Vulnerability index

Browse CVEs

800 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cleartext TransmissionCWE-319 × clear
MEDIUM 5.9 CVE-2017-8851 An issue was discovered on OnePlus One and X devices. Due to a lenient updater-script on the OnePlus One and X OTA images, the fact that both product… Oxygenos No fix yet Fix from $1,6002017-05-11 MEDIUM 5.3 CVE-2017-3305 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API). Supported versions that are affected are 5.5.55 and earlie… MySQL after 5.6.35 Fix from $1,6002017-04-24 MEDIUM 5.9 CVE-2017-2412 An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves the "iTunes Store" component. It allows man-in-the… Iphone Os after 10.2.1 Fix from $1,6002017-04-02 MEDIUM 5.3 CVE-2017-3815 An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Se… Telepresence Server Software Mitigation only Fix from $1,6002017-03-17 MEDIUM 5.3 CVE-2017-6370 TYPO3 7.6.15 sends an http request to an index.php?loginProvider URI in cases with an https Referer, which allows remote attackers to obtain sensitiv… TYPO3 No fix yet Fix from $1,6002017-03-17 HIGH 8.1 CVE-2017-6432 An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, i… Nvr Firmware No fix yet Fix from $1,9502017-03-09 MEDIUM 5.5 CVE-2017-6410 kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including… Kdelibs after 5.31 Fix from $1,6002017-03-02 MEDIUM 5.9 CVE-2017-6341EPSS 9% Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and SmartPSS Software 1.16.1 2… Camera Firmware Mitigation only Fix from $1,6002017-02-27 CRITICAL 10.0 CVE-2015-0987 Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which al… Cx Programmer after 9.5 Fix from $2,3002015-10-06 MEDIUM 5.0 CVE-2011-3022 translate/translate_manager.cc in Google Chrome before 17.0.963.56 and 19.x before 19.0.1036.7 uses an HTTP session to exchange data for translation,… Chrome 17.0.963.56 / 19.0.1036.7+ Fix from $1,6002012-02-16 HIGH 7.5 CVE-2008-4122 Joomla! 1.5.8 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this coo… Joomla\! Mitigation only Fix from $1,9502008-12-19 HIGH 7.5 CVE-2008-4390 The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext configuration data in response to a Setup Wizard remote-manageme… Linksys Wvc54gc Firmware 1.25+ Fix from $1,9502008-12-09 HIGH 7.5 CVE-2008-3289EPSS 5% EMC Dantz Retrospect Backup Client 7.5.116 sends the password hash in cleartext at an unspecified point, which allows remote attackers to obtain sens… Retrospect Backup Client Patch available Fix from $1,9502008-07-24 HIGH 7.5 CVE-2008-0374 OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 sends the configuration of the printer in cleartext, which allows remo… C5510mfp Firmware Mitigation only Fix from $1,9502008-01-22 MEDIUM 5.5 CVE-2007-5626 make_catalog_backup in Bacula 2.2.5, and probably earlier, sends a MySQL password as a command line argument, and sometimes transmits cleartext e-mai… Bacula after 2.2.5 Fix from $1,6002007-10-23 MEDIUM 5.3 CVE-2007-4786 Cisco Adaptive Security Appliance (ASA) running PIX 7.0 before 7.0.7.1, 7.1 before 7.1.2.61, 7.2 before 7.2.2.34, and 8.0 before 8.0.2.11, when AAA i… Adaptive Security Appliance Software 7.0.7.1 / 7.1.2.61+ Fix from $1,6002007-09-10 HIGH 7.5 CVE-2005-3140 Procom NetFORCE 800 4.02 M10 Build 20 and possibly other versions sends the NIS password map (passwd.nis) as a file attachment in diagnostic e-mail m… Netforce 800 Firmware Mitigation only Fix from $1,9502005-10-05 MEDIUM 5.0 CVE-2005-2069 pam_ldap and nss_ldap, when used with OpenLDAP and connecting to a slave using TLS, does not use TLS for the subsequent connection if the client is r… Nss Ldap Patch available Fix from $1,6002005-06-30 MEDIUM 5.0 CVE-2004-1852 DameWare Mini Remote Control 3.x before 3.74 and 4.x before 4.2 transmits the Blowfish encryption key in plaintext, which allows remote attackers to … Dameware Mini Remote Control 3.74 / 4.2+ Fix from $1,6002004-03-23 HIGH 7.5 CVE-2002-1949 The Network Attached Storage (NAS) Administration Web Page for Iomega NAS A300U transmits passwords in cleartext, which allows remote attackers to sn… Nas A300u Firmware Mitigation only Fix from $1,9502002-12-31