Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2017-1333 IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow an unauthenticated user to obtain sensitive information about the server that could be used … Openpages Grc Platform Patch available Fix from $1,6002017-11-01 MEDIUM 5.0 CVE-2017-1340 IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder inte… Jazz Reporting Service Patch available Fix from $1,6002017-11-01 MEDIUM 6.5 CVE-2017-16353EPSS 14% GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c fil… Debian Linux No fix yet Fix from $1,6002017-11-01 HIGH 7.5 CVE-2017-16248 The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in… Catalyst Plugin Static Simple 0.34+ Fix from $1,9502017-11-01 MEDIUM 5.5 CVE-2017-1000382 VIM version 8.0.1187 (and other versions most likely) ignores umask when creating a swap file ("[ORIGINAL_FILENAME].swp") resulting in files that may… Vim after 8.0.1187 Fix from $1,6002017-10-31 MEDIUM 5.5 CVE-2017-1000383 GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files … Emacs after 25.3.0 Fix from $1,6002017-10-31 MEDIUM 6.5 CVE-2017-10942 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio… Foxit Reader Patch available Fix from $1,6002017-10-31 MEDIUM 6.5 CVE-2017-10943 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio… Foxit Reader Patch available Fix from $1,6002017-10-31 MEDIUM 6.5 CVE-2017-10944 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interactio… Foxit Reader Patch available Fix from $1,6002017-10-31 MEDIUM 5.9 CVE-2017-3934 Missing HTTP Strict Transport Security state information vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows man-i… Network Data Loss Prevention after 9.3.0 Fix from $1,6002017-10-31 HIGH 7.5 CVE-2017-3935 Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the res… Network Data Loss Prevention after 9.3.0 Fix from $1,9502017-10-31 HIGH 7.5 CVE-2014-3526 Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors invo… Wicket 1.5.12+ Fix from $1,9502017-10-30 CRITICAL 9.1 CVE-2017-15597 An issue was discovered in Xen through 4.9.x. Grant copying code made an implication that any grant pin would be accompanied by a suitable page refer… Xen after 4.9.0 Fix from $2,3002017-10-30 MEDIUM 6.5 CVE-2017-15937 Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies… Pandora Fms Mitigation only Fix from $1,6002017-10-27 MEDIUM 6.5 CVE-2017-5117 Use of an uninitialized value in Skia in Google Chrome prior to 61.0.3163.79 for Linux and Windows allowed a remote attacker to obtain potentially se… Chrome 61.0.3163.79+ Fix from $1,6002017-10-27 MEDIUM 5.5 CVE-2017-5082 Failure to take advantage of available mitigations in credit card autofill in Google Chrome prior to 59.0.3071.92 for Android allowed a local attacke… Chrome 59.0.3071.92+ Fix from $1,6002017-10-27 MEDIUM 5.3 CVE-2017-1220 IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) discloses sensitive information to unauthorized users. The information can be used to m… Bigfix Platform Patch available Fix from $1,6002017-10-26 MEDIUM 5.3 CVE-2017-1225 IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) stores sensitive information in URL parameters. This may lead to information disclosure… Bigfix Platform Patch available Fix from $1,6002017-10-26 MEDIUM 5.3 CVE-2017-1230 IBM Tivoli Endpoint Manager (IBM BigFix Platform 9.2 and 9.5) uses insufficiently random numbers or values in a security context that depends on unpr… Bigfix Platform Patch available Fix from $1,6002017-10-26 HIGH 7.5 CVE-2017-1583 IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.13)could allow a remote attacker to obtain sensitive information caused by impro… Liberty Mitigation only Fix from $1,9502017-10-24 HIGH 8.8 CVE-2015-5173 Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have u… Cf Release 1.7.0 / 2.5.2+ Fix from $1,9502017-10-24 HIGH 7.5 CVE-2017-7116 An issue was discovered in certain Apple products. iOS before 11 is affected. tvOS before 11 is affected. watchOS before 4 is affected. The issue inv… Iphone Os after 10.3.3 Fix from $1,9502017-10-23 MEDIUM 5.5 CVE-2017-7131 An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Bluetooth" component. It allows attackers to ob… Iphone Os after 10.3.3 Fix from $1,6002017-10-23 MEDIUM 5.3 CVE-2017-7140 An issue was discovered in certain Apple products. iOS before 11 is affected. The issue involves the "Keyboard Suggestions" component. It allows atta… Iphone Os after 10.3.3 Fix from $1,6002017-10-23 MEDIUM 5.3 CVE-2017-7141 An issue was discovered in certain Apple products. macOS before 10.13 is affected. The issue involves the "Mail" component. It allows remote attacker… Mac Os X after 10.12.6 Fix from $1,6002017-10-23 MEDIUM 5.3 CVE-2017-7142 An issue was discovered in certain Apple products. Safari before 11 is affected. The issue involves the "WebKit Storage" component. It allows attacke… Safari after 10.1.2 Fix from $1,6002017-10-23 HIGH 7.5 CVE-2017-7090 An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected.… Safari after 12.6.2 Fix from $1,9502017-10-23 HIGH 8.1 CVE-2017-13127 The VIP.com application for IOS and Android allows remote attackers to obtain sensitive information and hijack the authentication of users via a rogu… Vip Mitigation only Fix from $1,9502017-10-20 MEDIUM 5.3 CVE-2017-2131 Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configu… Kx Hjb1000 Firmware Mitigation only Fix from $1,6002017-10-20 HIGH 7.5 CVE-2015-6668EPSS 10% The Job Manager plugin before 0.7.25 allows remote attackers to read arbitrary CV files via a brute force attack to the WordPress upload directory st… Job Manager after 0.7.24 Fix from $1,9502017-10-19