Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Chrome MEDIUM 5.0
CVE-2015-6759

The shouldTreatAsUniqueOrigin function in platform/weborigin/SecurityOrigin.cpp in Blink, as used in Google Chrome before 46.0.2490.71, does not ensu…

Fix: after 45.0.2454.101
Fix from $1,600 2015-10-15
Flash Player MEDIUM 5.0
CVE-2015-7628

Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Ad…

Fix: after 19.0.0.190
Fix from $1,600 2015-10-15
Acrobat MEDIUM 5.0
CVE-2015-7624

Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…

Fix: 15.006.30094 / 15.009.20069+
Fix from $1,600 2015-10-14
Acrobat MEDIUM 5.0
CVE-2015-6706

Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…

Fix: 15.006.30094 / 15.009.20069+
Fix from $1,600 2015-10-14
Acrobat MEDIUM 5.0
CVE-2015-6705

Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Ac…

Fix: 15.006.30094 / 15.009.20069+
Fix from $1,600 2015-10-14
Edge MEDIUM 5.0
CVE-2015-6057EPSS 16%

Microsoft Edge allows remote attackers to obtain sensitive information from process memory via a crafted web site, aka "Microsoft Edge Information Di…

Mitigation only
Fix from $1,600 2015-10-14
Prime Collaboration Assurance MEDIUM 6.8
CVE-2015-6328

The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and r…

Mitigation only
Fix from $1,600 2015-10-13
Mac Os X MEDIUM 5.0
CVE-2015-7761

Mail in Apple OS X before 10.11 does not properly recognize user preferences, which allows attackers to obtain sensitive information via an unspecifi…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Cx Programmer CRITICAL 10.0
CVE-2015-0987

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which al…

Fix: after 9.5
Fix from $2,300 2015-10-06
Pulse Connect Secure MEDIUM 5.0
CVE-2015-7322

The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 befo…

No fix yet
Fix from $1,600 2015-10-05
Danfoss Tlx Pro\+ MEDIUM 5.0
CVE-2015-6474

IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.

Mitigation only
Fix from $1,600 2015-09-26
Danfoss Tlx Pro\+ MEDIUM 5.0
CVE-2015-6469

The interpreter in IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allows remote attackers to discover script source code via unspecified vectors.

Mitigation only
Fix from $1,600 2015-09-26
Firefox MEDIUM 5.0
CVE-2015-4503

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open…

Fix: after 40.0.3
Fix from $1,600 2015-09-24
Data Integration MEDIUM 5.0
CVE-2015-6940

The GetResource servlet in Pentaho Business Analytics (BA) Suite 4.5.x, 4.8.x, and 5.0.x through 5.2.x and Pentaho Data Integration (PDI) Suite 4.3.x…

Patch available
Fix from $1,600 2015-09-22
Air MEDIUM 5.0
CVE-2015-6679EPSS 5%

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…

Fix: after 18.0.0.199
Fix from $1,600 2015-09-22
Air MEDIUM 5.0
CVE-2015-5576EPSS 5%

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…

Fix: after 18.0.0.199
Fix from $1,600 2015-09-22
Air MEDIUM 5.0
CVE-2015-5572

Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Ad…

Fix: after 18.0.0.199
Fix from $1,600 2015-09-22
Scald MEDIUM 5.0
CVE-2015-7305

The Scald module 7.x-1.x before 7.x-1.5 for Drupal does not properly restrict access to fields, which allows remote attackers to obtain sensitive ato…

Patch available
Fix from $1,600 2015-09-21
Xcode MEDIUM 5.0
CVE-2015-5909

IDE Xcode Server in Apple Xcode before 7.0 does not properly restrict access to repository e-mail lists, which allows remote attackers to obtain pote…

Fix: after 6.4
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5906

The HTML form implementation in WebKit in Apple iOS before 9 does not prevent QuickType access to the final character of a password, which might make…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5885

The CFNetwork Cookies component in Apple iOS before 9 allows remote attackers to track users via vectors involving a cookie for a top-level domain.

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5860

The CFNetwork HTTPProtocol component in Apple iOS before 9 mishandles HSTS state, which allows remote attackers to bypass the Safari private-browsing…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Iphone Os MEDIUM 5.0
CVE-2015-5858

The CFNetwork HTTPProtocol component in Apple iOS before 9 allows remote attackers to bypass the HSTS protection mechanism, and consequently obtain s…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Mac Os X MEDIUM 5.0
CVE-2015-5831

NetworkExtension in the kernel in Apple iOS before 9 does not properly initialize an unspecified data structure, which allows attackers to obtain sen…

Fix: after 10.10.5
Fix from $1,600 2015-09-18
Safari MEDIUM 5.0
CVE-2015-5827

WebKit in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain an object reference via vectors involving a (1) cust…

Fix: after 8.4.1
Fix from $1,600 2015-09-18
Administration Views MEDIUM 5.0
CVE-2015-7226

The Administration Views module 7.x-1.x before 7.x-1.5 for Drupal checks access permissions based on the router path from the view instead of the dis…

Patch available
Fix from $1,600 2015-09-17
phpMyAdmin MEDIUM 5.0
CVE-2015-6830EPSS 10%

libraries/plugins/auth/AuthenticationCookie.class.php in phpMyAdmin 4.3.x before 4.3.13.2 and 4.4.x before 4.4.14.1 allows remote attackers to bypass…

Patch available
Fix from $1,600 2015-09-14
Exchange Server MEDIUM 5.0
CVE-2015-2505EPSS 18%

Outlook Web Access (OWA) in Microsoft Exchange Server 2013 Cumulative Update 8 and 9 and SP1 allows remote attackers to obtain sensitive stacktrace i…

Mitigation only
Fix from $1,600 2015-09-09
Telepresence System Software Ix MEDIUM 5.0
CVE-2015-6276

Cisco TelePresence IX5000 8.0.3 stores a private key associated with an X.509 certificate under the web root with insufficient access control, which …

Mitigation only
Fix from $1,600 2015-09-05
Ubuntu Linux MEDIUM 5.0
CVE-2015-6727

The Special:DeletedContributions page in MediaWiki before 1.23.10, 1.24.x before 1.24.3, and 1.25.x before 1.25.2 allows remote attackers to determin…

Fix: after 1.23.9
Fix from $1,600 2015-09-01