 4.3.x before…

Fix: 4.1.22 / 4.2.7+
Fix from $1,600 2015-12-29
Tails MEDIUM 5.3
CVE-2015-7665

Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which allows remote FTP servers to…

Fix: after 1.6
Fix from $1,600 2015-12-27
Frontel Protocol MEDIUM 5.9
CVE-2015-8252

The Frontel protocol before 3 on RSI Video Technologies Videofied devices sends a cleartext serial number, which allows remote attackers to determine…

Fix: after 2.0
Fix from $1,600 2015-12-27
phpMyAdmin MEDIUM 5.3
CVE-2015-8669

libraries/config/messages.inc.php in phpMyAdmin 4.0.x before 4.0.10.12, 4.4.x before 4.4.15.2, and 4.5.x before 4.5.3.1 allows remote attackers to ob…

Patch available
Fix from $1,600 2015-12-26
Jabber MEDIUM 5.9
CVE-2015-6409

Cisco Jabber 10.6.x, 11.0.x, and 11.1.x on Windows allows man-in-the-middle attackers to conduct STARTTLS downgrade attacks and trigger cleartext XMP…

Mitigation only
Fix from $1,600 2015-12-26
A840 Telemetry Gateway Base Station Firmware HIGH 8.6
CVE-2015-7934

The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to discover log-file pathnames via unspecified vectors.

Mitigation only
Fix from $1,950 2015-12-24
A840 Telemetry Gateway Base Station Firmware HIGH 8.6
CVE-2015-7932

Adcon Telemetry A840 Telemetry Gateway Base Station allows remote attackers to obtain sensitive information by sniffing the network.

No fix yet
Fix from $1,950 2015-12-24
A840 Telemetry Gateway Base Station Firmware HIGH 8.7
CVE-2015-7931

The Java client in Adcon Telemetry A840 Telemetry Gateway Base Station does not authenticate the station device, which allows man-in-the-middle attac…

Mitigation only
Fix from $1,950 2015-12-24
Ewon Firmware HIGH 8.5
CVE-2015-7928

eWON devices with firmware before 10.1s0 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers t…

Fix: after 10.0s0
Fix from $1,950 2015-12-23