Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Owncloud Server MEDIUM 5.0
CVE-2013-2086

The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an u…

Patch available
Fix from $1,600 2014-03-14
Windows 7 MEDIUM 6.6
CVE-2014-0323

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…

Patch available
Fix from $1,600 2014-03-12
Diskstation Manager HIGH 7.8
CVE-2014-2264

The OpenVPN module in Synology DiskStation Manager (DSM) 4.3-3810 update 1 has a hardcoded root password of synopass, which makes it easier for remot…

Mitigation only
Fix from $1,950 2014-03-02
Chrome MEDIUM 5.0
CVE-2013-6656

The XSSAuditor::init function in core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, processe…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Customer Relationship Management MEDIUM 5.0
CVE-2014-1962

Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE)…

Mitigation only
Fix from $1,600 2014-02-14
Opensaml MEDIUM 5.0
CVE-2013-6440

The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expand…

Fix: after 2.6.0
Fix from $1,600 2014-02-14
Windows 7 HIGH 7.1
CVE-2014-0266EPSS 19%

The XMLHTTP ActiveX controls in XML Core Services 3.0 in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server…

Patch available
Fix from $1,950 2014-02-12
Compute HIGH 7.1
CVE-2013-7130

The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, w…

Patch available
Fix from $1,950 2014-02-06
Firefox MEDIUM 5.0
CVE-2014-1484

Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitiv…

Fix: after 26.0
Fix from $1,600 2014-02-06
Kdelibs MEDIUM 5.0
CVE-2013-2074

kioslave/http/http.cpp in KIO in kdelibs 4.10.3 and earlier allows attackers to discover credentials via a crafted request that triggers an "internal…

Fix: after 4.10.3
Fix from $1,600 2014-02-05
Openssh MEDIUM 5.5
CVE-2011-4327

ssh-keysign.c in ssh-keysign in OpenSSH before 5.8p2 on certain platforms executes ssh-rand-helper with unintended open file descriptors, which allow…

Fix: after 5.8
Fix from $1,600 2014-02-03
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4043

The server in IBM SPSS Collaboration and Deployment Services 4.x before 4.2.1.3 IF3, 5.x before 5.0 FP3, and 6.x before 6.0 IF1 allows remote attacke…

Mitigation only
Fix from $1,600 2014-02-01
Tntnet MEDIUM 5.0
CVE-2013-7299

framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n …

Fix: after 2.2
Fix from $1,600 2014-01-26
Gotomeeting MEDIUM 5.0
CVE-2014-1664

The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain use…

No fix yet
Fix from $1,600 2014-01-26
Jboss Seam 2 Framework MEDIUM 5.0
CVE-2013-6447

Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Re…

Fix: after 2.3.1
Fix from $1,600 2014-01-23
Command School Student Management System MEDIUM 5.0
CVE-2014-1637EPSS 7%

Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to dow…

No fix yet
Fix from $1,600 2014-01-22
Havana MEDIUM 5.0
CVE-2013-6419

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a reques…

Patch available
Fix from $1,600 2014-01-07
Blogengine.net MEDIUM 5.0
CVE-2013-6953

BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.

Fix: after 2.8
Fix from $1,600 2014-01-03
Fat Free Crm MEDIUM 5.0
CVE-2013-7224

Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, …

Fix: after 0.12.0
Fix from $1,600 2014-01-02
Fat Free Crm MEDIUM 5.0
CVE-2013-7249

Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, a…

Fix: after 0.12.0
Fix from $1,600 2014-01-02
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4069

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read …

Mitigation only
Fix from $1,600 2013-12-21
Spss Collaboration And Deployment Services MEDIUM 5.0
CVE-2013-4070

The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to disco…

Mitigation only
Fix from $1,600 2013-12-21
Prosafe Firmware HIGH 7.8
CVE-2013-4775EPSS 15%

NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, G…

Fix: after 5.4.1.14
Fix from $1,950 2013-12-19
Webex Training Center MEDIUM 5.0
CVE-2013-6968

Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows …

Mitigation only
Fix from $1,600 2013-12-14
Webex Meeting Center MEDIUM 5.0
CVE-2013-6970

Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6972

Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading…

Mitigation only
Fix from $1,600 2013-12-14
Webex Training Center MEDIUM 5.0
CVE-2013-6709

The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-12-14
Openjpeg MEDIUM 5.0
CVE-2013-6052

OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.

Fix: after 1.3
Fix from $1,600 2013-12-12
Opensuse HIGH 7.8
CVE-2012-0425

LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows contex…

Mitigation only
Fix from $1,950 2013-12-02
Jahia Xcm MEDIUM 5.0
CVE-2013-4617

Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attacker…

Fix: after 6.6.1
Fix from $1,600 2013-11-27