Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Mediawiki MEDIUM 5.0
CVE-2013-7444

The Special:Contributions page in MediaWiki before 1.22.0 allows remote attackers to determine if an IP is autoblocked via the "Change block" text.

Fix: after 1.22.0
Fix from $1,600 2015-09-01
Banking MEDIUM 5.0
CVE-2015-6747

Basware Banking (Maksuliikenne) 8.90.07.X does not properly prevent access to private keys, which allows remote attackers to spoof communications wit…

Fix: after 8.90.07
Fix from $1,600 2015-08-31
Banking MEDIUM 5.8
CVE-2015-0943

Basware Banking (Maksuliikenne) before 9.10.0.0 does not encrypt communication between the client and the backend server, which allows man-in-the-mid…

Fix: after 8.90.07
Fix from $1,600 2015-08-31
Matrix Operating Environment MEDIUM 5.0
CVE-2015-5430

HP Matrix Operating Environment before 7.5.0 allows remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 7.4
Fix from $1,600 2015-08-27
Version Control Repository Manager MEDIUM 6.8
CVE-2015-5411

HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.

Fix: after 7.4.0
Fix from $1,600 2015-08-26
Xfsprogs MEDIUM 5.0
CVE-2012-2150

xfs_metadump in xfsprogs before 3.2.4 does not properly obfuscate file data, which allows remote attackers to obtain sensitive information by reading…

Fix: after 3.2.3
Fix from $1,600 2015-08-25
Business Service Management MEDIUM 5.0
CVE-2015-3269EPSS 10%

Apache Flex BlazeDS, as used in flex-messaging-core.jar in Adobe LiveCycle Data Services (LCDS) 3.0.x before 3.0.0.354170, 4.5 before 4.5.1.354169, 4…

Fix: after 9.26
Fix from $1,600 2015-08-25
Drupal MEDIUM 5.0
CVE-2015-6661

Drupal 6.x before 6.37 and 7.x before 7.39 allows remote attackers to obtain sensitive node titles by reading the menu.

Patch available
Fix from $1,600 2015-08-24
Linux Pam MEDIUM 6.5
CVE-2015-3238

The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows loc…

Fix: after 1121
Fix from $1,600 2015-08-24
Websphere Virtual Enterprise MEDIUM 5.0
CVE-2015-1932

IBM WebSphere Application Server 7.x before 7.0.0.39, 8.0.x before 8.0.0.11, and 8.5.x before 8.5.5.7 and WebSphere Virtual Enterprise before 7.0.0.7…

Fix: after 7.0.0.6
Fix from $1,600 2015-08-22
Edge Bluebird Operating System MEDIUM 6.8
CVE-2015-4308

The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain s…

Mitigation only
Fix from $1,600 2015-08-19
Apache Solr Real Time MEDIUM 5.0
CVE-2015-5506

The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attacker…

Patch available
Fix from $1,600 2015-08-18
Views MEDIUM 5.0
CVE-2015-5490

The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the sta…

Patch available
Fix from $1,600 2015-08-18
Mac Os X MEDIUM 5.0
CVE-2015-3784

Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read arbitrary files via an XML document containing an ext…

Fix: after 10.10.4
Fix from $1,600 2015-08-16
Mac Os X MEDIUM 5.0
CVE-2015-3762

The Text Formats component in Apple OS X before 10.10.5, as used in TextEdit, allows remote attackers to read arbitrary files via a text file contain…

Fix: after 10.10.4
Fix from $1,600 2015-08-16
Safari MEDIUM 5.0
CVE-2015-3753

WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.1 and other products, does not properly perfor…

Fix: 6.2.8 / 7.1.8+
Fix from $1,600 2015-08-16
Safari MEDIUM 5.0
CVE-2015-3752

The Content Security Policy implementation in WebKit in Apple Safari before 6.2.8, 7.x before 7.1.8, and 8.x before 8.0.8, as used in iOS before 8.4.…

Fix: 6.2.8 / 7.1.8+
Fix from $1,600 2015-08-16
Ubuntu Linux MEDIUM 5.0
CVE-2015-4478

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which a…

Fix: after 39.0.3
Fix from $1,600 2015-08-16
Subversion MEDIUM 5.0
CVE-2015-3184EPSS 11%

mod_authz_svn in Apache Subversion 1.7.x before 1.7.21 and 1.8.x before 1.8.14, when using Apache httpd 2.4.x, does not properly restrict anonymous a…

Fix: after 7.2.1
Fix from $1,600 2015-08-12
Jabberd2 MEDIUM 6.5
CVE-2015-2058

c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated us…

Fix: after 2.3.2
Fix from $1,600 2015-08-12
Yodobashi MEDIUM 6.8
CVE-2015-2980

The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitiv…

Fix: after 1.2.1.0
Fix from $1,600 2015-08-08
Aleos HIGH 10.0
CVE-2015-2897

Sierra Wireless ALEOS before 4.4.2 on AirLink ES, GX, and LS devices has hardcoded root accounts, which makes it easier for remote attackers to obtai…

Fix: after 4.4.1
Fix from $1,950 2015-08-08
Fedora MEDIUM 5.0
CVE-2015-1840

jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allo…

Fix: after 3.1.2
Fix from $1,600 2015-07-26
Maximo Anywhere MEDIUM 5.0
CVE-2015-4945

Unspecified vulnerability in the IBM Maximo Anywhere application 7.5.1 through 7.5.1.2 for Android allows attackers to bypass a passcode protection m…

Patch available
Fix from $1,600 2015-07-26
Avamar Server HIGH 7.8
CVE-2015-4527

Directory traversal vulnerability in EMC Avamar Server 7.x before 7.1.2 and Avamar Virtual Addition (AVE) 7.x before 7.1.2 allows remote attackers to…

Mitigation only
Fix from $1,950 2015-07-23
Enterprise Linux Desktop Supplementary MEDIUM 5.0
CVE-2015-1285

The XSSAuditor::canonicalize function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 44.0.2403.89, d…

Fix: after 43.0.2357.134
Fix from $1,600 2015-07-23
Enterprise Manager Database Control MEDIUM 5.0
CVE-2015-4735

Unspecified vulnerability in the Enterprise Manager for Oracle Database component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1…

Patch available
Fix from $1,600 2015-07-16
Acrobat MEDIUM 5.0
CVE-2015-5092

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Acrobat MEDIUM 5.0
CVE-2015-5089

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 15.006.30060 / 15.008.20082+
Fix from $1,600 2015-07-15
Acrobat MEDIUM 5.0
CVE-2015-5088

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 15.006.30060 / 15.008.20082+
Fix from $1,600 2015-07-15