Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.3 CVE-2016-2388 KEVEPSS 52% The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user information via a crafted HTTP req… Netweaver Application Server Java after 7.50 Fix from $1,6002016-02-16 MEDIUM 5.8 CVE-2016-1321 Cisco Universal Small Cell devices with firmware R2.12 through R3.5 contain an image-decryption key in flash memory, which allows remote attackers to… Universal Small Cell Firmware Mitigation only Fix from $1,6002016-02-15 MEDIUM 5.3 CVE-2015-7444 The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to… Websphere Commerce Patch available Fix from $1,6002016-02-15 MEDIUM 5.9 CVE-2015-3197EPSS 11% ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m… OpenSSL Patch available Fix from $1,6002016-02-15 MEDIUM 5.3 CVE-2015-2005 IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attacker… Qradar Security Information And Event Manager Mitigation only Fix from $1,6002016-02-15 HIGH 8.1 CVE-2016-1526 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before… Debian Linux after 38.5.1 Fix from $1,9502016-02-13 MEDIUM 5.3 CVE-2016-0864 Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitiv… Smartgrid Lighthouse Sensor Management System after 5.0 Fix from $1,6002016-02-13 HIGH 7.5 CVE-2016-0958 Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object. Experience Manager Patch available Fix from $1,9502016-02-10 HIGH 7.5 CVE-2016-0956EPSS 46% The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows remote attackers to obtain sen… Sling Patch available Fix from $1,9502016-02-10 MEDIUM 5.3 CVE-2015-7680 Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allo… Moveit Dmz after 8.1 Fix from $1,6002016-02-10 MEDIUM 6.5 CVE-2015-7675 The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authoriz… Moveit Dmz after 8.1 Fix from $1,6002016-02-10 HIGH 7.5 CVE-2016-0047EPSS 21% WinForms in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 allows remote attackers to obtain sensitive information from process … .net Framework Mitigation only Fix from $1,9502016-02-10 MEDIUM 5.3 CVE-2016-1319 Cisco Unified Communications Manager (aka CallManager) 9.1(2.10000.28), 10.5(2.10000.5), 10.5(2.12901.1), and 11.0(1.10000.10); Unified Communication… Opensolaris 2.50+ Fix from $1,6002016-02-09 MEDIUM 5.3 CVE-2016-1316 Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction with Jabber Guest, allows remote attackers to obtain se… Telepresence Video Communication Server Software Mitigation only Fix from $1,6002016-02-09 MEDIUM 6.8 CVE-2016-0723 Race condition in the tty_ioctl function in drivers/tty/tty_io.c in the Linux kernel through 4.4.1 allows local users to obtain sensitive information… Linux Kernel after 4.4.1 Fix from $1,6002016-02-08 HIGH 7.5 CVE-2016-0811 Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows … Android Mitigation only Fix from $1,9502016-02-07 CRITICAL 9.8 CVE-2015-7915 Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffin… Moduweb Vision after 1.5.5 Fix from $2,3002016-02-06 MEDIUM 6.5 CVE-2016-0862EPSS 10% General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to obtain sensitive… Snmp\/web Adapter Firmware after 4.7 Fix from $1,6002016-02-05 MEDIUM 5.4 CVE-2016-1730 WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by operating a crafted captive portal. Iphone Os after 9.2 Fix from $1,6002016-02-01 MEDIUM 5.3 CVE-2016-1939 Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive informati… Firefox after 43.0.4 Fix from $1,6002016-01-31 HIGH 7.5 CVE-2016-0867 CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request. Plantvisor Enhanced Mitigation only Fix from $1,9502016-01-30 MEDIUM 5.3 CVE-2015-8792 The KaxInternalBlock::ReadData function in libMatroska before 1.4.4 allows context-dependent attackers to obtain sensitive information from process h… Libmatroska after 1.4.3 Fix from $1,6002016-01-29 HIGH 7.5 CVE-2015-8618 The Int.Exp Montgomery code in the math/big library in Go 1.5.x before 1.5.3 mishandles carry propagation and produces incorrect output, which makes … Go Patch available Fix from $1,9502016-01-27 MEDIUM 5.9 CVE-2015-7488 IBM Spectrum Scale 4.1.1.x before 4.1.1.4 and 4.2.x before 4.2.0.1, in certain LDAP File protocol configurations, allows remote attackers to discover… Spectrum Scale Mitigation only Fix from $1,6002016-01-27 HIGH 8.0 CVE-2016-1489 Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) ob… Shareit after 3.0.18_ww Fix from $1,9502016-01-26 MEDIUM 6.5 CVE-2016-1618 Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, whi… Chrome after 47.0.2526.106 Fix from $1,6002016-01-25 MEDIUM 5.9 CVE-2016-0201 GSKit in IBM Security Network Protection 5.3.1 before 5.3.1.7 and 5.3.2 allows remote attackers to discover credentials by triggering an MD5 collisio… Security Network Protection Firmware Patch available Fix from $1,6002016-01-18 HIGH 7.5 CVE-2015-7470 Report Builder in IBM Jazz Reporting Service (JRS) 5.x before 5.0.2-Rational-CLM-ifix011 and 6.0 before 6.0.0-Rational-CLM-ifix005 allows man-in-the-… Jazz Reporting Service Patch available Fix from $1,9502016-01-17 MEDIUM 5.3 CVE-2016-1295 Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote attackers to obtain sensitive information via an AnyConnect authentication attempt… Adaptive Security Appliance Software Mitigation only Fix from $1,6002016-01-16 MEDIUM 5.3 CVE-2016-1910EPSS 6% The User Management Engine (UME) in SAP NetWeaver 7.4 allows attackers to decrypt unspecified data via unknown vectors, aka SAP Security Note 2191290. Netweaver No fix yet Fix from $1,6002016-01-15