Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.5 CVE-2016-0793EPSS 16% Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Server) before 10.0.0.Final on … Jboss Wildfly Application Server No fix yet Fix from $1,9502016-04-01 MEDIUM 5.3 CVE-2016-1787 Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors. Mac Os X Server after 5.0.15 Fix from $1,6002016-03-24 MEDIUM 5.4 CVE-2016-1786 The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles HTTP responses with a 3xx (aka redirection) status… Safari after 9.2.1 Fix from $1,6002016-03-24 MEDIUM 6.5 CVE-2016-1785 The Page Loading implementation in WebKit in Apple iOS before 9.3 and Safari before 9.1 mishandles character encoding during access to cached data, w… Safari after 9.2.1 Fix from $1,6002016-03-24 MEDIUM 6.5 CVE-2016-1779 WebKit in Apple iOS before 9.3 and Safari before 9.1 allows remote attackers to bypass the Same Origin Policy and obtain physical-location data via a… Safari after 9.2.1 Fix from $1,6002016-03-24 MEDIUM 6.5 CVE-2015-2286 lms/templates/footer-edx-new.html in Open edX edx-platform before 2015-01-29 does not properly restrict links on the password-reset page, which allow… Open Edx after 2015-01-27 Fix from $1,6002016-03-19 MEDIUM 6.5 CVE-2016-1994 HPE System Management Homepage before 7.5.4 allows remote authenticated users to obtain sensitive information via unspecified vectors. System Management Homepage after 7.5.3.1 Fix from $1,6002016-03-18 MEDIUM 6.5 CVE-2016-1992 HPE ArcSight ESM before 6.8c, and ArcSight ESM Express before 6.9.1, allows remote authenticated users to obtain sensitive information via unspecifie… Enterprise Security Manager after 6.9.0 Fix from $1,6002016-03-17 MEDIUM 6.5 CVE-2016-1967 Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass … Firefox after 44.0.2 Fix from $1,6002016-03-13 MEDIUM 5.5 CVE-2016-0831 The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 201… Android Mitigation only Fix from $1,6002016-03-12 HIGH 7.5 CVE-2016-0829 The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 … Android Mitigation only Fix from $1,9502016-03-12 HIGH 7.5 CVE-2016-0828 The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x bef… Android Mitigation only Fix from $1,9502016-03-12 MEDIUM 5.3 CVE-2016-0825 The Widevine Trusted Application in Android 6.0.1 before 2016-03-01 allows attackers to obtain sensitive TrustZone secure-storage information by leve… Android Mitigation only Fix from $1,6002016-03-12 MEDIUM 5.3 CVE-2016-0824 libmpeg2 in libstagefright in Android 6.x before 2016-03-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified … Android Mitigation only Fix from $1,6002016-03-12 HIGH 7.1 CVE-2016-1360 Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows… Prime Lan Management Solution Mitigation only Fix from $1,9502016-03-12 MEDIUM 5.3 CVE-2015-6485 Schneider Electric Telvent Sage 2300 RTUs with firmware before C3413-500-S01, and LANDAC II-2, Sage 1410, Sage 1430, Sage 1450, Sage 2400, and Sage 3… Telvent Rtu Firmware Mitigation only Fix from $1,6002016-03-12 HIGH 7.5 CVE-2016-1325 The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request… Dpc3939 Wireless Residential Voice Gateway Firmware Mitigation only Fix from $1,9502016-03-09 MEDIUM 5.3 CVE-2016-2845 The Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 49.0.2623.75, does not ignore a URL's path component in th… Chrome after 48.0.2564.116 Fix from $1,6002016-03-06 MEDIUM 6.5 CVE-2016-1637 The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calcul… Chrome after 48.0.2564.116 Fix from $1,6002016-03-06 MEDIUM 5.9 CVE-2016-2244 HP LaserJet printers and MFPs and OfficeJet Enterprise printers with firmware before 3.7.01 allow remote attackers to obtain sensitive information vi… Futuresmart Firmware after 3.7 Fix from $1,6002016-03-04 MEDIUM 5.3 CVE-2016-1357 The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote… Cisco Policy Suite Mitigation only Fix from $1,6002016-03-03 MEDIUM 5.9 CVE-2016-0800EPSS 82% The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef… OpenSSL Mitigation only Fix from $1,6002016-03-01 MEDIUM 5.3 CVE-2016-1342 The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-versi… Secure Firewall Management Center Mitigation only Fix from $1,6002016-02-26 HIGH 7.5 CVE-2015-5267 lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to imp… Moodle after 2.6.11 Fix from $1,9502016-02-22 MEDIUM 5.3 CVE-2016-2044 libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a cr… Fedora Patch available Fix from $1,6002016-02-20 MEDIUM 5.3 CVE-2016-2042 phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) librarie… Fedora Patch available Fix from $1,6002016-02-20 MEDIUM 5.3 CVE-2016-2039 libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token v… Fedora Patch available Fix from $1,6002016-02-20 MEDIUM 5.3 CVE-2016-2038 phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafte… Fedora Patch available Fix from $1,6002016-02-20 MEDIUM 5.3 CVE-2016-2509 The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP co… Hirschmann Firmware after 09.0.05 Fix from $1,6002016-02-18 HIGH 7.5 CVE-2015-8148 The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about admi… Encryption Management Server after 3.3.2 Fix from $1,9502016-02-18