Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Cgi Application Module MEDIUM 5.0
CVE-2013-7329

The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive inform…

Fix: after 4.50
Fix from $1,600 2014-10-06
Conga MEDIUM 5.0
CVE-2013-6496

Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…

Mitigation only
Fix from $1,600 2014-10-06
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2014-3398

The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-versi…

Mitigation only
Fix from $1,600 2014-10-05
Change And Configuration Management Database MEDIUM 5.0
CVE-2014-4765

IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for…

Patch available
Fix from $1,600 2014-10-02
Plone MEDIUM 5.0
CVE-2012-5492

uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5497

membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5505

atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name.

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Rational Clearcase MEDIUM 5.0
CVE-2014-3103

The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for th…

Patch available
Fix from $1,600 2014-09-23
Rational Clearcase MEDIUM 5.0
CVE-2014-3105

The OSLC integration feature in the Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 pro…

Patch available
Fix from $1,600 2014-09-23
Bump MEDIUM 5.0
CVE-2014-5320

The Bump application for Android does not properly handle implicit intents, which allows attackers to obtain sensitive owner-name information via a c…

Mitigation only
Fix from $1,600 2014-09-22
Iphone Os MEDIUM 5.0
CVE-2014-4361

The Home & Lock Screen subsystem in Apple iOS before 8 does not properly restrict the private API for app prominence, which allows attackers to deter…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.0
CVE-2014-4362

The Sandbox Profiles implementation in Apple iOS before 8 does not properly restrict the third-party app sandbox profile, which allows attackers to o…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Integraxor MEDIUM 5.0
CVE-2014-2377

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an app…

Fix: after 4.1.4392
Fix from $1,600 2014-09-15
Mpay24 MEDIUM 5.0
CVE-2014-2009EPSS 7%

The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path, and other sensitive informa…

Fix: after 1.5.1
Fix from $1,600 2014-09-12
Rational Doors Next Generation MEDIUM 5.0
CVE-2014-3092

IBM Jazz Team Server, as used in Rational Collaborative Lifecycle Management; Rational Quality Manager 3.x before 3.0.1.6 iFix 3, 4.x before 4.0.7, a…

Patch available
Fix from $1,600 2014-09-12
Rational License Key Server MEDIUM 5.0
CVE-2014-0909

The Administration and Reporting Tool in IBM Rational License Key Server (RLKS) 8.1.4.x before 8.1.4.4 does not set the secure flag for the session c…

Patch available
Fix from $1,600 2014-09-10
Cbw700 Software MEDIUM 5.0
CVE-2014-4862EPSS 17%

The Netmaster CBW700N cable modem with software 81.447.392110.729.024 has an SNMP community of public, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2014-09-05
Touchstone Dg950a Software MEDIUM 5.0
CVE-2014-4863EPSS 16%

The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive pas…

No fix yet
Fix from $1,600 2014-09-05
Device Expert MEDIUM 5.0
CVE-2014-5377EPSS 57%

ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct…

Fix: after 5.9
Fix from $1,600 2014-09-04
Sierra MEDIUM 5.0
CVE-2014-5137

Innovative Interfaces Sierra Library Services Platform 1.2_3 provides different responses for login request depending on whether the user account exi…

Mitigation only
Fix from $1,600 2014-09-02
Encore Discovery Solution MEDIUM 5.0
CVE-2014-5128

Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive informa…

No fix yet
Fix from $1,600 2014-08-29
Cloud Portal MEDIUM 5.0
CVE-2014-3351

Cisco Intelligent Automation for Cloud (aka Cisco Cloud Portal) does not properly consider whether a session is a problematic NULL session, which all…

Mitigation only
Fix from $1,600 2014-08-29
Groupwise HIGH 7.8
CVE-2014-0600

FileUploadServlet in the Administration service in Novell GroupWise 2014 before SP1 allows remote attackers to read or write to arbitrary files via t…

Mitigation only
Fix from $1,950 2014-08-29
Directory Server MEDIUM 5.0
CVE-2014-3562

Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by se…

Mitigation only
Fix from $1,600 2014-08-21
Documentum Content Server MEDIUM 6.3
CVE-2014-2521

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to read sensitive object metadata via an RP…

Fix: after 6.7
Fix from $1,600 2014-08-20
Openstack MEDIUM 5.0
CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014…

Fix: after 0.5.0
Fix from $1,600 2014-08-19
Nx Os MEDIUM 5.0
CVE-2014-3341

The SNMP module in Cisco NX-OS 7.0(3)N1(1) and earlier on Nexus 5000 and 6000 devices provides different error messages for invalid requests dependin…

Fix: after 7.0
Fix from $1,600 2014-08-19
Global Console Manager 16 Firmware MEDIUM 6.3
CVE-2014-3081

prodtest.php on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allows remote authenticated users to read arbi…

Fix: after 1.20.0.22575
Fix from $1,600 2014-08-17
Websphere Portal MEDIUM 5.0
CVE-2014-4746

IBM WebSphere Portal 8.0.0 before 8.0.0.1 CF13 and 8.5.0 through CF01 provides different error codes for firewall-traversal requests depending on whe…

Patch available
Fix from $1,600 2014-08-12
Business Process Manager MEDIUM 5.0
CVE-2014-3076

IBM Business Process Manager (BPM) 8.5 through 8.5.5 allows remote attackers to obtain potentially sensitive information by visiting an unspecified J…

Patch available
Fix from $1,600 2014-08-11