Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2015-0844 The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1)… Fedora Mitigation only Fix from $1,6002015-04-14 MEDIUM 5.0 CVE-2015-2935 MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user … Mediawiki after 1.19.23 Fix from $1,6002015-04-13 MEDIUM 5.0 CVE-2015-1148 Screen Sharing in Apple OS X before 10.10.3 stores the password of a user in a log file, which might allow context-dependent attackers to obtain sens… Mac Os X after 10.10.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1147 Open Directory Client in Apple OS X before 10.10.3 sends unencrypted password-change requests in certain circumstances involving missing certificates… Mac Os X 10.10.3+ Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1128 The private-browsing implementation in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 allows attackers to obtain sensitive browsin… Safari after 6.2.4 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1112 Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5, as used on iOS before 8.3 and other platforms, does not properly delete browsing-h… Safari after 8.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1111 Safari in Apple iOS before 8.3 does not delete Recently Closed Tabs data in response to a history-clearing action, which allows attackers to obtain s… Iphone Os after 8.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1110 The Podcasts component in Apple iOS before 8.3 and Apple TV before 7.2 allows remote attackers to discover unique identifiers by reading asset-downlo… Iphone Os after 8.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1090 CFNetwork in Apple iOS before 8.3 does not delete HTTP Strict Transport Security (HSTS) state information in response to a Safari history-clearing ac… Iphone Os after 8.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-1089 CFNetwork in Apple iOS before 8.3 and Apple OS X before 10.10.3 does not properly handle cookies during processing of redirects in HTTP responses, wh… Mac Os X after 10.10.2 Fix from $1,6002015-04-10 MEDIUM 5.0 CVE-2015-0991 Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message about an unhandled exception,… Ignition Mitigation only Fix from $1,6002015-04-03 MEDIUM 5.0 CVE-2015-0902 The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Me… All In One Seo Pack after 2.2.5.1 Fix from $1,6002015-04-03 HIGH 9.0 CVE-2014-5405 Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypas… Mednet after 5.8 Fix from $1,9502015-04-03 MEDIUM 5.0 CVE-2015-2817 The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Secu… Netweaver No fix yet Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2015-0800 The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for quer… Firefox after 36.0.4 Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2015-2809 The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently responds to unicast queries with source addresses t… Diskstation Manager after 3.0 Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2015-1892 The Multicast DNS (mDNS) responder in IBM Security Access Manager for Web 7.x before 7.0.0 FP12 and 8.x before 8.0.1 FP1 inadvertently responds to un… Security Access Manager For Web 7.0 Firmware after 7.0.0.11 Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2015-0997 Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 provide an HMI user int… Aveva Edge 7.1 / 7.1.3.4+ Fix from $1,6002015-03-29 MEDIUM 5.0 CVE-2014-5427 Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Cont… Metsys Mitigation only Fix from $1,6002015-03-29 MEDIUM 5.0 CVE-2015-2771 The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain … Triton Ap Email after 7.8.3 Fix from $1,6002015-03-27 MEDIUM 5.0 CVE-2015-2762 Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication. Triton Ap Web after 7.8.3 Fix from $1,6002015-03-27 MEDIUM 5.0 CVE-2015-2748 Websense TRITON AP-WEB before 8.0.0 does not properly restrict access to files in explorer_wse/, which allows remote attackers to obtain sensitive in… Triton Ap Data after 7.8.3 Fix from $1,6002015-03-26 MEDIUM 5.0 CVE-2015-2335 A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors. Mybb after 1.8.3 Fix from $1,6002015-03-18 MEDIUM 5.0 CVE-2015-0089EPSS 21% Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,… Windows 7 Patch available Fix from $1,6002015-03-11 MEDIUM 5.0 CVE-2015-0087EPSS 23% Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1,… Windows 7 Patch available Fix from $1,6002015-03-11 MEDIUM 5.0 CVE-2015-2184EPSS 8% ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls the phpinfo function. Zeuscart No fix yet Fix from $1,6002015-03-10 MEDIUM 5.0 CVE-2014-8105 389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows r… Fedora after 1.3.2.26 Fix from $1,6002015-03-10 MEDIUM 5.0 CVE-2015-2206 libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values … Fedora Patch available Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2015-1165 RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket… Debian Linux Mitigation only Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2015-2214 NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php. Netcat after 5.01 Fix from $1,6002015-03-05