Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Linux MEDIUM 6.4
CVE-2014-8566

The mod_auth_mellon module before 0.8.1 allows remote attackers to obtain sensitive information or cause a denial of service (segmentation fault) via…

Fix: after 0.8.0
Fix from $1,600 2014-11-15
Open Atrium MEDIUM 5.0
CVE-2014-8736

The Open Atrium Core module for Drupal before 7.x-2.22 allows remote attackers to bypass access restrictions and read file attachments that have been…

Fix: after 7.x-2.21
Fix from $1,600 2014-11-12
Flash Player MEDIUM 5.0
CVE-2014-8437

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,600 2014-11-11
Linux Kernel MEDIUM 5.0
CVE-2014-8709

The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allow…

Fix: after 3.13.4
Fix from $1,600 2014-11-10
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8665

The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.

Mitigation only
Fix from $1,600 2014-11-06
Business Intelligence Development Workbench MEDIUM 5.0
CVE-2014-8666

The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2014-11-06
Axm Net HIGH 7.5
CVE-2014-2374

The AXN-NET Ethernet module accessory 3.04 for the Accuenergy Acuvim II allows remote attackers to discover passwords and modify settings via vectors…

Patch available
Fix from $1,950 2014-11-05
Notes Traveler MEDIUM 5.0
CVE-2014-6130

The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for …

Fix: after 9.0.1.2
Fix from $1,600 2014-11-04
Epicor Enterprise MEDIUM 5.0
CVE-2014-4311EPSS 6%

Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by rea…

Fix: after 7.4
Fix from $1,600 2014-11-04
Plone MEDIUM 5.0
CVE-2012-5508

The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password re…

Fix: after 4.2.2
Fix from $1,600 2014-11-03
Ea3500 Firmware HIGH 7.5
CVE-2014-8244

Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6…

Fix: after 2.0.14294
Fix from $1,950 2014-11-01
Testlink MEDIUM 5.0
CVE-2014-8082

lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which rev…

Fix: after 1.9.12
Fix from $1,600 2014-10-31
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8520

McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network por…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8524

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remot…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Network Data Loss Prevention MEDIUM 5.0
CVE-2014-8525

McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes i…

Fix: after 9.2.2
Fix from $1,600 2014-10-29
Pidgin MEDIUM 5.0
CVE-2014-3698

The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sen…

Fix: after 2.10.9
Fix from $1,600 2014-10-29
Websphere Portal MEDIUM 5.0
CVE-2014-4821

IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF0…

Patch available
Fix from $1,600 2014-10-28
Classic Meeting Server MEDIUM 5.0
CVE-2014-4766

IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playbac…

Mitigation only
Fix from $1,600 2014-10-23
Dokuwiki MEDIUM 5.0
CVE-2014-8761

inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary image…

Fix: after 2013-12-08
Fix from $1,600 2014-10-22
Dokuwiki MEDIUM 5.0
CVE-2014-8762

The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns param…

Fix: after 2013-12-08
Fix from $1,600 2014-10-22
Status2k MEDIUM 5.0
CVE-2014-5094EPSS 6%

Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo f…

No fix yet
Fix from $1,600 2014-10-20
Jenkins MEDIUM 5.0
CVE-2014-2064

The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attac…

Fix: after 1.550
Fix from $1,600 2014-10-17
Businessobjects Explorer MEDIUM 5.0
CVE-2014-8315

polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow…

Mitigation only
Fix from $1,600 2014-10-16
Businessobjects MEDIUM 5.0
CVE-2014-8309

SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen…

Mitigation only
Fix from $1,600 2014-10-16
Jenkins MEDIUM 5.0
CVE-2014-3662

Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.

Fix: after 3.1
Fix from $1,600 2014-10-16
Debian Linux MEDIUM 5.0
CVE-2014-1829

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected requ…

Fix: after 2.2.1
Fix from $1,600 2014-10-15
Requests MEDIUM 5.0
CVE-2014-1830

Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redi…

Fix: after 2.2.1
Fix from $1,600 2014-10-15
Firefox MEDIUM 5.0
CVE-2014-1580

Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from pr…

Fix: after 32.0
Fix from $1,600 2014-10-15
Linux Kernel MEDIUM 6.4
CVE-2014-7284

The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not p…

Patch available
Fix from $1,600 2014-10-13
Digital Editions MEDIUM 5.0
CVE-2014-8068

Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitiv…

Mitigation only
Fix from $1,600 2014-10-09