Vulnerability index

Browse CVEs

7,768 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
phpMyAdmin MEDIUM 5.0
CVE-2013-4999

phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
phpMyAdmin MEDIUM 5.0
CVE-2013-5000

phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path i…

Mitigation only
Fix from $1,600 2013-07-31
Openscape Session Border Controller HIGH 7.8
CVE-2013-4778

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Openscape Session Border Controller HIGH 7.8
CVE-2013-4780

core/getLog.php on the Siemens Enterprise OpenScape Branch appliance and OpenScape Session Border Controller (SBC) before 2 R0.32.0, and 7 before 7 R…

Mitigation only
Fix from $1,950 2013-07-18
Chrome MEDIUM 5.8
CVE-2013-2879

Google Chrome before 28.0.1500.71 does not properly determine the circumstances in which a renderer process can be considered a trusted process for s…

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0481

The console in IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allows remote attackers to read stack traces by triggeri…

Mitigation only
Fix from $1,600 2013-07-03
Sterling B2b Integrator MEDIUM 5.0
CVE-2013-0558

IBM Sterling B2B Integrator 5.1 and 5.2 and Sterling File Gateway 2.1 and 2.2 allow remote attackers to obtain sensitive information about applicatio…

No fix yet
Fix from $1,600 2013-07-03
Prime Central For Hosted Collaboration Solution MEDIUM 5.0
CVE-2013-3398

The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance provides different responses to requests for arbitrary pat…

Mitigation only
Fix from $1,600 2013-06-26
Cybozu Live MEDIUM 6.8
CVE-2013-3647

The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to execute arbitrary JavaScript code, and obtain sensitive…

Fix: after 2.0.0
Fix from $1,600 2013-06-18
Rational Directory Server MEDIUM 5.0
CVE-2013-0599

IBM Eclipse Help System (IEHS), as used in IBM Rational Directory Server 5.1.1 through 5.1.1.2 and 5.2 through 5.2.1 and other products, allows remot…

Fix: after 5.2.1
Fix from $1,600 2013-05-28
Chrome MEDIUM 5.0
CVE-2013-2848

The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 27.0.1453.91
Fix from $1,600 2013-05-22
Acrobat Reader MEDIUM 5.0
CVE-2013-2737

A JavaScript API in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to obtain sensitive infor…

Patch available
Fix from $1,600 2013-05-16
Sterling Secure Proxy MEDIUM 5.0
CVE-2013-0519

IBM Sterling Secure Proxy 3.2.0 and 3.3.01 before 3.3.01.23 Interim Fix 1, 3.4.0 before 3.4.0.6 Interim Fix 1, and 3.4.1 before 3.4.1.7 provides web-…

Mitigation only
Fix from $1,600 2013-05-10
Webex Meetings Server MEDIUM 5.0
CVE-2013-1231

The HTTP implementation in Cisco WebEx Node for MCS and WebEx Meetings Server allows remote attackers to read cache files via a crafted request, aka …

Mitigation only
Fix from $1,600 2013-05-03
Zend Framework MEDIUM 5.0
CVE-2012-5657

The (1) Zend_Feed_Rss and (2) Zend_Feed_Atom classes in Zend_Feed in Zend Framework 1.11.x before 1.11.15 and 1.12.x before 1.12.1 allow remote attac…

Mitigation only
Fix from $1,600 2013-05-02
Service Manager Web Tier MEDIUM 5.0
CVE-2012-5222

HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to obtain sensitive information via unspecified vectors.

Mitigation only
Fix from $1,600 2013-05-02
Curl MEDIUM 5.0
CVE-2013-1944

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remot…

Fix: after 7.29.0
Fix from $1,600 2013-04-29
Unified Computing System Infrastructure And Unified Computing System Software HIGH 9.3
CVE-2013-1185

The web interface in the Manager component in Cisco Unified Computing System (UCS) 1.x and 2.x before 2.0(2m) allows remote attackers to obtain sensi…

Mitigation only
Fix from $1,950 2013-04-25
Infosphere Replication Server MEDIUM 5.0
CVE-2013-0584

The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a l…

Mitigation only
Fix from $1,600 2013-04-23
Opera Browser MEDIUM 5.0
CVE-2013-3210

Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by …

Fix: after 12.14
Fix from $1,600 2013-04-19
Adaptive Security Appliance Software MEDIUM 5.0
CVE-2013-1194

The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages dependin…

Mitigation only
Fix from $1,600 2013-04-18
Ruby Agent MEDIUM 5.0
CVE-2013-0284

Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obta…

Mitigation only
Fix from $1,600 2013-04-09
Folsom MEDIUM 5.0
CVE-2013-1665

The XML libraries for Python 3.4, 3.3, 3.2, 3.1, 2.7, and 2.6, as used in OpenStack Keystone Essex and Folsom, Django, and possibly other products al…

Patch available
Fix from $1,600 2013-04-03
Backupbuddy MEDIUM 5.0
CVE-2013-2744

importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo actio…

No fix yet
Fix from $1,600 2013-04-02
Open Source MEDIUM 5.0
CVE-2013-2264

The SIP channel driver in Asterisk Open Source 1.8.x before 1.8.20.2, 10.x before 10.12.2, and 11.x before 11.2.2; Certified Asterisk 1.8.15 before 1…

Mitigation only
Fix from $1,600 2013-04-01
Moodle MEDIUM 5.0
CVE-2013-1831

lib/setuplib.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 allows remote attackers to obtain sensitive…

Patch available
Fix from $1,600 2013-03-25
Simatic Pcs7 MEDIUM 5.8
CVE-2013-0677

The web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote attackers to obtain sensitive in…

Fix: after 8.0
Fix from $1,600 2013-03-21
Sterling Multi Channel Fulfillment Solution MEDIUM 5.5
CVE-2013-0505

IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticate…

Mitigation only
Fix from $1,600 2013-03-19
Spotfire Statistics Services MEDIUM 5.0
CVE-2013-2371

The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remo…

Mitigation only
Fix from $1,600 2013-03-15
Office MEDIUM 5.0
CVE-2013-0095EPSS 21%

Outlook in Microsoft Office for Mac 2008 before 12.3.6 and Office for Mac 2011 before 14.3.2 allows remote attackers to trigger access to a remote UR…

Mitigation only
Fix from $1,600 2013-03-13