Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2017-8471 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607,… Windows 10 Patch available Fix from $1,6002017-06-15 MEDIUM 5.0 CVE-2017-8473 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allow a… Windows 10 Patch available Fix from $1,6002017-06-15 MEDIUM 5.0 CVE-2017-8474 The kernel in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 151… Windows 10 Patch available Fix from $1,6002017-06-15 MEDIUM 5.0 CVE-2017-0282 Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, … Office Patch available Fix from $1,6002017-06-15 MEDIUM 5.0 CVE-2017-0284 Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, … Office Patch available Fix from $1,6002017-06-15 MEDIUM 5.3 CVE-2017-4986 EMC ESRS VE 3.18 or earlier contains Authentication Bypass that could potentially be exploited by malicious users to compromise the affected system. Secure Remote Services Mitigation only Fix from $1,6002017-06-14 MEDIUM 5.5 CVE-2017-0639 An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission le… Android Mitigation only Fix from $1,6002017-06-14 MEDIUM 5.5 CVE-2017-0645 An elevation of privilege vulnerability in Bluetooth could enable a local malicious application to access data outside of its permission levels. This… Android Mitigation only Fix from $1,6002017-06-14 MEDIUM 5.5 CVE-2017-0646 An information disclosure vulnerability in Bluetooth component could enable a local malicious application to access data outside of its permission le… Android Mitigation only Fix from $1,6002017-06-14 MEDIUM 5.5 CVE-2017-0647 An information disclosure vulnerability in libziparchive could enable a local malicious application to access data outside of its permission levels. … Android Mitigation only Fix from $1,6002017-06-14 HIGH 7.1 CVE-2016-10339 In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore. Android Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2017-8239 In all Android releases from CAF using the Linux kernel, userspace-controlled parameters for flash initialization are not sanitized potentially leadi… Android Patch available Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2017-9605 The vmw_gb_surface_define_ioctl function (accessible via DRM_IOCTL_VMW_GB_SURFACE_CREATE) in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux ker… Linux Kernel after 4.11.4 Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2016-3696 The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key. Fedora after 2.8.4 Fix from $1,6002017-06-13 MEDIUM 6.5 CVE-2017-6673 A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use … Secure Firewall Management Center Mitigation only Fix from $1,6002017-06-13 HIGH 7.5 CVE-2017-6681 A vulnerability in the AutoVNF VNFStagingView class of Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to execute a re… Ultra Services Framework Mitigation only Fix from $1,9502017-06-13 MEDIUM 6.5 CVE-2017-6691 A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive information … Elastic Services Controller Mitigation only Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2017-6695 A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More… Ultra Services Platform Mitigation only Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2017-6696 A vulnerability in the file system of Cisco Elastic Services Controllers could allow an authenticated, local attacker to gain access to sensitive use… Elastic Services Controller Mitigation only Fix from $1,6002017-06-13 MEDIUM 6.5 CVE-2017-6697 A vulnerability in the web interface of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to access sensitive system c… Elastic Services Controller Mitigation only Fix from $1,6002017-06-13 HIGH 7.8 CVE-2017-4966 An issue was discovered in these Pivotal RabbitMQ versions: all 3.4.x versions, all 3.5.x versions, and 3.6.x versions prior to 3.6.9; and these Rabb… Debian Linux Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.7 CVE-2017-1214 IBM iNotes 8.5 and 9.0 could allow a remote attacker to send a malformed email to a victim, that when opened could cause an information disclosure. I… Inotes Patch available Fix from $1,6002017-06-12 MEDIUM 5.9 CVE-2017-9526 In Libgcrypt before 1.7.7, an attacker who learns the EdDSA session key (from side-channel observation during the signing process) can easily recover… Libgcrypt after 1.7.6 Fix from $1,6002017-06-11 MEDIUM 5.3 CVE-2016-7832 Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to obtain an arbitrary DBM (Cybozu Dezie proprietary format) file v… Dezie Mitigation only Fix from $1,6002017-06-09 MEDIUM 6.5 CVE-2017-2165 GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as e… Groupsession after 4.6.4 Fix from $1,6002017-06-09 HIGH 7.5 CVE-2016-7814 I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authen… Ts Wrlp Firmware after 1.00.01 Fix from $1,9502017-06-09 HIGH 7.5 CVE-2015-3634 The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attack… Slideshow Patch available Fix from $1,9502017-06-08 MEDIUM 5.3 CVE-2016-9736 IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information. Websphere Application Server Patch available Fix from $1,6002017-06-08 MEDIUM 5.5 CVE-2016-3095 server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key. Fedora after 2.8.1 Fix from $1,6002017-06-08 HIGH 7.5 CVE-2016-4992 389 Directory Server in Red Hat Enterprise Linux Desktop 6 through 7, Red Hat Enterprise Linux HPC Node 6 through 7, Red Hat Enterprise Linux Server … Enterprise Linux Desktop Patch available Fix from $1,9502017-06-08