Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Moodle MEDIUM 5.0
CVE-2013-4522

lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP…

Fix: after 2.2.11
Fix from $1,600 2013-11-26
Adaptive Server Enterprise HIGH 7.8
CVE-2013-6868

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows lo…

Mitigation only
Fix from $1,950 2013-11-23
Ec Cube MEDIUM 5.0
CVE-2013-5994

data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive informati…

Patch available
Fix from $1,600 2013-11-21
Ec Cube MEDIUM 5.5
CVE-2013-5995

data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 through 2.13.0 allows remote authenticated user…

Patch available
Fix from $1,600 2013-11-21
Chrome MEDIUM 5.0
CVE-2013-6629EPSS 10%

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, …

Fix: 1.3.1 / 9.03+
Fix from $1,600 2013-11-19
Silverstripe MEDIUM 5.0
CVE-2013-6789

security/MemberLoginForm.php in SilverStripe 3.0.3 supports credentials in a GET request, which allows remote or local attackers to obtain sensitive …

Patch available
Fix from $1,600 2013-11-13
Outlook MEDIUM 5.0
CVE-2013-3905EPSS 12%

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remo…

Mitigation only
Fix from $1,600 2013-11-13
Chrony MEDIUM 5.0
CVE-2012-4503

cmdmon.c in Chrony before 1.29 allows remote attackers to obtain potentially sensitive information from stack memory via vectors related to (1) an in…

Fix: after 1.28
Fix from $1,600 2013-11-05
Junos CRITICAL 9.3
CVE-2013-6014

Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1…

Mitigation only
Fix from $2,300 2013-10-28
Drupal MEDIUM 6.8
CVE-2012-0825

Drupal 6.x before 6.23 and 7.x before 7.11 does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modif…

Mitigation only
Fix from $1,600 2013-10-28
Taxweb MEDIUM 5.8
CVE-2013-6020

passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-recovery requests depending on w…

Mitigation only
Fix from $1,600 2013-10-28
Taxweb MEDIUM 5.0
CVE-2013-6285

The search component in the Treasurer application in Tyler Technologies TaxWeb 3.13.3.1 allows remote attackers to obtain sensitive query-structure i…

Mitigation only
Fix from $1,600 2013-10-28
Mediawiki MEDIUM 5.0
CVE-2013-4301

includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote att…

Patch available
Fix from $1,600 2013-10-27
Linux Kernel MEDIUM 6.0
CVE-2013-4299

Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive i…

Fix: after 3.11.6
Fix from $1,600 2013-10-24
Safari MEDIUM 5.0
CVE-2013-5130

WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes it easier for context-depende…

Fix: after 6.0.5
Fix from $1,600 2013-10-24
Shindig MEDIUM 5.0
CVE-2013-4295EPSS 12%

The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an externa…

Patch available
Fix from $1,600 2013-10-24
Imc Service Operation Management Software Module MEDIUM 5.0
CVE-2013-4826EPSS 32%

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers t…

No fix yet
Fix from $1,600 2013-10-13
Ose HIGH 10.0
CVE-2013-0693

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and RO…

Fix: after 3.50
Fix from $1,950 2013-10-03
Jboss Enterprise Application Platform MEDIUM 5.4
CVE-2013-4112

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (di…

Mitigation only
Fix from $1,600 2013-09-28
Prime Data Center Network Manager HIGH 7.8
CVE-2013-5487

DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary files via unspecified vecto…

Fix: after 6.1
Fix from $1,950 2013-09-23
Prime Data Center Network Manager HIGH 7.8
CVE-2013-5490

Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to read arbitrary text files via an XML external entity declarat…

Fix: after 6.1
Fix from $1,950 2013-09-23
Office MEDIUM 5.0
CVE-2013-3160EPSS 23%

Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, and Word Viewer allow remote attackers to read arbitrary files via an XML documen…

Mitigation only
Fix from $1,600 2013-09-11
Mobility Services Engine MEDIUM 5.0
CVE-2013-3469

Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to…

Mitigation only
Fix from $1,600 2013-09-04
FreeBSD HIGH 7.8
CVE-2013-5209

The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does …

Patch available
Fix from $1,950 2013-08-29
Searchblox MEDIUM 5.0
CVE-2013-3597EPSS 8%

servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.

Fix: after 7.5
Fix from $1,600 2013-08-28
Puppet Enterprise MEDIUM 5.0
CVE-2013-4961

Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows …

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Netweaver MEDIUM 5.0
CVE-2013-3319EPSS 20%

The GetComputerSystem method in the HostControl service in SAP Netweaver 7.03 allows remote attackers to obtain sensitive information via a crafted S…

Mitigation only
Fix from $1,600 2013-08-16
Infosphere Information Server MEDIUM 5.0
CVE-2013-3040

IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 produces login-failure messages indicating whether the username or passwo…

Patch available
Fix from $1,600 2013-08-16
Active Directory Federation Services MEDIUM 5.0
CVE-2013-3185EPSS 41%

Microsoft Active Directory Federation Services (AD FS) 1.x through 2.1 on Windows Server 2003 R2 SP2, Windows Server 2008 SP2 and R2 SP1, and Windows…

Mitigation only
Fix from $1,600 2013-08-14
phpMyAdmin MEDIUM 5.0
CVE-2013-4998

phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveal…

Mitigation only
Fix from $1,600 2013-07-31