Vulnerability index

Browse CVEs

479 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fabric Operating System HIGH 8.8
CVE-2016-8202

A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b …

Fix: after 7.4.1c
Fix from $1,950 2017-05-08
Symantec Data Center Security Server MEDIUM 5.5
CVE-2016-5309EPSS 7%

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud…

Fix: after 12.1.6
Fix from $1,600 2017-04-14
Symantec Data Center Security Server MEDIUM 5.5
CVE-2016-5310EPSS 5%

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud…

Fix: after 12.1.6
Fix from $1,600 2017-04-14
Hardmac Wi Fi Soc Firmware HIGH 8.8
CVE-2017-6956

On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to…

Mitigation only
Fix from $1,950 2017-04-05
Bcm4339 Soc Firmware HIGH 8.1
CVE-2017-6957

Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feat…

No fix yet
Fix from $1,950 2017-03-27
Tcpreplay HIGH 7.8
CVE-2017-6429

Buffer overflow in the tcpcapinfo utility in Tcpreplay before 4.2.0 Beta 1 allows remote attackers to have unspecified impact via a pcap file with an…

Fix: after 4.1.2
Fix from $1,950 2017-03-15
Ca Workload Automation Ae HIGH 7.8
CVE-2016-9795

The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance f…

Mitigation only
Fix from $1,950 2017-01-27
Tcpreplay HIGH 7.5
CVE-2016-6160

tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to …

Fix: after 4.1.1
Fix from $1,950 2017-01-23
Brocade Network Advisor CRITICAL 9.8
CVE-2016-8204EPSS 7%

A Directory Traversal vulnerability in FileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow …

Fix: after 14.0.2
Fix from $2,300 2017-01-14
Rabbitmq Server CRITICAL 9.8
CVE-2016-9877

An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ for PCF 1.5.x before 1.5.20, 1.6.x before 1.6.12, an…

Mitigation only
Fix from $2,300 2016-12-29
Fabric Operating System MEDIUM 6.5
CVE-2016-4376

HPE FOS before 7.4.1d and 8.x before 8.0.1 on StoreFabric B switches allows remote attackers to obtain sensitive information via unspecified vectors.

Fix: after 7.4.1
Fix from $1,600 2016-08-22
Ehealth HIGH 8.8
CVE-2016-6152

CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via …

Patch available
Fix from $1,950 2016-07-26
Release Automation MEDIUM 6.1
CVE-2015-8699

Multiple cross-site scripting (XSS) vulnerabilities in CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before …

Fix: 5.0.2-227 / 5.5.1-1616+
Fix from $1,600 2016-06-29
Release Automation HIGH 7.1
CVE-2015-8698

CA Release Automation (formerly LISA Release Automation) 5.0.2 before 5.0.2-227, 5.5.1 before 5.5.1-1616, 5.5.2 before 5.5.2-434, and 6.1.0 before 6.…

Fix: 5.0.2-227 / 5.5.1-1616+
Fix from $1,950 2016-06-29
Symantec Critical System Protection HIGH 7.3
CVE-2015-8800

Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers …

Mitigation only
Fix from $1,950 2016-06-08
Symantec Critical System Protection HIGH 7.6
CVE-2015-8799EPSS 5%

Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, …

Fix: 6.5.0+
Fix from $1,950 2016-06-08
Symantec Critical System Protection HIGH 8.0
CVE-2015-8798

Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, …

Fix: after 6.6.0
Fix from $1,950 2016-06-08
Symantec Critical System Protection HIGH 8.8
CVE-2015-8157

SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedd…

Fix: after 6.6.0
Fix from $1,950 2016-06-08
Api Gateway MEDIUM 6.5
CVE-2016-3118

CRLF injection vulnerability in CA API Gateway (formerly Layer7 API Gateway) 7.1 before 7.1.04, 8.0 through 8.3 before 8.3.01, and 8.4 before 8.4.01 …

Mitigation only
Fix from $1,600 2016-04-06
Single Sign On CRITICAL 9.1
CVE-2015-6854

The non-Domino web agents in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, and R12.5 before CR…

Mitigation only
Fix from $2,300 2016-03-24
Single Sign On CRITICAL 9.1
CVE-2015-6853

The Domino web agent in CA Single Sign-On (aka SSO, formerly SiteMinder) R6, R12.0 before SP3 CR13, R12.0J before SP3 CR1.2, R12.5 before CR5, R12.51…

Mitigation only
Fix from $2,300 2016-03-24
Spectrum HIGH 9.0
CVE-2015-2828

CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain admi…

No fix yet
Fix from $1,950 2015-04-08
Rabbitmq Server MEDIUM 5.0
CVE-2014-9650

CRLF injection vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary HTTP h…

Mitigation only
Fix from $1,600 2015-01-27
Symantec Critical System Protection HIGH 7.2
CVE-2014-9226

The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.…

No fix yet
Fix from $1,950 2015-01-21
Symantec Critical System Protection MEDIUM 6.5
CVE-2014-7289

SQL injection vulnerability in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security…

No fix yet
Fix from $1,600 2015-01-21
Symantec Critical System Protection HIGH 9.0
CVE-2014-3440

The Agent Control Interface in the management server in Symantec Critical System Protection (SCSP) 5.2.9 before MP6 and Symantec Data Center Security…

Mitigation only
Fix from $1,950 2015-01-21
Release Automation MEDIUM 6.5
CVE-2014-8248

SQL injection vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote authenticated users to e…

Fix: after 4.7.1
Fix from $1,600 2014-12-16
Release Automation MEDIUM 6.8
CVE-2014-8246

Cross-site request forgery (CSRF) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote atta…

Fix: after 4.7.1
Fix from $1,600 2014-12-16
Investigation Tool MEDIUM 5.4
CVE-2014-6799

The Investigation Tool (aka gov.ca.post.lp.itool) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man…

Mitigation only
Fix from $1,600 2014-09-29
Pipa C211 Web Interface HIGH 9.7
CVE-2014-2046

cgi-bin/rpcBridge in the web interface 1.1 on Broadcom Ltd PIPA C211 rev2 does not properly restrict access, which allows remote attackers to (1) obt…

No fix yet
Fix from $1,950 2014-05-14