Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Acrobat MEDIUM 5.0
CVE-2015-4450

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Acrobat MEDIUM 5.0
CVE-2015-4449

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 15.006.30060 / 15.008.20082+
Fix from $1,600 2015-07-15
Acrobat MEDIUM 5.0
CVE-2014-8450

Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Ac…

Fix: 10.1.15 / 11.0.12+
Fix from $1,600 2015-07-15
Websphere Portal MEDIUM 5.0
CVE-2015-1887

IBM WebSphere Portal 7.0.0 through 7.0.0.2 CF29, 8.0.0 before 8.0.0.1 CF17, and 8.5.0 before CF06 allows remote attackers to obtain sensitive Java Co…

Patch available
Fix from $1,600 2015-07-14
Lifecare Pcainfusion Firmware MEDIUM 5.0
CVE-2015-1011

Hospira LifeCare PCA Infusion System before 7.0 has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecifie…

Fix: after 5.0
Fix from $1,600 2015-07-06
Java MEDIUM 5.0
CVE-2015-1914

IBM Java 7 R1 before SR3, 7 before SR9, 6 R1 before SR8 FP4, 6 before SR16 FP4, and 5.0 before SR16 FP10 allows remote attackers to bypass "permissio…

Fix: 5.0.16.10 / 6.0.16.4+
Fix from $1,600 2015-07-02
Crypto\+\+ Library MEDIUM 5.0
CVE-2015-2141

The InvertibleRWFunction::CalculateInverse function in rw.cpp in libcrypt++ 5.6.2 does not properly blind private key operations for the Rabin-Willia…

Patch available
Fix from $1,600 2015-07-01
Tivoli Storage Manager Fastback HIGH 7.8
CVE-2015-1941EPSS 6%

The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to read arbitrary files via a crafted TCP packet to an un…

Mitigation only
Fix from $1,950 2015-06-30
Unified Communications Domain Manager MEDIUM 5.0
CVE-2015-4229

The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsm…

Mitigation only
Fix from $1,600 2015-06-30
Content Security Management Virtual Appliance MEDIUM 5.0
CVE-2015-4216

The remote-support feature on Cisco Web Security Virtual Appliance (WSAv), Email Security Virtual Appliance (ESAv), and Security Management Virtual A…

Mitigation only
Fix from $1,600 2015-06-26
Ubuntu Linux MEDIUM 6.8
CVE-2015-1851

OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users t…

Fix: after 2014.1.4
Fix from $1,600 2015-06-25
Jabber MEDIUM 5.0
CVE-2015-4218

The web-based user interface in Cisco Jabber through 9.6(3) and 9.7 through 9.7(5) on Windows allows remote attackers to obtain sensitive information…

Mitigation only
Fix from $1,600 2015-06-24
Webex Meeting Center MEDIUM 5.0
CVE-2015-4212

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by discovering credential…

No fix yet
Fix from $1,600 2015-06-24
Webex Meeting Center HIGH 7.5
CVE-2015-4208

Cisco WebEx Meeting Center does not properly restrict the content of URLs in GET requests, which allows remote attackers to obtain sensitive informat…

Mitigation only
Fix from $1,950 2015-06-24
Chec MEDIUM 5.0
CVE-2014-4875

CreateBossCredentials.jar in Toshiba CHEC before 6.6 build 4014 and 6.7 before build 4329 contains a hardcoded AES key, which allows attackers to dis…

Fix: after 6.6
Fix from $1,600 2015-06-24
Webex Meeting Center MEDIUM 6.4
CVE-2015-4209

Cisco WebEx Meeting Center does not properly determine authorization for reading a host calendar, which allows remote attackers to obtain sensitive i…

Mitigation only
Fix from $1,600 2015-06-23
Webex Meeting Center MEDIUM 5.0
CVE-2015-4207

Cisco WebEx Meeting Center places a meeting's access number in a URL, which allows remote attackers to obtain sensitive information and bypass intend…

Mitigation only
Fix from $1,600 2015-06-23
Curl MEDIUM 5.0
CVE-2015-3236EPSS 7%

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset…

Patch available
Fix from $1,600 2015-06-22
iOS MEDIUM 5.0
CVE-2015-4202

Cisco IOS 12.2SCH on uBR10000 router Cable Modem Termination Systems (CMTS) does not properly restrict access to the IP Detail Record (IPDR) service,…

Mitigation only
Fix from $1,600 2015-06-20
Webex Meeting Center MEDIUM 5.0
CVE-2015-4194

The web-based administrative interface in Cisco WebEx Meeting Center provides different error messages for failed login attempts depending on whether…

Mitigation only
Fix from $1,600 2015-06-19
Restful Web Services MEDIUM 5.0
CVE-2015-4345

The RESTWS Basic Auth submodule in the RESTful Web Services module 7.x-1.x before 7.x-1.5 and 7.x-2.x before 7.x-2.3 for Drupal caches pages for auth…

Patch available
Fix from $1,600 2015-06-15
Nova Wind Turbine Hmi Firmware MEDIUM 5.0
CVE-2015-3951

RLE Nova-Wind Turbine HMI devices store cleartext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors.

No fix yet
Fix from $1,600 2015-06-13
Coppermine Photo Gallery MEDIUM 5.0
CVE-2015-3923

Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.

Fix: after 1.5.4
Fix from $1,600 2015-06-10
Xcloner MEDIUM 5.0
CVE-2014-8604EPSS 7%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in the configuration panel, which …

No fix yet
Fix from $1,600 2015-06-10
Flash Player MEDIUM 5.0
CVE-2015-3108

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Air MEDIUM 5.0
CVE-2015-3102

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Air MEDIUM 5.0
CVE-2015-3099

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Air MEDIUM 5.0
CVE-2015-3098

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows and OS X and before 11.2.202.466 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Air MEDIUM 5.0
CVE-2015-3097EPSS 12%

Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160, Adobe AIR before 18.0.0.144, Adobe AIR SDK before 18.0.0.144, and Adobe…

Fix: after 17.0.0.172
Fix from $1,600 2015-06-10
Sysaid MEDIUM 5.0
CVE-2015-2998EPSS 26%

SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensitive information, as demonstr…

Fix: after 15.1
Fix from $1,600 2015-06-08