Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Telemetry Web Server HIGH 7.8
CVE-2015-7910

Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass inte…

Mitigation only
Fix from $1,950 2015-11-19
Firepower Extensible Operating System MEDIUM 5.0
CVE-2015-6368

Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, ak…

Mitigation only
Fix from $1,600 2015-11-19
Netscaler Service Delivery Appliance Service Vm MEDIUM 5.0
CVE-2015-7998

The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.1…

Patch available
Fix from $1,600 2015-11-17
Netscaler Application Delivery Controller Firmware MEDIUM 5.0
CVE-2015-7996

The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 1…

Patch available
Fix from $1,600 2015-11-17
Gcc MEDIUM 5.0
CVE-2015-5276

The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking so…

Fix: 4.9.4+
Fix from $1,600 2015-11-17
Datapower Gateway MEDIUM 5.0
CVE-2015-7427

IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x b…

Fix: after 6.0.0.16
Fix from $1,600 2015-11-14
Videoscape Distribution Suite Service Manager MEDIUM 5.0
CVE-2015-6364

Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor…

Fix: after 3.2.0
Fix from $1,600 2015-11-14
Hana MEDIUM 5.0
CVE-2015-7991

The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files an…

No fix yet
Fix from $1,600 2015-11-10
Mediawiki MEDIUM 5.0
CVE-2015-8005

MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote at…

Fix: after 1.23.10
Fix from $1,600 2015-11-09
Monster Menus MEDIUM 5.0
CVE-2015-8095

The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote…

Patch available
Fix from $1,600 2015-11-09
Leap MEDIUM 5.0
CVE-2015-7940

The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obt…

Fix: after 1.50
Fix from $1,600 2015-11-09
WordPress MEDIUM 5.0
CVE-2015-5730EPSS 7%

The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison…

Fix: after 4.2.3
Fix from $1,600 2015-11-09
Websphere Commerce Enterprise MEDIUM 5.0
CVE-2015-5015

IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST UR…

Fix: after 7.0.0.9
Fix from $1,600 2015-11-08
Security Qradar Incident Forensics MEDIUM 5.0
CVE-2015-1999

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive…

Mitigation only
Fix from $1,600 2015-11-08
Security Qradar Incident Forensics MEDIUM 5.0
CVE-2015-1994

IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, w…

Mitigation only
Fix from $1,600 2015-11-08
Field As Block MEDIUM 5.0
CVE-2015-8081

The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might allow remote attackers to obtain sensitive field information by reading a cached bl…

Patch available
Fix from $1,600 2015-11-06
Openafs MEDIUM 5.0
CVE-2015-7763

rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx ackno…

Mitigation only
Fix from $1,600 2015-11-06
Debian Linux MEDIUM 5.0
CVE-2015-7762

rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowl…

Fix: after 1.6.14.1
Fix from $1,600 2015-11-06
Firefox MEDIUM 5.0
CVE-2015-7195

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which al…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Firefox MEDIUM 5.0
CVE-2015-7190

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access thi…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Unified Computing System MEDIUM 5.0
CVE-2015-6355

The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i…

Mitigation only
Fix from $1,600 2015-11-04
Android MEDIUM 5.0
CVE-2015-8074

mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection…

Fix: after 5.1
Fix from $1,600 2015-11-03
Android MEDIUM 5.0
CVE-2015-6611

mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass…

Fix: 5.1.1+
Fix from $1,600 2015-11-03
Joomla\! MEDIUM 5.0
CVE-2015-7859

The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,600 2015-10-29
Mango Automation MEDIUM 5.0
CVE-2015-7902

Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecifie…

Patch available
Fix from $1,600 2015-10-28
Spotfire Server MEDIUM 5.0
CVE-2015-5713

Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x …

Fix: after 7.0.1
Fix from $1,600 2015-10-28
Umg 508 MEDIUM 5.0
CVE-2015-3969

Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to UDP port (…

Patch available
Fix from $1,600 2015-10-28
Swift MEDIUM 5.0
CVE-2015-5223

OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that refer…

Fix: after 2.3.0
Fix from $1,600 2015-10-26
PostgreSQL MEDIUM 6.4
CVE-2015-5288

The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9…

Fix: after 9.0.22
Fix from $1,600 2015-10-26
Sourceone Email Supervisor MEDIUM 5.0
CVE-2015-6843

Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to…

Fix: after 7.1
Fix from $1,600 2015-10-18