Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Kaku San Sei Million Aruthur MEDIUM 5.0
CVE-2014-7259

SQUARE ENIX Co., Ltd. Kaku-San-Sei Million Arthur before 2.25 for Android stores "product credentials" on the SD card, which allows attackers to gain…

Fix: after 1.0.1
Fix from $1,600 2014-12-05
L 04d MEDIUM 5.0
CVE-2014-7243

LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web administration interface, which allows remote attackers…

Mitigation only
Fix from $1,600 2014-12-05
Icecast MEDIUM 5.0
CVE-2014-9018

Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to sh…

Fix: after 2.4.0
Fix from $1,600 2014-12-03
Modx Revolution MEDIUM 5.0
CVE-2014-8775

MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote …

No fix yet
Fix from $1,600 2014-12-03
Html5 Mp3 Player With Playlist Free MEDIUM 5.0
CVE-2014-9177

The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html…

Fix: after 2.6
Fix from $1,600 2014-12-02
Ke Questionnaire MEDIUM 5.0
CVE-2014-8874

The ke_questionnaire extension 2.5.2 and earlier for TYPO3 uses predictable names for the questionnaire answer forms, which makes it easier for remot…

Fix: after 2.5.2
Fix from $1,600 2014-12-02
Vap2500 Firmware HIGH 7.8
CVE-2014-8425

The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.

Fix: after 08.41
Fix from $1,950 2014-11-28
Qradar Risk Manager MEDIUM 5.0
CVE-2014-6075

IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2…

Patch available
Fix from $1,600 2014-11-28
Simatic Pcs 7 MEDIUM 5.0
CVE-2014-8552

The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through S…

Mitigation only
Fix from $1,600 2014-11-26
Oputils HIGH 7.8
CVE-2014-8678

The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related …

Fix: after 7.0
Fix from $1,950 2014-11-25
Moodle MEDIUM 5.0
CVE-2014-7848

lib/phpunit/bootstrap.php in Moodle 2.6.x before 2.6.6 and 2.7.x before 2.7.3 allows remote attackers to obtain sensitive information via a direct re…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Direct Web Remoting MEDIUM 5.0
CVE-2014-5325

The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x throu…

Fix: after 2.0.10
Fix from $1,600 2014-11-24
Database Server MEDIUM 6.8
CVE-2014-6477

Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote au…

Patch available
Fix from $1,600 2014-11-23
Commerce MEDIUM 5.0
CVE-2014-9025

The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email add…

Mitigation only
Fix from $1,600 2014-11-20
Clearpass MEDIUM 6.8
CVE-2014-6624

The Insight module in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to read arbitrary files via unsp…

Fix: after 6.3.4
Fix from $1,600 2014-11-19
Clearpass MEDIUM 5.0
CVE-2014-6622

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote attackers to determine the validity of filenames via unspecified vectors.

Fix: after 6.3.4
Fix from $1,600 2014-11-19
Clearpass MEDIUM 5.0
CVE-2014-6621

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not disable the troubleshooting and diagnostics page in production systems, which a…

Fix: after 6.3.4
Fix from $1,600 2014-11-19
Mac Os X MEDIUM 5.0
CVE-2014-4458

The "System Profiler About This Mac" component in Apple OS X before 10.10.1 includes extraneous cookie data in system-model requests, which might all…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
Iphone Os MEDIUM 5.0
CVE-2014-4453

Apple iOS before 8.1.1 and OS X before 10.10.1 include location data during establishment of a Spotlight Suggestions server connection by Spotlight o…

Fix: after 10.10.0
Fix from $1,600 2014-11-18
iOS MEDIUM 5.0
CVE-2014-7992EPSS 27%

The DLSw implementation in Cisco IOS does not initialize packet buffers, which allows remote attackers to obtain sensitive credential information fro…

Mitigation only
Fix from $1,600 2014-11-18
Webfs HIGH 7.2
CVE-2013-0347

The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by read…

No fix yet
Fix from $1,950 2014-11-16
Request Tracker MEDIUM 5.0
CVE-2013-3737

The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (…

Patch available
Fix from $1,600 2014-11-16
Linux MEDIUM 6.4
CVE-2014-8566

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via…

Fix: after 0.8.0
Fix from $1,600 2014-11-15
Open Atrium MEDIUM 5.0
CVE-2014-8736

The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been…

Fix: after 7.x-2.21
Fix from $1,600 2014-11-12
Flash Player MEDIUM 5.0
CVE-2014-8437

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,600 2014-11-11
Linux Kernel MEDIUM 5.0
CVE-2014-8709

The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allow…

Fix: after 3.13.4
Fix from $1,600 2014-11-10
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8665

The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.

Mitigation only
Fix from $1,600 2014-11-06
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8666

The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2014-11-06
Axm Net HIGH 7.5
CVE-2014-2374

The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors…

Patch available
Fix from $1,950 2014-11-05
Notes Traveler MEDIUM 5.0
CVE-2014-6130

The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for …

Fix: after 9.0.1.2
Fix from $1,600 2014-11-04