Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Sametime MEDIUM 5.0
CVE-2013-3982EPSS 13%

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to obtain unspecified installation information…

Mitigation only
Fix from $1,600 2014-05-26
Webex Business Suite MEDIUM 5.0
CVE-2014-2199

meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and ea…

Fix: after 1.5
Fix from $1,600 2014-05-20
Netweaver MEDIUM 5.0
CVE-2014-3787

SAP NetWeaver 7.20 and earlier allows remote attackers to read arbitrary SAP Central User Administration (SAP CUA) tables via unspecified vectors.

Fix: after 7.20
Fix from $1,600 2014-05-19
Icedtea Web MEDIUM 5.0
CVE-2011-2513

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…

Fix: after 1.8.8
Fix from $1,600 2014-05-14
Soappy MEDIUM 5.0
CVE-2014-3242

SOAPpy 0.12.5 allows remote attackers to read arbitrary files via a SOAP request containing an external entity declaration in conjunction with an ent…

No fix yet
Fix from $1,600 2014-05-12
Mediawiki MEDIUM 5.0
CVE-2013-6472

MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) l…

Fix: after 1.19.9
Fix from $1,600 2014-05-12
Bscw MEDIUM 5.0
CVE-2014-2301

OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

Fix: after 5.0.7
Fix from $1,600 2014-05-12
Foreman MEDIUM 5.0
CVE-2013-0174

The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.

Fix: after 1.0
Fix from $1,600 2014-05-08
Plone MEDIUM 5.0
CVE-2013-7060

Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file obj…

Mitigation only
Fix from $1,600 2014-05-02
Integraxor MEDIUM 5.0
CVE-2014-0786

Ecava IntegraXor before 4.1.4393 allows remote attackers to read cleartext credentials for administrative accounts via SELECT statements that leverag…

Fix: after 4.1.4390
Fix from $1,600 2014-05-01
Netweaver Software Lifecycle Manager MEDIUM 5.0
CVE-2014-3129

The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted …

Mitigation only
Fix from $1,600 2014-04-30
Slingshot MEDIUM 5.0
CVE-2014-2545

TIBCO Managed File Transfer Internet Server before 7.2.2, Managed File Transfer Command Center before 7.2.2, Slingshot before 1.9.1, and Vault before…

Fix: after 7.2.1
Fix from $1,600 2014-04-30
Android HIGH 7.5
CVE-2013-7373

Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection …

Fix: after 4.3.1
Fix from $1,950 2014-04-29
Basespace Ruby Sdk MEDIUM 5.0
CVE-2013-7111

The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on …

No fix yet
Fix from $1,600 2014-04-29
Dompdf MEDIUM 6.8
CVE-2014-2383EPSS 39%

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitr…

Fix: after 0.6.0
Fix from $1,600 2014-04-28
Lotus Domino MEDIUM 5.0
CVE-2014-0892

IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier f…

Mitigation only
Fix from $1,600 2014-04-23
Drupal MEDIUM 5.0
CVE-2014-2983

Drupal 6.x before 6.31 and 7.x before 7.27 does not properly isolate the cached data of different anonymous users, which allows remote anonymous user…

Fix: 6.31 / 7.27+
Fix from $1,600 2014-04-23
Rt Ac66u Firmware MEDIUM 6.3
CVE-2014-2719

Advanced_System_Content.asp in the ASUS RT series routers with firmware before 3.0.0.4.374.5517, when an administrator session is active, allows remo…

Mitigation only
Fix from $1,600 2014-04-22
Movicon MEDIUM 5.0
CVE-2014-0778

TCPUploader module listens on Port 10651/TCP for incoming connections. Exploitation of this vulnerability could allow a remote unauthenticated user…

Mitigation only
Fix from $1,600 2014-04-19
Imapsync MEDIUM 5.0
CVE-2013-4279

imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to t…

Fix: after 1.564
Fix from $1,600 2014-04-18
Cloud Tiering Appliance Software HIGH 7.8
CVE-2014-0644EPSS 53%

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external …

Mitigation only
Fix from $1,950 2014-04-17
Commonspot Content Server MEDIUM 5.0
CVE-2014-2869

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as d…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2871

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attacke…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2872

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing v…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server MEDIUM 5.0
CVE-2014-2873

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obta…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Advantech Webaccess MEDIUM 5.0
CVE-2014-0771

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “OpenUrlToBuffer.” This method takes a URL as a parameter and returns its contents to t…

Fix: after 7.1
Fix from $1,600 2014-04-12
Advantech Webaccess MEDIUM 5.0
CVE-2014-0772

The BWOCXRUN.BwocxrunCtrl.1 control contains a method named OpenUrlToBufferTimeout. This method takes a URL as a parameter and returns its contents…

Fix: after 7.1
Fix from $1,600 2014-04-12
Hana MEDIUM 5.0
CVE-2014-2749

The HANA ICM process in SAP HANA allows remote attackers to obtain the platform version, host name, instance number, and possibly other sensitive inf…

Mitigation only
Fix from $1,600 2014-04-10
Webex Meeting Center MEDIUM 5.0
CVE-2014-0708

WebEx Meeting Center in Cisco WebEx Business Suite does not properly compose URLs for HTTP GET requests, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2014-03-21
Firefox HIGH 7.5
CVE-2014-1505

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows…

Fix: 24.4 / 28.0+
Fix from $1,950 2014-03-19