Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Ewon Firmware CRITICAL 9.9
CVE-2015-7926

eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests, which allows remote attackers to obtain sensitive …

Fix: after 10.0s0
Fix from $2,300 2015-12-23
Moscad Ip Gateway Firmware HIGH 7.5
CVE-2015-7935

Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors.

Mitigation only
Fix from $1,950 2015-12-23
Proview MEDIUM 5.3
CVE-2015-6471

Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields…

Mitigation only
Fix from $1,600 2015-12-23
Midas Firmware HIGH 9.3
CVE-2015-7908

Honeywell Midas gas detectors before 1.13b3 and Midas Black gas detectors before 2.13b3 allow remote attackers to discover cleartext passwords by sni…

Fix: after 2.13b1
Fix from $1,950 2015-12-21
Dpq3925 8x4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter MEDIUM 5.0
CVE-2015-6428

Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.

Mitigation only
Fix from $1,600 2015-12-18
Chat Room MEDIUM 5.0
CVE-2015-8601

The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allow…

Patch available
Fix from $1,600 2015-12-17
Fedora MEDIUM 5.0
CVE-2015-7215

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Pol…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7214EPSS 6%

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7208

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by readi…

Fix: after 42.0
Fix from $1,600 2015-12-16
Firefox MEDIUM 5.0
CVE-2015-7207

Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass …

Fix: after 42.0
Fix from $1,600 2015-12-16
Secure Firewall Management Center MEDIUM 5.0
CVE-2015-6411

Cisco FirePOWER Management Center 5.4.1.3, 6.0.0, and 6.0.1 provides verbose responses to requests for help files, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2015-12-15
Firesight System Software MEDIUM 6.8
CVE-2015-6419

Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via …

Mitigation only
Fix from $1,600 2015-12-12
Xcode MEDIUM 5.0
CVE-2015-7056

IDE SCM in Apple Xcode before 7.2 does not recognize .gitignore files, which allows remote attackers to obtain sensitive information in opportunistic…

Fix: after 7.1.1
Fix from $1,600 2015-12-11
Jscript MEDIUM 5.0
CVE-2015-6135EPSS 23%

The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remot…

Mitigation only
Fix from $1,600 2015-12-09
Android MEDIUM 5.0
CVE-2015-6632

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6631

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6629

Wi-Fi in Android 5.x before 5.1.1 LMY48Z allows attackers to obtain sensitive information via unspecified vectors, as demonstrated by obtaining Signa…

Fix: after 5.1
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6628

Media Framework in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and consequently bypass an…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6626

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows remote attackers to obtain sensitive information, and consequently byp…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Android MEDIUM 5.0
CVE-2015-6622

The Native Frameworks Library in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to obtain sensitive information, and conseque…

Fix: 5.1.1+
Fix from $1,600 2015-12-08
Django MEDIUM 5.0
CVE-2015-8213

The get_format function in utils/formats.py in Django before 1.7.x before 1.7.11, 1.8.x before 1.8.7, and 1.9.x before 1.9rc2 might allow remote atta…

Fix: after 1.7.10
Fix from $1,600 2015-12-07
Proxysg Firmware MEDIUM 5.0
CVE-2015-4334

The default configuration of SGOS in Blue Coat ProxySG before 6.2.16.5, 6.5 before 6.5.7.1, and 6.6 before 6.6.2.1 forwards authentication challenges…

Fix: after 6.6.2.0
Fix from $1,600 2015-12-07
Libreport MEDIUM 5.0
CVE-2015-5302

libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive info…

Patch available
Fix from $1,600 2015-12-07
HTTP Server MEDIUM 5.3
CVE-2015-3195EPSS 39%

The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before …

Fix: 0.9.8zh / 1.0.0t+
Fix from $1,600 2015-12-06
Leap HIGH 7.5
CVE-2015-8076

The index_urlfetch function in index.c in Cyrus IMAP 2.3.x before 2.3.19, 2.4.x before 2.4.18, 2.5.x before 2.5.4 allows remote attackers to obtain s…

Mitigation only
Fix from $1,950 2015-12-03
Fedora HIGH 7.5
CVE-2015-8393

pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a craf…

Fix: 5.5.32 / 5.6.18+
Fix from $1,950 2015-12-02
Openshift MEDIUM 5.0
CVE-2015-5321

The sidepanel widgets in the CLI command overview and help pages in Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sens…

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 5.0
CVE-2015-5320

Jenkins before 1.638 and LTS before 1.625.2 do not properly verify the shared secret used in JNLP slave connections, which allows remote attackers to…

Fix: after 3.1
Fix from $1,600 2015-11-25
Jenkins HIGH 7.5
CVE-2015-5317 KEVEPSS 22%

The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information…

Fix: after 3.1
Fix from $1,950 2015-11-25
Ubuntu Linux MEDIUM 5.0
CVE-2015-7981EPSS 6%

The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to o…

Patch available
Fix from $1,600 2015-11-24