Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.5
CVE-2018-4084
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to…
Mac Os X
10.13.3+
MEDIUM 6.5
CVE-2017-2493
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affec…
Safari
6.2 / 10.1+
MEDIUM 5.5
CVE-2017-13839
An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local user…
Mac Os X
Mitigation only
MEDIUM 5.5
CVE-2017-17769
Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver.
Android
No fix yet
MEDIUM 5.5
CVE-2018-1234
RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows …
Authentication Agent For Web
after 8.0.1
HIGH 7.5
CVE-2017-11087
libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larg…
Android
Mitigation only
HIGH 7.5
CVE-2017-14875
In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a hea…
Android
Patch available
MEDIUM 5.3
CVE-2017-14891
In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the sta…
Android
Patch available
HIGH 7.8
CVE-2017-15852
Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver.
Android
Mitigation only
MEDIUM 6.5
CVE-2018-3817
When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information.
Logstash
5.6.6 / 6.1.2+
MEDIUM 6.5
CVE-2017-9681
In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel me…
Android
Mitigation only
CRITICAL 9.6
CVE-2016-6658
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho…
Cf Release
1.6.49 / 1.7.31+
HIGH 8.8
CVE-2018-1191
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to…
Cf Deployment
1.9.0 / 1.11.0+
MEDIUM 6.5
CVE-2014-5028
The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass in…
Review Board
1.7.27 / 2.0.4+
CRITICAL 9.8
CVE-2017-11510
An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an…
Hw0021 Firmware
No fix yet
MEDIUM 5.9
CVE-2018-7676
The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information.
Identity Manager
after 4.6
MEDIUM 6.5
CVE-2014-5130
Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct acce…
Projectdox
No fix yet
MEDIUM 6.5
CVE-2014-5131
Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse.
Projectdox
No fix yet
MEDIUM 5.3
CVE-2017-7630
QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver…
Qts
Mitigation only
MEDIUM 5.6
CVE-2018-9056
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v…
Atom C
No fix yet
HIGH 7.5
CVE-2017-12310
A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive …
Spark Hybrid Calendar Service
Mitigation only
HIGH 7.8
CVE-2015-7432
IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. …
Capacity Management Analytics
Patch available
HIGH 7.8
CVE-2015-7433
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install ma…
Capacity Management Analytics
Patch available
HIGH 7.8
CVE-2015-7434
IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install ma…
Capacity Management Analytics
Patch available
HIGH 7.5
CVE-2018-9014
dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request.
Dsmall
Mitigation only
MEDIUM 5.3
CVE-2016-9711
IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker i…
Cognos Analytics
Mitigation only
MEDIUM 5.5
CVE-2017-17319
Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not properly prote…
P9 Firmware
Mitigation only
HIGH 7.5
CVE-2018-1000135
GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DN…
Ubuntu Linux
after 1.10.2
HIGH 7.1
CVE-2014-2885
Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLeng…
Truecrypt
Mitigation only
MEDIUM 5.9
CVE-2014-4024
SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 1…
Big Ip Local Traffic Manager
after 11.5.1