Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 6.5 CVE-2016-6827 Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive inform… Fusioncompute Mitigation only Fix from $1,6002016-09-26 MEDIUM 6.8 CVE-2016-5972 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 uses weak permissions for unspecified resources, which allows… Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,6002016-09-26 HIGH 7.1 CVE-2016-5971 IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or … Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,9502016-09-26 MEDIUM 6.5 CVE-2016-5970 Directory traversal vulnerability in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authentica… Security Privileged Identity Manager Virtual Appliance after 2.0.2 Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-5946 Directory traversal vulnerability in IBM Spectrum Control (formerly Tivoli Storage Productivity Center) 5.2.x before 5.2.11 allows remote authenticat… Spectrum Control Patch available Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-2999 IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unsp… Connections after 5.5.0.0 Fix from $1,6002016-09-26 MEDIUM 6.5 CVE-2016-5172 The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive informat… Chrome after 53.0.2785.101 Fix from $1,6002016-09-25 MEDIUM 5.5 CVE-2016-4771 The kernel in Apple iOS before 10 and OS X before 10.12 allows local users to bypass intended file-access restrictions via a crafted directory pathna… Iphone Os after 10.11.6 Fix from $1,6002016-09-25 MEDIUM 6.5 CVE-2016-4758 WebKit in Apple iOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 does not properly restrict access to the location variable, whic… Safari after 12.4.3 Fix from $1,6002016-09-25 MEDIUM 5.5 CVE-2016-4755 Terminal in Apple OS X before 10.12 uses weak permissions for the .bash_history and .bash_session files, which allows local users to obtain sensitive… Mac Os X after 10.11.6 Fix from $1,6002016-09-25 MEDIUM 5.5 CVE-2016-4752 The SecKeyDeriveFromPassword function in Apple OS X before 10.12 does not use the CF_RETURNS_RETAINED keyword, which allows attackers to obtain sensi… Mac Os X after 10.11.6 Fix from $1,6002016-09-25 MEDIUM 5.3 CVE-2016-4745 The Kerberos 5 (aka krb5) PAM module in Apple OS X before 10.12 does not use constant-time operations for determining username validity, which makes … Mac Os X after 10.11.6 Fix from $1,6002016-09-25 MEDIUM 5.5 CVE-2016-4742 NSSecureTextField in Apple OS X before 10.12 does not enable Secure Input, which allows attackers to discover credentials via a crafted app. Mac Os X after 10.11.6 Fix from $1,6002016-09-25 MEDIUM 5.3 CVE-2016-4713 CoreDisplay in Apple OS X before 10.12 allows attackers to view arbitrary users' screens by leveraging screen-sharing access. Mac Os X after 10.11.6 Fix from $1,6002016-09-25 HIGH 7.5 CVE-2016-4711 CCrypt in corecrypto in CommonCrypto in Apple iOS before 10 and OS X before 10.12 allows attackers to discover cleartext information by leveraging a … Iphone Os after 10.11.6 Fix from $1,9502016-09-25 MEDIUM 6.5 CVE-2016-4708 CFNetwork in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 misparses the Set-Cookie header, which allows remote attack… Iphone Os 3.0 / 10.0+ Fix from $1,6002016-09-25 MEDIUM 6.5 CVE-2016-5282 Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive informa… Firefox after 48.0.2 Fix from $1,6002016-09-22 MEDIUM 6.5 CVE-2016-4968 The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to discover administra… Fortiwan after 4.2.4 Fix from $1,6002016-09-21 MEDIUM 6.5 CVE-2016-4967 Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sensitive information from (1) a backup of the devic… Fortiwan after 4.2.4 Fix from $1,6002016-09-21 HIGH 8.6 CVE-2016-0904 Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 use the same encryption key across different customers… Avamar Server after 7.3.0 Fix from $1,9502016-09-21 CRITICAL 9.1 CVE-2016-0903 Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233 rely on client-side authentication, which allows remot… Avamar Server after 7.3.0 Fix from $2,3002016-09-21 HIGH 7.5 CVE-2016-6537 AVer Information EH6108H+ devices with firmware X9.03.24.00.07l store passwords in a cleartext base64 format and require cleartext credentials in HTT… Eh6108h\+ Firmware Mitigation only Fix from $1,9502016-09-19 HIGH 7.5 CVE-2016-6415 KEVEPSS 87% The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x and 5.0.x through 5.2.x, and… iOS 5.3.0+ Fix from $1,9502016-09-19 MEDIUM 5.3 CVE-2016-0870 The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request. Tracer Sc after 4.2.1134 Fix from $1,6002016-09-19 MEDIUM 5.3 CVE-2016-4746 The Keyboards component in Apple iOS before 10 does not properly use a cache for auto-correct suggestions, which allows remote attackers to obtain se… Iphone Os after 9.3.5 Fix from $1,6002016-09-18 MEDIUM 5.5 CVE-2016-4719 The GeoServices component in Apple iOS before 10 and watchOS before 3 does not properly restrict access to PlaceData information, which allows attack… Watchos after 9.3.5 Fix from $1,6002016-09-18 HIGH 7.5 CVE-2016-0929 The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might al… Rabbitmq Mitigation only Fix from $1,9502016-09-18 MEDIUM 5.3 CVE-2016-6644 EMC Documentum D2 4.5 before patch 15 and 4.6 before patch 03 allows remote attackers to read arbitrary Docbase documents by leveraging knowledge of … Documentum D2 after 4.6 Fix from $1,6002016-09-17 MEDIUM 5.9 CVE-2016-7420 Crypto++ (aka cryptopp) through 5.6.4 does not document the requirement for a compile-time NDEBUG definition disabling the many assert calls that are… Crypto\+\+ after 5.6.4 Fix from $1,6002016-09-16 HIGH 7.5 CVE-2016-6936 Adobe AIR SDK & Compiler before 23.0.0.257 on Windows does not support Android runtime-analytics transport security, which might allow remote attacke… Air Sdk \& Compiler Mitigation only Fix from $1,9502016-09-16