Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.9 CVE-2016-5900 IBM Tealeaf Customer Experience on Cloud Network Capture Add-On could allow a remote attacker to obtain sensitive information, caused by the failure … Tealeaf Customer Experience On Cloud Network Capture Add On Patch available Fix from $1,6002017-02-08 MEDIUM 5.9 CVE-2016-0270 IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which mak… Client Application Access Patch available Fix from $1,6002017-02-08 MEDIUM 5.9 CVE-2016-10212 Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a … Alteon after 30.2.1.1 Fix from $1,6002017-02-08 MEDIUM 5.9 CVE-2016-10213 A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to … Advanced Core Operating System after 2.7.2 Fix from $1,6002017-02-08 MEDIUM 5.9 CVE-2016-8492 The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPS… Fortios after 4.3.18 Fix from $1,6002017-02-08 MEDIUM 5.9 CVE-2017-5933 Citrix NetScaler ADC and NetScaler Gateway 10.5 before Build 65.11, 11.0 before Build 69.12/69.123, and 11.1 before Build 51.21 randomly generates GC… Netscaler Application Delivery Controller Firmware after 11.1.51.21 Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0420 An information disclosure vulnerability in AOSP Mail could enable a local malicious application to bypass operating system protections that isolate a… Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0421 An information disclosure vulnerability in the Framework APIs could enable a local malicious application to bypass operating system protections that … Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0424 An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its p… Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0425 An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. Th… Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0426 An information disclosure vulnerability in the Filesystem could enable a local malicious application to access data outside of its permission levels.… Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0448 An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio… Linux Kernel after 7.1.1 Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0413 An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isol… Android Mitigation only Fix from $1,6002017-02-08 MEDIUM 5.5 CVE-2017-0414 An information disclosure vulnerability in AOSP Messaging could enable a local malicious application to bypass operating system protections that isol… Android Mitigation only Fix from $1,6002017-02-08 HIGH 7.5 CVE-2015-8544 NetApp SnapDrive for Windows before 7.0.2P4, 7.0.3, and 7.1 before 7.1.3P1 allows remote attackers to obtain sensitive information via unspecified ve… Snapdrive after 7.1.3 Fix from $1,9502017-02-07 MEDIUM 5.3 CVE-2016-3124 The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors. Simplesamlphp after 1.14.0 Fix from $1,6002017-02-07 HIGH 7.5 CVE-2016-4341 NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors. Clustered Data Ontap after 8.3.2 Fix from $1,9502017-02-07 MEDIUM 5.9 CVE-2016-6495 NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP acces… Data Ontap after 8.2.4 Fix from $1,6002017-02-07 MEDIUM 6.2 CVE-2016-6092 IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user. Security Key Lifecycle Manager Patch available Fix from $1,6002017-02-07 MEDIUM 5.5 CVE-2015-5677 bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secr… FreeBSD Patch available Fix from $1,6002017-02-07 MEDIUM 5.3 CVE-2016-9772 OpenAFS 1.6.19 and earlier allows remote attackers to obtain sensitive directory information via vectors involving the (1) client cache partition, (2… Openafs after 1.6.19 Fix from $1,6002017-02-06 MEDIUM 5.5 CVE-2017-5595 A file disclosure and inclusion vulnerability exists in web/views/file.php in ZoneMinder 1.x through v1.30.0 because of unfiltered user-input being p… Zoneminder after 1.30.0 Fix from $1,6002017-02-06 MEDIUM 5.5 CVE-2017-5550 Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to obtain sensitive information f… Linux Kernel after 4.9.4 Fix from $1,6002017-02-06 MEDIUM 6.4 CVE-2016-0890 EMC PowerPath Virtual (Management) Appliance 2.0, EMC PowerPath Virtual (Management) Appliance 2.0 SP1 is affected by a sensitive information disclos… Powerpath Virtual Appliance No fix yet Fix from $1,6002017-02-03 MEDIUM 5.9 CVE-2016-5935 IBM Jazz for Service Management could allow a remote attacker to obtain sensitive information, caused by the failure to properly validate the SSL cer… Dashboard Application Services Hub Mitigation only Fix from $1,6002017-02-02 MEDIUM 5.3 CVE-2016-6099 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further atta… Security Key Lifecycle Manager Patch available Fix from $1,6002017-02-02 MEDIUM 5.9 CVE-2016-6116 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable … Security Key Lifecycle Manager Patch available Fix from $1,6002017-02-02 MEDIUM 5.3 CVE-2016-8977 IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This information could be used to mount… License Metric Tool Mitigation only Fix from $1,6002017-02-01 MEDIUM 5.3 CVE-2016-8982 IBM InfoSphere Information Server stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties hav… Infosphere Datastage Patch available Fix from $1,6002017-02-01 MEDIUM 5.5 CVE-2016-2941 IBM UrbanCode Deploy creates temporary files during step execution that could contain sensitive information including passwords that could be read by… Urbancode Deploy Mitigation only Fix from $1,6002017-02-01