Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Fedora MEDIUM 5.0
CVE-2015-0844

The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1)…

Mitigation only
Fix from $1,600 2015-04-14
Mediawiki MEDIUM 5.0
CVE-2015-2935

MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user …

Fix: after 1.19.23
Fix from $1,600 2015-04-13
Mac Os X MEDIUM 5.0
CVE-2015-1148

Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sens…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1147

Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates…

Fix: 10.10.3+
Fix from $1,600 2015-04-10
Safari MEDIUM 5.0
CVE-2015-1128

The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsin…

Fix: after 6.2.4
Fix from $1,600 2015-04-10
Safari MEDIUM 5.0
CVE-2015-1112

Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-h…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1111

Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain s…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1110

The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-downlo…

Fix: after 8.2
Fix from $1,600 2015-04-10
Iphone Os MEDIUM 5.0
CVE-2015-1090

CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing ac…

Fix: after 8.2
Fix from $1,600 2015-04-10
Mac Os X MEDIUM 5.0
CVE-2015-1089

CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, wh…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Ignition MEDIUM 5.0
CVE-2015-0991

Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception,…

Mitigation only
Fix from $1,600 2015-04-03
All In One Seo Pack MEDIUM 5.0
CVE-2015-0902

The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Me…

Fix: after 2.2.5.1
Fix from $1,600 2015-04-03
Mednet HIGH 9.0
CVE-2014-5405

Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypas…

Fix: after 5.8
Fix from $1,950 2015-04-03
Netweaver MEDIUM 5.0
CVE-2015-2817

The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu…

No fix yet
Fix from $1,600 2015-04-01
Firefox MEDIUM 5.0
CVE-2015-0800

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Diskstation Manager MEDIUM 5.0
CVE-2015-2809

The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses t…

Fix: after 3.0
Fix from $1,600 2015-04-01
Security Access Manager For Web 7.0 Firmware MEDIUM 5.0
CVE-2015-1892

The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to un…

Fix: after 7.0.0.11
Fix from $1,600 2015-04-01
Aveva Edge MEDIUM 5.0
CVE-2015-0997

Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user int…

Fix: 7.1 / 7.1.3.4+
Fix from $1,600 2015-03-29
Metsys MEDIUM 5.0
CVE-2014-5427

Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Cont…

Mitigation only
Fix from $1,600 2015-03-29
Triton Ap Email MEDIUM 5.0
CVE-2015-2771

The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain …

Fix: after 7.8.3
Fix from $1,600 2015-03-27
Triton Ap Web MEDIUM 5.0
CVE-2015-2762

Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication.

Fix: after 7.8.3
Fix from $1,600 2015-03-27
Triton Ap Data MEDIUM 5.0
CVE-2015-2748

Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive in…

Fix: after 7.8.3
Fix from $1,600 2015-03-26
Mybb MEDIUM 5.0
CVE-2015-2335

A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.

Fix: after 1.8.3
Fix from $1,600 2015-03-18
Windows 7 MEDIUM 5.0
CVE-2015-0089EPSS 21%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,600 2015-03-11
Windows 7 MEDIUM 5.0
CVE-2015-0087EPSS 23%

Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,…

Patch available
Fix from $1,600 2015-03-11
Zeuscart MEDIUM 5.0
CVE-2015-2184EPSS 8%

ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function.

No fix yet
Fix from $1,600 2015-03-10
Fedora MEDIUM 5.0
CVE-2014-8105

389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows r…

Fix: after 1.3.2.26
Fix from $1,600 2015-03-10
Fedora MEDIUM 5.0
CVE-2015-2206

libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values …

Patch available
Fix from $1,600 2015-03-09
Debian Linux MEDIUM 5.0
CVE-2015-1165

RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket…

Mitigation only
Fix from $1,600 2015-03-09
Netcat MEDIUM 5.0
CVE-2015-2214

NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.

Fix: after 5.01
Fix from $1,600 2015-03-05