Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
HIGH 7.8 CVE-2015-7910 Exemys Telemetry Web Server relies on an HTTP Location header to indicate that a client is unauthorized, which allows remote attackers to bypass inte… Telemetry Web Server Mitigation only Fix from $1,9502015-11-19 MEDIUM 5.0 CVE-2015-6368 Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote attackers to read files via a crafted HTTP request, ak… Firepower Extensible Operating System Mitigation only Fix from $1,6002015-11-19 MEDIUM 5.0 CVE-2015-7998 The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.1… Netscaler Service Delivery Appliance Service Vm Patch available Fix from $1,6002015-11-17 MEDIUM 5.0 CVE-2015-7996 The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 1… Netscaler Application Delivery Controller Firmware Patch available Fix from $1,6002015-11-17 MEDIUM 5.0 CVE-2015-5276 The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking so… Gcc 4.9.4+ Fix from $1,6002015-11-17 MEDIUM 5.0 CVE-2015-7427 IBM DataPower Gateway appliances with firmware 6.x before 6.0.0.17, 6.0.1.x before 6.0.1.17, 7.x before 7.0.0.10, 7.1.0.x before 7.1.0.7, and 7.2.x b… Datapower Gateway after 6.0.0.16 Fix from $1,6002015-11-14 MEDIUM 5.0 CVE-2015-6364 Cisco Content Delivery System Manager Software 3.2 on Videoscape Distribution Suite Service Manager allows remote attackers to obtain sensitive infor… Videoscape Distribution Suite Service Manager after 3.2.0 Fix from $1,6002015-11-14 MEDIUM 5.0 CVE-2015-7991 The Web Dispatcher service in SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to read web dispatcher and security trace files an… Hana No fix yet Fix from $1,6002015-11-10 MEDIUM 5.0 CVE-2015-8005 MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote at… Mediawiki after 1.23.10 Fix from $1,6002015-11-09 MEDIUM 5.0 CVE-2015-8095 The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not properly remove nodes from view, which allows remote… Monster Menus Patch available Fix from $1,6002015-11-09 MEDIUM 5.0 CVE-2015-7940 The Bouncy Castle Java library before 1.51 does not validate a point is withing the elliptic curve, which makes it easier for remote attackers to obt… Leap after 1.50 Fix from $1,6002015-11-09 MEDIUM 5.0 CVE-2015-5730EPSS 7% The sanitize_widget_instance function in wp-includes/class-wp-customize-widgets.php in WordPress before 4.2.4 does not use a constant-time comparison… WordPress after 4.2.3 Fix from $1,6002015-11-09 MEDIUM 5.0 CVE-2015-5015 IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST UR… Websphere Commerce Enterprise after 7.0.0.9 Fix from $1,6002015-11-08 MEDIUM 5.0 CVE-2015-1999 IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 places session IDs in https URLs, which allows remote attackers to obtain sensitive… Security Qradar Incident Forensics Mitigation only Fix from $1,6002015-11-08 MEDIUM 5.0 CVE-2015-1994 IBM Security QRadar Incident Forensics 7.2.x before 7.2.5 Patch 5 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, w… Security Qradar Incident Forensics Mitigation only Fix from $1,6002015-11-08 MEDIUM 5.0 CVE-2015-8081 The Field as Block module 7.x-1.x before 7.x-1.4 for Drupal might allow remote attackers to obtain sensitive field information by reading a cached bl… Field As Block Patch available Fix from $1,6002015-11-06 MEDIUM 5.0 CVE-2015-7763 rx/rx.c in OpenAFS 1.5.75 through 1.5.78, 1.6.x before 1.6.15, and 1.7.x before 1.7.33 does not properly initialize padding at the end of an Rx ackno… Openafs Mitigation only Fix from $1,6002015-11-06 MEDIUM 5.0 CVE-2015-7762 rx/rx.c in OpenAFS before 1.6.15 and 1.7.x before 1.7.33 does not properly initialize the padding of a data structure when constructing an Rx acknowl… Debian Linux after 1.6.14.1 Fix from $1,6002015-11-06 MEDIUM 5.0 CVE-2015-7195 The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which al… Firefox after 41.0.2 Fix from $1,6002015-11-05 MEDIUM 5.0 CVE-2015-7190 The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access thi… Firefox after 41.0.2 Fix from $1,6002015-11-05 MEDIUM 5.0 CVE-2015-6355 The web interface in Cisco Unified Computing System (UCS) 2.2(5b)A on blade servers allows remote attackers to obtain potentially sensitive version i… Unified Computing System Mitigation only Fix from $1,6002015-11-04 MEDIUM 5.0 CVE-2015-8074 mediaserver in Android before 5.1.1 LMY48X allows remote attackers to obtain sensitive information, and consequently bypass an unspecified protection… Android after 5.1 Fix from $1,6002015-11-03 MEDIUM 5.0 CVE-2015-6611 mediaserver in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows remote attackers to obtain sensitive information, and consequently bypass… Android 5.1.1+ Fix from $1,6002015-11-03 MEDIUM 5.0 CVE-2015-7859 The com_contenthistory component in Joomla! 3.2 before 3.4.5 does not properly check ACLs, which allows remote attackers to obtain sensitive informat… Joomla\! Mitigation only Fix from $1,6002015-10-29 MEDIUM 5.0 CVE-2015-7902 Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different error messages for failed login attempts in unspecifie… Mango Automation Patch available Fix from $1,6002015-10-28 MEDIUM 5.0 CVE-2015-5713 Spotfire Parsing Library and Spotfire Security Filter in TIBCO Spotfire Server 5.5.x before 5.5.4, 6.0.x before 6.0.5, 6.5.x before 6.5.4, and 7.0.x … Spotfire Server after 7.0.1 Fix from $1,6002015-10-28 MEDIUM 5.0 CVE-2015-3969 Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to obtain sensitive network-connection information via a request to UDP port (… Umg 508 Patch available Fix from $1,6002015-10-28 MEDIUM 5.0 CVE-2015-5223 OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that refer… Swift after 2.3.0 Fix from $1,6002015-10-26 MEDIUM 6.4 CVE-2015-5288 The crypt function in contrib/pgcrypto in PostgreSQL before 9.0.23, 9.1.x before 9.1.19, 9.2.x before 9.2.14, 9.3.x before 9.3.10, and 9.4.x before 9… PostgreSQL after 9.0.22 Fix from $1,6002015-10-26 MEDIUM 5.0 CVE-2015-6843 Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to… Sourceone Email Supervisor after 7.1 Fix from $1,6002015-10-18