Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2015-2209 DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php. Dlguard Mitigation only Fix from $1,6002015-03-04 MEDIUM 5.0 CVE-2015-2076 The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note … Businessobjects Edge No fix yet Fix from $1,6002015-02-27 MEDIUM 5.0 CVE-2015-2077 The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qu… Redirector Sdk No fix yet Fix from $1,6002015-02-24 MEDIUM 5.0 CVE-2014-6115 IBM Rational Insight 1.1.1.5 allows remote attackers to bypass authentication and obtain sensitive information via a crafted request to a Jazz Report… Rational Insight Patch available Fix from $1,6002015-02-24 MEDIUM 5.0 CVE-2015-0628 The proxy engine on Cisco Web Security Appliance (WSA) devices allows remote attackers to bypass intended proxying restrictions via a malformed HTTP … Web Security Appliance Mitigation only Fix from $1,6002015-02-20 MEDIUM 5.0 CVE-2014-9423 The svcauth_gss_accept_sec_context function in lib/rpc/svc_auth_gss.c in MIT Kerberos 5 (aka krb5) 1.11.x through 1.11.5, 1.12.x through 1.12.2, and … Kerberos 5 Patch available Fix from $1,6002015-02-19 MEDIUM 5.0 CVE-2014-6304 The Form Controls CSS file in PNMsoft Sequence Kinetics before 7.7 allows remote attackers to obtain sensitive source-code information via unspecifie… Sequence Kinetics after 7.5 Fix from $1,6002015-02-19 MEDIUM 5.0 CVE-2014-7883EPSS 37% HP Universal CMDB (UCMDB) Probe 9.05, 10.01, and 10.11 enables the HTTP TRACE method, which allows remote attackers to obtain sensitive information b… Universal Configuration Management Database Mitigation only Fix from $1,6002015-02-15 MEDIUM 6.4 CVE-2015-0255 X.Org Server (aka xserver and xorg-server) before 1.16.3 and 1.17.x before 1.17.1 allows remote attackers to obtain sensitive information from proces… X Server after 1.16.3 Fix from $1,6002015-02-13 MEDIUM 5.0 CVE-2014-0154 oVirt Engine before 3.5.0 does not include the HTTPOnly flag in a Set-Cookie header for the session IDs, which makes it easier for remote attackers t… Ovirt after 3.4.4 Fix from $1,6002015-02-13 MEDIUM 5.0 CVE-2014-4781 The alert module in IBM InfoSphere BigInsights 2.1.2 and 3.x before 3.0.0.2 allows remote attackers to obtain sensitive Alert management-services API… Infosphere Biginsights Patch available Fix from $1,6002015-02-13 MEDIUM 5.0 CVE-2015-0602 The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by s… Unified Ip Phones 9900 Series Firmware after 9.4 Fix from $1,6002015-02-07 MEDIUM 5.0 CVE-2015-1482EPSS 9% Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connect… Tower after 2.0.4 Fix from $1,6002015-02-04 MEDIUM 5.0 CVE-2014-9046 The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrar… Owncloud after 5.0.17 Fix from $1,6002015-02-04 MEDIUM 5.0 CVE-2014-9044 Asset Pipeline in ownCloud 7.x before 7.0.3 uses an MD5 hash of the absolute file paths of the original CSS and JS files as the name of the concatena… Owncloud Server Mitigation only Fix from $1,6002015-02-04 MEDIUM 5.0 CVE-2015-1357 Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmwa… Ruggedcom Firmware Mitigation only Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2015-0597 The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via c… Webex Meetings Server after 1.5 Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2015-0595 The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages … Webex Meetings Server after 1.5 Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2014-6170 The HTTPInput node in IBM WebSphere Message Broker 7.0 before 7.0.0.8 and 8.0 before 8.0.0.6 and IBM Integration Bus 9.0 before 9.0.0.4 allows remote… Integration Bus Mitigation only Fix from $1,6002015-02-02 MEDIUM 5.0 CVE-2014-8839 Spotlight in Apple OS X before 10.10.2 does not enforce the Mail "Load remote content in messages" configuration, which allows remote attackers to di… Mac Os X after 10.10.1 Fix from $1,6002015-01-30 MEDIUM 5.0 CVE-2014-4491 The extension APIs in the kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 do not prevent the presence of addre… Iphone Os after 10.10.1 Fix from $1,6002015-01-30 HIGH 7.8 CVE-2015-0310 KEVEPSS 15% Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly r… Flash Player 11.2.202.438 / 13.0.0.262+ Fix from $1,9502015-01-23 MEDIUM 5.0 CVE-2015-1306 The newsletter posting area in the web interface in Sympa 6.0.x before 6.0.10 and 6.1.x before 6.1.24 allows remote attackers to read arbitrary files… Sympa Patch available Fix from $1,6002015-01-22 MEDIUM 6.8 CVE-2014-8008EPSS 8% Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) allows remote authen… Unified Communications Manager Mitigation only Fix from $1,6002015-01-22 MEDIUM 5.0 CVE-2015-0514EPSS 8% EMC M&R (aka Watch4Net) before 6.5u1 and ViPR SRM before 3.6.1 might allow remote attackers to obtain cleartext data-center discovery credentials by … Watch4net after 6.5 Fix from $1,6002015-01-21 MEDIUM 5.0 CVE-2014-6172 IBM API Management 3.0 before 3.0.4.0 IF1 allows remote attackers to obtain sensitive analytics information in an encrypted form via unspecified vect… Api Management Patch available Fix from $1,6002015-01-21 MEDIUM 5.0 CVE-2015-0590 Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providi… Webex Meeting Center Mitigation only Fix from $1,6002015-01-17 MEDIUM 5.0 CVE-2014-9199 The Clorius Controls Java web client before 01.00.0009g allows remote attackers to discover credentials by sniffing the network for cleartext-equival… Java Web Client after 01.00.0009b Fix from $1,6002015-01-17 MEDIUM 5.0 CVE-2014-9593 Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call. Cloudstack after 4.3.1 Fix from $1,6002015-01-15 MEDIUM 5.0 CVE-2015-0583 Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors … Webex Meeting Center Mitigation only Fix from $1,6002015-01-14