Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2014-8637 Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensi… Firefox after 34.0.5 Fix from $1,6002015-01-14 MEDIUM 5.0 CVE-2014-10026 index.cgi in D-Link DAP-1360 with firmware 2.5.4 and earlier allows remote attackers to bypass authentication and obtain sensitive information by set… Dap 1360 Firmware after 2.5.4 Fix from $1,6002015-01-13 MEDIUM 5.0 CVE-2014-10005 Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which revea… Maian Uploader No fix yet Fix from $1,6002015-01-13 MEDIUM 5.0 CVE-2014-100009 The Joomlaskin JS Multi Hotel (aka JS MultiHotel and Js-Multi-Hotel) plugin 2.2.1 and earlier for WordPress allows remote attackers to obtain the ins… Js Multi Hotel after 2.2.1 Fix from $1,6002015-01-13 MEDIUM 5.0 CVE-2014-8035 The web framework in Cisco WebEx Meetings Server produces different returned messages for URL requests depending on whether a username exists, which … Webex Meetings Server Mitigation only Fix from $1,6002015-01-10 MEDIUM 5.0 CVE-2015-0922EPSS 13% McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows … Epolicy Orchestrator after 4.6.8 Fix from $1,6002015-01-09 MEDIUM 5.0 CVE-2014-9579 VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by re… Vdg Sense No fix yet Fix from $1,6002015-01-08 MEDIUM 5.0 CVE-2014-9576 VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgre… Vdg Sense No fix yet Fix from $1,6002015-01-08 MEDIUM 5.0 CVE-2014-4638 EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame-injection attacks and obtain sensitive information via u… Documentum Wdk after 6.7 Fix from $1,6002015-01-07 MEDIUM 5.0 CVE-2011-5314 templates/default/index.php in Redaxscript 0.3.2 allows remote attackers to obtain sensitive information via a direct request, which reveals the full… Redaxscript No fix yet Fix from $1,6002015-01-01 MEDIUM 5.0 CVE-2014-1908EPSS 7% The error-handling feature in (1) bp.php, (2) videowhisper_streaming.php, and (3) ls/rtmp.inc.php in the VideoWhisper Live Streaming Integration plug… Videowhisper Live Streaming Integration after 4.27.4 Fix from $1,6002014-12-29 MEDIUM 5.0 CVE-2014-6229 The HashContext class in hphp/runtime/ext/ext_hash.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 incorrectly expects that a certain key … Hiphop Virtual Machine after 3.2.0 Fix from $1,6002014-12-28 MEDIUM 5.0 CVE-2013-6043 The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the … Webuzo after 2.1.3 Fix from $1,6002014-12-27 MEDIUM 5.0 CVE-2014-8017 The periodic-backup feature in Cisco Identity Services Engine (ISE) allows remote attackers to discover backup-encryption passwords via a crafted req… Identity Services Engine Software Mitigation only Fix from $1,6002014-12-22 MEDIUM 5.0 CVE-2014-9408 Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 uses part of the MAC add… Activator No fix yet Fix from $1,6002014-12-19 MEDIUM 5.0 CVE-2014-6164 IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, a… Websphere Application Server Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-6088 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a… Security Access Manager For Web Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-6086 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not ensure … Security Access Manager For Mobile Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-6083 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote a… Security Access Manager For Web Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-8553 The mci_account_get_array_by_id function in api/soap/mc_account_api.php in MantisBT before 1.2.18 allows remote attackers to obtain sensitive informa… Mantisbt after 1.2.17 Fix from $1,6002014-12-17 MEDIUM 5.0 CVE-2014-9250 Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remot… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-9245 Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name a… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 MEDIUM 5.0 CVE-2014-6114 The Hosted Transparent Decision Service in the Rule Execution Server in IBM WebSphere ILOG JRules 7.1 before MP1 FP5 IF43; WebSphere Operational Deci… Operational Decision Manager Mitigation only Fix from $1,6002014-12-11 MEDIUM 5.0 CVE-2014-6355EPSS 34% The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows… Windows 7 Mitigation only Fix from $1,6002014-12-11 MEDIUM 5.0 CVE-2014-8452EPSS 18% Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to read arbitrary files via an XML ex… Acrobat Reader Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-8451EPSS 9% An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain … Acrobat Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-8448EPSS 9% An unspecified JavaScript API in Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allows attackers to obtain … Acrobat Mitigation only Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-8009 The Management subsystem in Cisco Unified Computing System 2.1(3f) and earlier allows remote attackers to obtain sensitive information by reading log… Unified Computing System after 2.1 Fix from $1,6002014-12-10 MEDIUM 5.0 CVE-2014-9279 The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x before 1.2.18 allows remote attackers to obtain data… Mantisbt Patch available Fix from $1,6002014-12-08 HIGH 7.8 CVE-2014-9303 EntryPass N5200 Active Network Control Panel allows remote attackers to read device memory and obtain the administrator username and password via a U… N5200 Active Network Control Panel No fix yet Fix from $1,9502014-12-07