Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2017-5372 The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system informati… Netweaver No fix yet Fix from $1,9502017-01-23 HIGH 7.5 CVE-2016-6668 The Atlassian Hipchat Integration Plugin for Bitbucket Server 6.26.0 before 6.27.5, 6.28.0 before 7.3.7, and 7.4.0 before 7.8.17; Confluence HipChat … Confluence Server No fix yet Fix from $1,9502017-01-23 HIGH 7.5 CVE-2017-5182 Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that … Open Enterprise Server Mitigation only Fix from $1,9502017-01-23 HIGH 7.5 CVE-2016-10143 A vulnerability in Tiki Wiki CMS 15.2 could allow a remote attacker to read arbitrary files on a targeted system via a crafted pathname in a banner U… Tikiwiki Cms\/groupware Patch available Fix from $1,9502017-01-20 MEDIUM 5.3 CVE-2016-5012 In Moodle 3.x, glossary search displays entries without checking user permissions to view them. Moodle Patch available Fix from $1,6002017-01-20 MEDIUM 5.4 CVE-2016-5014 In Moodle 2.x and 3.x, an unenrolled user still receives event monitor notifications even though they can no longer access the course. Moodle Patch available Fix from $1,6002017-01-20 MEDIUM 6.5 CVE-2016-5201 A leak of privateClass in the extensions API in Google Chrome prior to 54.0.2840.100 for Linux, and 54.0.2840.99 for Windows, and 54.0.2840.98 for Ma… Chrome after 54.0.2840.87 Fix from $1,6002017-01-19 MEDIUM 6.5 CVE-2016-5212 Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android insufficiently sanitized DevTools URLs, which allowed a … Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 MEDIUM 6.5 CVE-2016-5220 PDFium in Google Chrome prior to 55.0.2883.75 for Mac, Windows and Linux, and 55.0.2883.84 for Android incorrectly handled navigation within PDFs, wh… Chrome after 54.0.2840.99 Fix from $1,6002017-01-19 HIGH 7.5 CVE-2016-9680 Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors. Provisioning Services Mitigation only Fix from $1,9502017-01-18 MEDIUM 5.3 CVE-2016-9677 Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors. Provisioning Services Mitigation only Fix from $1,6002017-01-18 MEDIUM 5.5 CVE-2017-5223 An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an em… Phpmailer after 5.2.21 Fix from $1,6002017-01-16 HIGH 7.1 CVE-2017-2584 arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel memory or cause a denial of s… Linux Kernel after 4.9.3 Fix from $1,9502017-01-15 MEDIUM 5.3 CVE-2017-5487EPSS 87% wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before 4.7.1 does not properly rest… WordPress after 4.7 Fix from $1,6002017-01-15 MEDIUM 5.5 CVE-2017-0398 An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. Th… Android Mitigation only Fix from $1,6002017-01-13 MEDIUM 5.9 CVE-2016-6887 The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred… Matrixssl after 3.8.6 Fix from $1,6002017-01-13 MEDIUM 5.9 CVE-2016-8671 The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred… Matrixssl after 3.8.6 Fix from $1,6002017-01-13 HIGH 7.5 CVE-2016-9107 The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecifi… Gajim Otr Patch available Fix from $1,9502017-01-13 MEDIUM 5.5 CVE-2016-10135 An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5… Lg Mobile Mitigation only Fix from $1,6002017-01-13 HIGH 7.5 CVE-2016-10140EPSS 7% Information disclosure and authentication bypass vulnerability exists in the Apache HTTP Server configuration bundled with ZoneMinder v1.30 and v1.29… Zoneminder Patch available Fix from $1,9502017-01-13 HIGH 8.1 CVE-2016-3130 An information disclosure vulnerability in the Core and Management Console in BlackBerry Enterprise Server (BES) 12 through 12.5.2 allows remote atta… Enterprise Service Mitigation only Fix from $1,9502017-01-13 CRITICAL 9.8 CVE-2016-3152 Barco ClickShare CSC-1 devices with firmware before 01.09.03 allow remote attackers to obtain the root password by downloading and extracting the fir… Clickshare Csc 1 Firmware after 01.09.02.03 Fix from $2,3002017-01-12 MEDIUM 5.5 CVE-2017-0388 An elevation of privilege vulnerability in the External Storage Provider could enable a local secondary user to read data from an external storage SD… Android Mitigation only Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0396 An information disclosure vulnerability in visualizer/EffectVisualizer.cpp in libeffects in Mediaserver could enable a local malicious application to… Android Patch available Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0397 An information disclosure vulnerability in id3/ID3.cpp in libstagefright in Mediaserver could enable a local malicious application to access data out… Android Patch available Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0399 An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca… Android after 7.1.1 Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0400 An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio… Android Patch available Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0401 An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in the Qualcomm audio post processor could enable a loca… Android after 7.1.1 Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2017-0402 An information disclosure vulnerability in lvm/wrapper/Bundle/EffectBundle.cpp in libeffects in Audioserver could enable a local malicious applicatio… Android after 7.1.1 Fix from $1,6002017-01-12 MEDIUM 5.5 CVE-2016-8460 An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permissio… Linux Kernel Mitigation only Fix from $1,6002017-01-12