Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.9 CVE-2017-8582EPSS 8% HTTP.sys in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gol… Windows 10 Patch available Fix from $1,6002017-07-11 MEDIUM 6.5 CVE-2017-8592EPSS 8% Microsoft browsers on when Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1, Windows RT 8.1, and Windows Server 2012 and R2, Windows … Windows 10 Patch available Fix from $1,6002017-07-11 MEDIUM 5.5 CVE-2017-6726 A vulnerability in the CLI of the Cisco Prime Network Gateway could allow an authenticated, local attacker to retrieve system process information, wh… Prime Network Mitigation only Fix from $1,6002017-07-10 MEDIUM 5.3 CVE-2017-6730 A vulnerability in the web-based GUI of Cisco Wide Area Application Services (WAAS) Central Manager could allow an unauthenticated, remote attacker t… Wide Area Application Services Mitigation only Fix from $1,6002017-07-10 HIGH 7.5 CVE-2017-11145 In PHP before 5.6.31, 7.x before 7.0.21, and 7.1.x before 7.1.7, an error in the date extension's timelib_meridian parsing code could be used by atta… PHP after 5.6.30 Fix from $1,9502017-07-10 MEDIUM 6.5 CVE-2017-8442 Elasticsearch X-Pack Security versions 5.0.0 to 5.4.3, when enabled, can result in the Elasticsearch _nodes API leaking sensitive configuration infor… X Pack after 5.4.3 Fix from $1,6002017-07-07 HIGH 7.5 CVE-2017-1000381 The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given inp… Node.js 4.8.4 / 6.11.1+ Fix from $1,9502017-07-07 MEDIUM 5.5 CVE-2017-0326 An information disclosure vulnerability in the NVIDIA Video Driver due to an out-of-bounds read function in the Tegra Display Controller driver could… Android Mitigation only Fix from $1,6002017-07-07 MEDIUM 5.3 CVE-2017-2239 Marp versions v0.0.10 and earlier may allow an attacker to access local resources and files using JavaScript. Marp Mitigation only Fix from $1,6002017-07-07 MEDIUM 6.5 CVE-2017-4999 EMC RSA Archer 5.4.1.3, 5.5.3.1, 5.5.2.3, 5.5.2, 5.5.1.3.1, 5.5.1.1 is affected by an authorization bypass through user-controlled key vulnerability … Rsa Archer Egrc Mitigation only Fix from $1,6002017-07-07 MEDIUM 5.5 CVE-2017-0698 A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35467… Android No fix yet Fix from $1,6002017-07-06 MEDIUM 5.5 CVE-2017-0699 A information disclosure vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36490… Android No fix yet Fix from $1,6002017-07-06 MEDIUM 5.5 CVE-2017-0708 A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879. Android No fix yet Fix from $1,6002017-07-06 MEDIUM 5.5 CVE-2017-0668 A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Andr… Android No fix yet Fix from $1,6002017-07-06 MEDIUM 5.5 CVE-2017-0669 A information disclosure vulnerability in the Android framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34114752. Android No fix yet Fix from $1,6002017-07-06 CRITICAL 9.8 CVE-2017-6708 A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the Cisco Ultra Services Framework could allow an unaut… Ultra Services Framework after 5.0.2 Fix from $2,3002017-07-06 CRITICAL 9.8 CVE-2017-6709 A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative c… Ultra Services Framework after 5.0.2 Fix from $2,3002017-07-06 HIGH 7.5 CVE-2017-2294 Versions of Puppet Enterprise prior to 2016.4.5 or 2017.2.1 failed to mark MCollective server private keys as sensitive (a feature added in Puppet 4.… Puppet Enterprise after 2016.4.3 Fix from $1,9502017-07-05 MEDIUM 6.5 CVE-2017-10911 The make_response function in drivers/block/xen-blkback/blkback.c in the Linux kernel before 4.11.8 allows guest OS users to obtain sensitive informa… Linux Kernel after 4.11.7 Fix from $1,6002017-07-05 HIGH 7.5 CVE-2017-10916 The vCPU context-switch implementation in Xen through 4.8.x improperly interacts with the Memory Protection Extensions (MPX) and Protection Key (PKU)… Xen Mitigation only Fix from $1,9502017-07-05 CRITICAL 9.8 CVE-2017-7317 An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin. Hg100r Firmware No fix yet Fix from $2,3002017-07-04 MEDIUM 5.5 CVE-2017-6705 A vulnerability in the filesystem of the Cisco Prime Collaboration Provisioning tool could allow an authenticated, local attacker to acquire sensitiv… Prime Collaboration Provisioning Mitigation only Fix from $1,6002017-07-04 MEDIUM 5.1 CVE-2017-6706 A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire… Prime Collaboration Provisioning Mitigation only Fix from $1,6002017-07-04 HIGH 8.1 CVE-2016-5045 NetApp OnCommand System Manager before 9.0 allows remote attackers to obtain sensitive credentials via vectors related to cluster peering setup. Oncommand System Manager Mitigation only Fix from $1,9502017-07-03 HIGH 7.5 CVE-2017-0377 Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote a… Tor Patch available Fix from $1,9502017-07-02 MEDIUM 6.5 CVE-2017-8443 In Kibana X-Pack security versions prior to 5.4.3 if a Kibana user opens a crafted Kibana URL the result could be a redirect to an improperly initial… Kibana after 5.4.2 Fix from $1,6002017-06-30 MEDIUM 5.3 CVE-2017-6040 An Information Exposure issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. Non-sensitive informa… Gecko Lite Managed Switch Firmware after 2.0.00 Fix from $1,6002017-06-30 HIGH 7.5 CVE-2017-6046 An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT,… Airlink Raven Xe Firmware Mitigation only Fix from $1,9502017-06-30 CRITICAL 9.8 CVE-2017-7899 An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series … 1763 L16awa Series A after 16.000 Fix from $2,3002017-06-30 HIGH 7.5 CVE-2017-10679 Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL … Piwigo after 2.9.1 Fix from $1,9502017-06-29