Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.5 CVE-2016-2415 exchange/eas/EasAutoDiscover.java in the Autodiscover implementation in Exchange ActiveSync in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.… Android Mitigation only Fix from $1,6002016-04-18 HIGH 7.5 CVE-2015-5271 The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift)… Openstack Patch available Fix from $1,9502016-04-15 MEDIUM 5.3 CVE-2016-1378 Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to… iOS Mitigation only Fix from $1,6002016-04-14 MEDIUM 5.9 CVE-2016-0787 The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in… Fedora after 1.6.0 Fix from $1,6002016-04-13 MEDIUM 5.9 CVE-2016-0739 libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange me… Enterprise Linux after 0.7.2 Fix from $1,6002016-04-13 MEDIUM 5.9 CVE-2016-3686 The Single Sign-On (SSO) feature in F5 BIG-IP APM 11.x before 11.6.0 HF6 and BIG-IP Edge Gateway 11.0.0 through 11.3.0 might allow remote attackers t… Big Ip Edge Gateway Mitigation only Fix from $1,6002016-04-13 HIGH 7.4 CVE-2016-2084 F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2… Big Iq Security Mitigation only Fix from $1,9502016-04-13 HIGH 7.5 CVE-2016-2055EPSS 18% xymond/xymond.c in xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote attackers to read arbitrary files in the configuration director… Debian Linux Patch available Fix from $1,9502016-04-13 HIGH 8.6 CVE-2015-8555 Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended… Xenserver Patch available Fix from $1,9502016-04-13 MEDIUM 6.5 CVE-2015-8553 Xen allows guest OS users to obtain sensitive information from uninitialized locations in host OS kernel memory by not enabling memory and I/O decodi… Enterprise Linux Patch available Fix from $1,6002016-04-13 HIGH 7.5 CVE-2016-1035 Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors. Robohelp Mitigation only Fix from $1,9502016-04-12 MEDIUM 5.9 CVE-2016-0887 EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE… Bsafe Crypto C Micro Edition 2.8.9 / 4.1.5+ Fix from $1,6002016-04-12 HIGH 7.1 CVE-2016-0090 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS memory vi… Windows 10 Mitigation only Fix from $1,9502016-04-12 HIGH 7.1 CVE-2016-0089 Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to obtain sensitive information from host OS … Windows 10 Mitigation only Fix from $1,9502016-04-12 MEDIUM 5.3 CVE-2016-3170 The "have you forgotten your password" links in the User module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allow remote attackers to obtain sensi… Debian Linux Patch available Fix from $1,6002016-04-12 MEDIUM 6.5 CVE-2016-2166 The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 i… Qpid Proton after 0.12.0 Fix from $1,6002016-04-12 MEDIUM 5.3 CVE-2016-2140 The libvirt driver in OpenStack Compute (Nova) before 2015.1.4 (kilo) and 12.0.x before 12.0.3 (liberty), when using raw storage and use_cow_images i… Nova 12.0.3 / 2015.1.4+ Fix from $1,6002016-04-12 MEDIUM 5.3 CVE-2015-8537 app/views/journals/index.builder in Redmine before 2.6.9, 3.0.x before 3.0.7, and 3.1.x before 3.1.3 allows remote attackers to obtain sensitive info… Debian Linux after 2.6.8 Fix from $1,6002016-04-12 MEDIUM 5.3 CVE-2015-7528 Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name. Kubernetes after 1.2.0 Fix from $1,6002016-04-11 MEDIUM 5.1 CVE-2015-7502 Red Hat CloudForms 3.2 Management Engine (CFME) 5.4.4 and CloudForms 4.0 Management Engine (CFME) 5.5.0 do not properly encrypt data in the backend P… Cloudforms Management Engine Mitigation only Fix from $1,6002016-04-11 MEDIUM 5.3 CVE-2014-9759 Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obta… Mantisbt Patch available Fix from $1,6002016-04-11 HIGH 7.5 CVE-2016-2164EPSS 7% The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-0783EPSS 7% The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attacke… Openmeetings after 3.1.0 Fix from $1,9502016-04-11 MEDIUM 6.2 CVE-2015-5969 The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 4… Leap Mitigation only Fix from $1,6002016-04-08 CRITICAL 9.8 CVE-2016-0791 Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify CSRF tokens, which makes it easier for remote attackers to… Openshift after 1.649 Fix from $2,3002016-04-07 MEDIUM 5.3 CVE-2016-0790 Jenkins before 1.650 and LTS before 1.642.2 do not use a constant-time algorithm to verify API tokens, which makes it easier for remote attackers to … Jenkins after 1.649 Fix from $1,6002016-04-07 MEDIUM 5.9 CVE-2015-2774 Erlang/OTP before 18.0-rc1 does not properly check CBC padding bytes when terminating connections, which makes it easier for man-in-the-middle attack… Erlang\/otp after 18.0 Fix from $1,6002016-04-07 MEDIUM 5.3 CVE-2016-3973 The chat feature in the Real-Time Collaboration (RTC) services 7.3 and 7.4 in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to obtain… Netweaver Application Server Java after 7.50 Fix from $1,6002016-04-07 MEDIUM 6.8 CVE-2016-1563 NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof ser… Clustered Data Ontap Mitigation only Fix from $1,6002016-04-07 HIGH 7.5 CVE-2016-0871 Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a… Eg2 Web Control after 4.04p Fix from $1,9502016-04-06