Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Edr 810 Firmware HIGH 7.5
CVE-2016-8346

An issue was discovered in Moxa EDR-810 Industrial Secure Router. By accessing a specific uniform resource locator (URL) on the web server, a malicio…

Fix: after 3.12
Fix from $1,950 2017-02-13
Linux Kernel MEDIUM 5.5
CVE-2017-5549

The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitialized heap-memory contents in…

Fix: after 4.9.4
Fix from $1,600 2017-02-06
Entera Sms Gateway Firmware MEDIUM 6.2
CVE-2017-5137

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticat…

Mitigation only
Fix from $1,600 2017-02-05
Merge System HIGH 7.5
CVE-2015-8977

MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allow remote attackers to obtain the installation …

Fix: after 1.8.5
Fix from $1,950 2017-01-31
Capi Release HIGH 7.5
CVE-2016-9882

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs …

Fix: after 249
Fix from $1,950 2017-01-13
Enterprise Virtualization MEDIUM 5.5
CVE-2016-4443

Red Hat Enterprise Virtualization (RHEV) Manager 3.6 allows local users to obtain encryption keys, certificates, and other sensitive information by r…

Patch available
Fix from $1,600 2016-12-14
Rational Asset Analyzer MEDIUM 5.5
CVE-2016-5967

The installation component in IBM Rational Asset Analyzer (RAA) 6.1.0 before FP10 allows local users to discover the WAS Admin password by reading IM…

Mitigation only
Fix from $1,600 2016-11-25
Edr G903 Firmware HIGH 7.5
CVE-2016-0879

Moxa Secure Router EDR-G903 devices before 3.4.12 do not delete copies of configuration and log files after completing the import function, which all…

Fix: 3.4.12+
Fix from $1,950 2016-05-31
Edr G903 Firmware HIGH 7.5
CVE-2016-0875

Moxa Secure Router EDR-G903 devices before 3.4.12 allow remote attackers to read configuration and log files via a crafted URL.

Fix: 3.4.12+
Fix from $1,950 2016-05-31
Dasdec Eas HIGH 7.5
CVE-2013-4733

The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows rem…

Fix: after 2.0-1
Fix from $1,950 2013-06-30
Openssh MEDIUM 6.5
CVE-2012-0814

The auth_parse_options function in auth-options.c in sshd in OpenSSH before 5.7 provides debug messages containing authorized_keys command options, w…

Fix: after 5.6
Fix from $1,600 2012-01-27
HTTP Server MEDIUM 5.0
CVE-2001-1556

The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allo…

Fix: 1.3.31 / 2.0.49+
Fix from $1,600 2001-12-31