Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Dlguard MEDIUM 5.0
CVE-2015-2209

DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.

Mitigation only
Fix from $1,600 2015-03-04
Businessobjects Edge MEDIUM 5.0
CVE-2015-2076

The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note …

No fix yet
Fix from $1,600 2015-02-27
Redirector Sdk MEDIUM 5.0
CVE-2015-2077

The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qu…

No fix yet
Fix from $1,600 2015-02-24
Rational Insight MEDIUM 5.0
CVE-2014-6115

IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Report…

Patch available
Fix from $1,600 2015-02-24
Web Security Appliance MEDIUM 5.0
CVE-2015-0628

The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP …

Mitigation only
Fix from $1,600 2015-02-20
Kerberos 5 MEDIUM 5.0
CVE-2014-9423

The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and …

Patch available
Fix from $1,600 2015-02-19
Sequence Kinetics MEDIUM 5.0
CVE-2014-6304

The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-code information via unspecifie…

Fix: after 7.5
Fix from $1,600 2015-02-19
Universal Configuration Management Database MEDIUM 5.0
CVE-2014-7883EPSS 37%

HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information b…

Mitigation only
Fix from $1,600 2015-02-15
X Server MEDIUM 6.4
CVE-2015-0255

X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from proces…

Fix: after 1.16.3
Fix from $1,600 2015-02-13
Ovirt MEDIUM 5.0
CVE-2014-0154

oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers t…

Fix: after 3.4.4
Fix from $1,600 2015-02-13
Infosphere Biginsights MEDIUM 5.0
CVE-2014-4781

The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API…

Patch available
Fix from $1,600 2015-02-13
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2015-0602

The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by s…

Fix: after 9.4
Fix from $1,600 2015-02-07
Tower MEDIUM 5.0
CVE-2015-1482EPSS 9%

Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connect…

Fix: after 2.0.4
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9046

The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrar…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Owncloud Server MEDIUM 5.0
CVE-2014-9044

Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatena…

Mitigation only
Fix from $1,600 2015-02-04
Ruggedcom Firmware MEDIUM 5.0
CVE-2015-1357

Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmwa…

Mitigation only
Fix from $1,600 2015-02-02
Webex Meetings Server MEDIUM 5.0
CVE-2015-0597

The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c…

Fix: after 1.5
Fix from $1,600 2015-02-02
Webex Meetings Server MEDIUM 5.0
CVE-2015-0595

The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages …

Fix: after 1.5
Fix from $1,600 2015-02-02
Integration Bus MEDIUM 5.0
CVE-2014-6170

The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote…

Mitigation only
Fix from $1,600 2015-02-02
Mac Os X MEDIUM 5.0
CVE-2014-8839

Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to di…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Iphone Os MEDIUM 5.0
CVE-2014-4491

The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addre…

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Flash Player HIGH 7.8
CVE-2015-0310 KEVEPSS 15%

Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly r…

Fix: 11.2.202.438 / 13.0.0.262+
Fix from $1,950 2015-01-23
Sympa MEDIUM 5.0
CVE-2015-1306

The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files…

Patch available
Fix from $1,600 2015-01-22
Unified Communications Manager MEDIUM 6.8
CVE-2014-8008EPSS 8%

Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen…

Mitigation only
Fix from $1,600 2015-01-22
Watch4net MEDIUM 5.0
CVE-2015-0514EPSS 8%

EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by …

Fix: after 6.5
Fix from $1,600 2015-01-21
Api Management MEDIUM 5.0
CVE-2014-6172

IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vect…

Patch available
Fix from $1,600 2015-01-21
Webex Meeting Center MEDIUM 5.0
CVE-2015-0590

Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi…

Mitigation only
Fix from $1,600 2015-01-17
Java Web Client MEDIUM 5.0
CVE-2014-9199

The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equival…

Fix: after 01.00.0009b
Fix from $1,600 2015-01-17
Cloudstack MEDIUM 5.0
CVE-2014-9593

Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.

Fix: after 4.3.1
Fix from $1,600 2015-01-15
Webex Meeting Center MEDIUM 5.0
CVE-2015-0583

Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors …

Mitigation only
Fix from $1,600 2015-01-14