Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
Oxygenos MEDIUM 5.9
CVE-2017-8851

An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both product…

No fix yet
Fix from $1,600 2017-05-11
MySQL MEDIUM 5.3
CVE-2017-3305

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlie…

Fix: after 5.6.35
Fix from $1,600 2017-04-24
Iphone Os MEDIUM 5.9
CVE-2017-2412

An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the…

Fix: after 10.2.1
Fix from $1,600 2017-04-02
Telepresence Server Software MEDIUM 5.3
CVE-2017-3815

An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Se…

Mitigation only
Fix from $1,600 2017-03-17
TYPO3 MEDIUM 5.3
CVE-2017-6370

TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv…

No fix yet
Fix from $1,600 2017-03-17
Nvr Firmware HIGH 8.1
CVE-2017-6432

An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, i…

No fix yet
Fix from $1,950 2017-03-09
Kdelibs MEDIUM 5.5
CVE-2017-6410

kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including…

Fix: after 5.31
Fix from $1,600 2017-03-02
Camera Firmware MEDIUM 5.9
CVE-2017-6341EPSS 9%

Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2…

Mitigation only
Fix from $1,600 2017-02-27
Cx Programmer CRITICAL 10.0
CVE-2015-0987

Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which al…

Fix: after 9.5
Fix from $2,300 2015-10-06
Chrome MEDIUM 5.0
CVE-2011-3022

translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation,…

Fix: 17.0.963.56 / 19.0.1036.7+
Fix from $1,600 2012-02-16
Joomla\! HIGH 7.5
CVE-2008-4122

Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this coo…

Mitigation only
Fix from $1,950 2008-12-19
Linksys Wvc54gc Firmware HIGH 7.5
CVE-2008-4390

The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-manageme…

Fix: 1.25+
Fix from $1,950 2008-12-09
Retrospect Backup Client HIGH 7.5
CVE-2008-3289EPSS 5%

EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sens…

Patch available
Fix from $1,950 2008-07-24
C5510mfp Firmware HIGH 7.5
CVE-2008-0374

OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remo…

Mitigation only
Fix from $1,950 2008-01-22
Bacula MEDIUM 5.5
CVE-2007-5626

make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mai…

Fix: after 2.2.5
Fix from $1,600 2007-10-23
Adaptive Security Appliance Software MEDIUM 5.3
CVE-2007-4786

Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA i…

Fix: 7.0.7.1 / 7.1.2.61+
Fix from $1,600 2007-09-10
Netforce 800 Firmware HIGH 7.5
CVE-2005-3140

Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail m…

Mitigation only
Fix from $1,950 2005-10-05
Nss Ldap MEDIUM 5.0
CVE-2005-2069

pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is r…

Patch available
Fix from $1,600 2005-06-30
Dameware Mini Remote Control MEDIUM 5.0
CVE-2004-1852

DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to …

Fix: 3.74 / 4.2+
Fix from $1,600 2004-03-23
Nas A300u Firmware HIGH 7.5
CVE-2002-1949

The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sn…

Mitigation only
Fix from $1,950 2002-12-31