Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Firefox MEDIUM 5.0
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi…

Fix: after 34.0.5
Fix from $1,600 2015-01-14
Dap 1360 Firmware MEDIUM 5.0
CVE-2014-10026

index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by set…

Fix: after 2.5.4
Fix from $1,600 2015-01-13
Maian Uploader MEDIUM 5.0
CVE-2014-10005

Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which revea…

No fix yet
Fix from $1,600 2015-01-13
Js Multi Hotel MEDIUM 5.0
CVE-2014-100009

The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the ins…

Fix: after 2.2.1
Fix from $1,600 2015-01-13
Webex Meetings Server MEDIUM 5.0
CVE-2014-8035

The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which …

Mitigation only
Fix from $1,600 2015-01-10
Epolicy Orchestrator MEDIUM 5.0
CVE-2015-0922EPSS 13%

McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows …

Fix: after 4.6.8
Fix from $1,600 2015-01-09
Vdg Sense MEDIUM 5.0
CVE-2014-9579

VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by re…

No fix yet
Fix from $1,600 2015-01-08
Vdg Sense MEDIUM 5.0
CVE-2014-9576

VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgre…

No fix yet
Fix from $1,600 2015-01-08
Documentum Wdk MEDIUM 5.0
CVE-2014-4638

EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtain sensitive information via u…

Fix: after 6.7
Fix from $1,600 2015-01-07
Redaxscript MEDIUM 5.0
CVE-2011-5314

templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full…

No fix yet
Fix from $1,600 2015-01-01
Videowhisper Live Streaming Integration MEDIUM 5.0
CVE-2014-1908EPSS 7%

The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plug…

Fix: after 4.27.4
Fix from $1,600 2014-12-29
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-6229

The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key …

Fix: after 3.2.0
Fix from $1,600 2014-12-28
Webuzo MEDIUM 5.0
CVE-2013-6043

The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the …

Fix: after 2.1.3
Fix from $1,600 2014-12-27
Identity Services Engine Software MEDIUM 5.0
CVE-2014-8017

The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req…

Mitigation only
Fix from $1,600 2014-12-22
Activator MEDIUM 5.0
CVE-2014-9408

Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC add…

No fix yet
Fix from $1,600 2014-12-19
Websphere Application Server MEDIUM 5.0
CVE-2014-6164

IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, a…

Mitigation only
Fix from $1,600 2014-12-18
Security Access Manager For Web MEDIUM 5.0
CVE-2014-6088

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a…

Mitigation only
Fix from $1,600 2014-12-18
Security Access Manager For Mobile MEDIUM 5.0
CVE-2014-6086

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure …

Mitigation only
Fix from $1,600 2014-12-18
Security Access Manager For Web MEDIUM 5.0
CVE-2014-6083

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a…

Mitigation only
Fix from $1,600 2014-12-18
Mantisbt MEDIUM 5.0
CVE-2014-8553

The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive informa…

Fix: after 1.2.17
Fix from $1,600 2014-12-17
Zenoss Core MEDIUM 5.0
CVE-2014-9250

Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-9245

Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Operational Decision Manager MEDIUM 5.0
CVE-2014-6114

The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Deci…

Mitigation only
Fix from $1,600 2014-12-11
Windows 7 MEDIUM 5.0
CVE-2014-6355EPSS 34%

The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…

Mitigation only
Fix from $1,600 2014-12-11
Acrobat Reader MEDIUM 5.0
CVE-2014-8452EPSS 18%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML ex…

Mitigation only
Fix from $1,600 2014-12-10
Acrobat MEDIUM 5.0
CVE-2014-8451EPSS 9%

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain …

Mitigation only
Fix from $1,600 2014-12-10
Acrobat MEDIUM 5.0
CVE-2014-8448EPSS 9%

An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain …

Mitigation only
Fix from $1,600 2014-12-10
Unified Computing System MEDIUM 5.0
CVE-2014-8009

The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log…

Fix: after 2.1
Fix from $1,600 2014-12-10
Mantisbt MEDIUM 5.0
CVE-2014-9279

The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain data…

Patch available
Fix from $1,600 2014-12-08
N5200 Active Network Control Panel HIGH 7.8
CVE-2014-9303

EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a U…

No fix yet
Fix from $1,950 2014-12-07