Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2018-4084 An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Wi-Fi" component. It allows attackers to… Mac Os X 10.13.3+ Fix from $1,6002018-04-03 MEDIUM 6.5 CVE-2017-2493 An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud before 6.2 on Windows is affec… Safari 6.2 / 10.1+ Fix from $1,6002018-04-03 MEDIUM 5.5 CVE-2017-13839 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Spotlight" component. It allows local user… Mac Os X Mitigation only Fix from $1,6002018-04-03 MEDIUM 5.5 CVE-2017-17769 Information leakage in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the audio driver. Android No fix yet Fix from $1,6002018-03-30 MEDIUM 5.5 CVE-2018-1234 RSA Authentication Agent version 8.0.1 and earlier for Web for IIS is affected by a problem where access control list (ACL) permissions on a Windows … Authentication Agent For Web after 8.0.1 Fix from $1,6002018-03-30 HIGH 7.5 CVE-2017-11087 libOmxVenc in Android for MSM, Firefox OS for MSM, and QRD Android copies the output buffer to an application with the "filled length", which is larg… Android Mitigation only Fix from $1,9502018-03-30 HIGH 7.5 CVE-2017-14875 In the handler for the ioctl command VIDIOC_MSM_ISP_DUAL_HW_LPM_MODE in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-05-23, a hea… Android Patch available Fix from $1,9502018-03-30 MEDIUM 5.3 CVE-2017-14891 In the KGSL driver function _gpuobj_map_useraddr() in Android for MSM, Firefox OS for MSM, and QRD Android before 2017-10-12, the contents of the sta… Android Patch available Fix from $1,6002018-03-30 HIGH 7.8 CVE-2017-15852 Information leak of the ISPIF base address in Android for MSM, Firefox OS for MSM, and QRD Android can occur in the camera driver. Android Mitigation only Fix from $1,9502018-03-30 MEDIUM 6.5 CVE-2018-3817 When logging warnings regarding deprecated settings, Logstash before 5.6.6 and 6.x before 6.1.2 could inadvertently log sensitive information. Logstash 5.6.6 / 6.1.2+ Fix from $1,6002018-03-30 MEDIUM 6.5 CVE-2017-9681 In Android before 2017-08-05 on Qualcomm MSM, Firefox OS for MSM, QRD Android, and all Android releases from CAF using the Linux kernel, if kernel me… Android Mitigation only Fix from $1,6002018-03-30 CRITICAL 9.6 CVE-2016-6658 Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho… Cf Release 1.6.49 / 1.7.31+ Fix from $2,3002018-03-29 HIGH 8.8 CVE-2018-1191 Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to… Cf Deployment 1.9.0 / 1.11.0+ Fix from $1,9502018-03-29 MEDIUM 6.5 CVE-2014-5028 The Original File and Patched File resources in Review Board 1.7.x before 1.7.27 and 2.0.x before 2.0.4 allow remote authenticated users to bypass in… Review Board 1.7.27 / 2.0.4+ Fix from $1,6002018-03-29 CRITICAL 9.8 CVE-2017-11510 An information leak exists in Wanscam's HW0021 network camera that allows an unauthenticated remote attacker to recover the administrator username an… Hw0021 Firmware No fix yet Fix from $2,3002018-03-28 MEDIUM 5.9 CVE-2018-7676 The NetIQ Identity Manager, in versions prior to 4.7, userapp with log / trace enabled may leak sensitive information. Identity Manager after 4.6 Fix from $1,6002018-03-28 MEDIUM 6.5 CVE-2014-5130 Avolve Software ProjectDox 8.1 allows remote authenticated users to obtain sensitive information from other users via vectors involving a direct acce… Projectdox No fix yet Fix from $1,6002018-03-27 MEDIUM 6.5 CVE-2014-5131 Avolve Software ProjectDox 8.1 makes it easier for remote authenticated users to obtain sensitive information by leveraging ciphertext reuse. Projectdox No fix yet Fix from $1,6002018-03-27 MEDIUM 5.3 CVE-2017-7630 QNAP QTS 4.2.6 build 20171026, QTS 4.3.3 build 20170727 and earlier allows remote attackers to obtain potentially sensitive information (firmware ver… Qts Mitigation only Fix from $1,6002018-03-27 MEDIUM 5.6 CVE-2018-9056 Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v… Atom C No fix yet Fix from $1,6002018-03-27 HIGH 7.5 CVE-2017-12310 A vulnerability in the auto discovery phase of Cisco Spark Hybrid Calendar Service could allow an unauthenticated, remote attacker to view sensitive … Spark Hybrid Calendar Service Mitigation only Fix from $1,9502018-03-27 HIGH 7.8 CVE-2015-7432 IBM Capacity Management Analytics 2.1.0.0 allows local users to decrypt usernames and passwords by leveraging access to setenv.sh and parameter.txt. … Capacity Management Analytics Patch available Fix from $1,9502018-03-26 HIGH 7.8 CVE-2015-7433 IBM Capacity Management Analytics 2.1.0.0 allows local users to discover cleartext usernames and passwords by leveraging access to the CMA install ma… Capacity Management Analytics Patch available Fix from $1,9502018-03-26 HIGH 7.8 CVE-2015-7434 IBM Capacity Management Analytics 2.1.0.0 allows local users to discover encrypted usernames and passwords by leveraging access to the CMA install ma… Capacity Management Analytics Patch available Fix from $1,9502018-03-26 HIGH 7.5 CVE-2018-9014 dsmall v20180320 allows physical path leakage via a public/index.php/home/predeposit/index.html?pdr_sn= request. Dsmall Mitigation only Fix from $1,9502018-03-25 MEDIUM 5.3 CVE-2016-9711 IBM Predictive Solutions Foundation (IBM Cognos Analytics 11.0) reveals sensitive information in detailed error messages that could aid an attacker i… Cognos Analytics Mitigation only Fix from $1,6002018-03-22 MEDIUM 5.5 CVE-2017-17319 Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not properly prote… P9 Firmware Mitigation only Fix from $1,6002018-03-20 HIGH 7.5 CVE-2018-1000135 GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DN… Ubuntu Linux after 1.10.2 Fix from $1,9502018-03-20 HIGH 7.1 CVE-2014-2885 Multiple integer overflows in TrueCrypt 7.1a allow local users to (1) obtain sensitive information via vectors involving a crafted item->OriginalLeng… Truecrypt Mitigation only Fix from $1,9502018-03-19 MEDIUM 5.9 CVE-2014-4024 SSL virtual servers in F5 BIG-IP systems 10.x before 10.2.4 HF9, 11.x before 11.2.1 HF12, 11.3.0 before HF10, 11.4.0 before HF8, 11.4.1 before HF5, 1… Big Ip Local Traffic Manager after 11.5.1 Fix from $1,6002018-03-19