Vulnerability index

Browse CVEs

7,760 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
MEDIUM 5.0 CVE-2014-4311EPSS 6% Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allows attackers to obtain the (1) Database Connection and (2) E-mail Connection passwords by rea… Epicor Enterprise after 7.4 Fix from $1,6002014-11-04 MEDIUM 5.0 CVE-2012-5508 The error pages in Plone before 4.2.3 and 4.3 before beta 1 allow remote attackers to obtain random numbers and derive the PRNG state for password re… Plone after 4.2.2 Fix from $1,6002014-11-03 HIGH 7.5 CVE-2014-8244 Linksys SMART WiFi firmware on EA2700 and EA3500 devices; before 2.1.41 build 162351 on E4200v2 and EA4500 devices; before 1.1.41 build 162599 on EA6… Ea3500 Firmware after 2.0.14294 Fix from $1,9502014-11-01 MEDIUM 5.0 CVE-2014-8082 lib/functions/database.class.php in TestLink before 1.9.13 allows remote attackers to obtain sensitive information via unspecified vectors, which rev… Testlink after 1.9.12 Fix from $1,6002014-10-31 MEDIUM 5.0 CVE-2014-8520 McAfee Network Data Loss Prevention (NDLP) before 9.3 allows remote attackers to obtain sensitive information via vectors related to open network por… Network Data Loss Prevention after 9.2.2 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-8524 McAfee Network Data Loss Prevention (NDLP) before 9.3 does not disable the autocomplete setting for the password and other fields, which allows remot… Network Data Loss Prevention after 9.2.2 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-8525 McAfee Network Data Loss Prevention (NDLP) before 9.3 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes i… Network Data Loss Prevention after 9.2.2 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-3698 The jabber_idn_validate function in jutil.c in the Jabber protocol plugin in libpurple in Pidgin before 2.10.10 allows remote attackers to obtain sen… Pidgin after 2.10.9 Fix from $1,6002014-10-29 MEDIUM 5.0 CVE-2014-4821 IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF0… Websphere Portal Patch available Fix from $1,6002014-10-28 MEDIUM 5.0 CVE-2014-4766 IBM Sametime Classic Meeting Server 8.0.x and 8.5.x allows remote attackers to obtain sensitive information by reading an exported Record and Playbac… Classic Meeting Server Mitigation only Fix from $1,6002014-10-23 MEDIUM 5.0 CVE-2014-8761 inc/template.php in DokuWiki before 2014-05-05a only checks for access to the root namespace, which allows remote attackers to access arbitrary image… Dokuwiki after 2013-12-08 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-8762 The ajax_mediadiff function in DokuWiki before 2014-05-05a allows remote attackers to access arbitrary images via a crafted namespace in the ns param… Dokuwiki after 2013-12-08 Fix from $1,6002014-10-22 MEDIUM 5.0 CVE-2014-5094EPSS 6% Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo f… Status2k No fix yet Fix from $1,6002014-10-20 MEDIUM 5.0 CVE-2014-2064 The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attac… Jenkins after 1.550 Fix from $1,6002014-10-17 MEDIUM 5.0 CVE-2014-8315 polestar_xml.jsp in SAP BusinessObjects Explorer 14.0.5 build 882 replies with different timing depending on if a connection can be made, which allow… Businessobjects Explorer Mitigation only Fix from $1,6002014-10-16 MEDIUM 5.0 CVE-2014-8309 SAP BusinessObjects 4.0 and BusinessObjects XI (BOXI) R2 and 3.1 generates error messages for a failed logon attempt with different time delays depen… Businessobjects Mitigation only Fix from $1,6002014-10-16 MEDIUM 5.0 CVE-2014-3662 Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts. Jenkins after 3.1 Fix from $1,6002014-10-16 MEDIUM 5.0 CVE-2014-1829 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected requ… Debian Linux after 2.2.1 Fix from $1,6002014-10-15 MEDIUM 5.0 CVE-2014-1830 Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redi… Requests after 2.2.1 Fix from $1,6002014-10-15 MEDIUM 5.0 CVE-2014-1580 Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from pr… Firefox after 32.0 Fix from $1,6002014-10-15 MEDIUM 6.4 CVE-2014-7284 The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not p… Linux Kernel Patch available Fix from $1,6002014-10-13 MEDIUM 5.0 CVE-2014-8068 Adobe Digital Editions (DE) 4 does not use encryption for transmission of data to adelogs.adobe.com, which allows remote attackers to obtain sensitiv… Digital Editions Mitigation only Fix from $1,6002014-10-09 MEDIUM 5.0 CVE-2013-7329 The CGI::Application module before 4.50_50 and 4.50_51 for Perl, when run modes are not specified, allows remote attackers to obtain sensitive inform… Cgi Application Module after 4.50 Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2013-6496 Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)… Conga Mitigation only Fix from $1,6002014-10-06 MEDIUM 5.0 CVE-2014-3398 The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to obtain potentially sensitive software-versi… Adaptive Security Appliance Software Mitigation only Fix from $1,6002014-10-05 MEDIUM 5.0 CVE-2014-4765 IBM Maximo Asset Management 7.1 through 7.1.1.13 and 7.5 through 7.5.0.6, Maximo Asset Management 7.5.0 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for… Change And Configuration Management Database Patch available Fix from $1,6002014-10-02 MEDIUM 5.0 CVE-2012-5492 uid_catalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to obtain metadata about hidden objects via a crafted URL. Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5497 membership_tool.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to enumerate user account names via a crafted URL. Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5505 atat.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read private data structures via a request for a view without a name. Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2014-3103 The Web component in IBM Rational ClearQuest 7.1 before 7.1.2.15, 8.0.0 before 8.0.0.12, and 8.0.1 before 8.0.1.5 does not set the secure flag for th… Rational Clearcase Patch available Fix from $1,6002014-09-23