Vulnerability index

Browse CVEs

364 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2021-27769 Information leakage occurs when a website reveals information that could aid an attacker to further exploit the system. This information may or may n… Sametime No fix yet Fix from $1,6002022-05-12 HIGH 7.8 CVE-2021-27765 The BigFix Server API installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to… Bigfix Platform after 10.0.5 Fix from $1,9502022-05-06 HIGH 7.8 CVE-2021-27766 The BigFix Client installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to per… Bigfix Platform after 10.0.5 Fix from $1,9502022-05-06 HIGH 7.8 CVE-2021-27767 The BigFix Console installer is created with InstallShield, which was affected by CVE-2021-41526, a vulnerability that could allow a local user to pe… Bigfix Platform after 10.0.5 Fix from $1,9502022-05-06 CRITICAL 9.8 CVE-2021-27762 Misconfigured security-related HTTP headers: Several security-related headers were missing or mis-configured on the web responses Bigfix Platform 9.5.19 / 10.0.6+ Fix from $2,3002022-05-06 HIGH 7.5 CVE-2021-27761 Weak web transport security (Weak TLS): An attacker may be able to decrypt the data using attacks Bigfix Platform 9.5.19 / 10.0.6+ Fix from $1,9502022-05-06 MEDIUM 6.5 CVE-2021-27758 There is a security vulnerability in login form related to Cross-site Request Forgery which prevents user to login after attacker spam to login and s… Bigfix Inventory 10.0.7.0+ Fix from $1,6002022-05-06 MEDIUM 6.5 CVE-2021-27759 This vulnerability arises because the application allows the user to perform some sensitive action without verifying that the request was sent intent… Bigfix Inventory 10.0.7.0+ Fix from $1,6002022-05-06 MEDIUM 6.5 CVE-2021-27764 Cookie without HTTPONLY flag set. NUMBER cookie(s) was set without Secure or HTTPOnly flags. The images show the cookie with the missing flag. (WebUI) Bigfix Webui Mitigation only Fix from $1,6002022-05-06 MEDIUM 5.5 CVE-2021-27760 An issue was discovered in the Sametime chat feature in the Notes 11.0 - 11.0.1 FP4 clients. An authenticated Sametime chat user could cause Remote C… Hcl Inotes Mitigation only Fix from $1,6002022-05-06 HIGH 7.5 CVE-2021-27756 "TLS-RSA cipher suites are not disabled in BigFix Compliance up to v2.0.5. If TLS 2.0 and secure ciphers are not enabled then an attacker can passive… Bigfix Compliance 2.0.6+ Fix from $1,9502022-03-04 HIGH 7.5 CVE-2021-27757 " Insecure password storage issue.The application stores sensitive information in cleartext within a resource that might be accessible to another con… Bigfix Insights 10.0.8.0+ Fix from $1,9502022-03-04 MEDIUM 5.5 CVE-2021-27753 "Sametime Android PathTraversal Vulnerability" Hcl Sametime 11.6.5+ Fix from $1,6002022-02-21 MEDIUM 5.5 CVE-2021-27755 "Sametime Android potential path traversal vulnerability when using File class" Hcl Sametime 11.6.5+ Fix from $1,6002022-02-21 MEDIUM 6.1 CVE-2020-4081 In Digital Experience 8.5, 9.0, and 9.5, WSRP consumer is vulnerable to cross-site scripting (XSS). Digital Experience Mitigation only Fix from $1,6002021-02-02 HIGH 7.5 CVE-2020-14255 HCL Digital Experience 9.5 containers include vulnerabilities that could expose sensitive data to unauthorized parties via crafted requests. These af… Digital Experience Mitigation only Fix from $1,9502021-02-02 HIGH 7.5 CVE-2020-14273 HCL Domino is susceptible to a Denial of Service (DoS) vulnerability due to insufficient validation of input to its public API. An unauthenticated at… Domino No fix yet Fix from $1,9502020-12-28 MEDIUM 5.3 CVE-2020-14270 HCL Domino v9, v10, v11 is susceptible to an Information Disclosure vulnerability in XPages due to improper error handling of user input. An unauthen… Domino after 10.0.0 Fix from $1,6002020-12-22 MEDIUM 6.5 CVE-2020-14225 HCL iNotes is susceptible to a Tabnabbing vulnerability caused by improper sanitization of message content. A remote unauthenticated attacker could u… Hcl Inotes 9.0.1+ Fix from $1,6002020-12-21 CRITICAL 9.8 CVE-2020-14224 A vulnerability in the MIME message handling of the HCL Notes v9 client could potentially be exploited by an unauthenticated attacker resulting in a … Notes Patch available Fix from $2,3002020-12-18 MEDIUM 6.1 CVE-2020-14271 HCL iNotes v9, v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauth… Hcl Inotes 10.0.1 / 11.0.1+ Fix from $1,6002020-12-18 MEDIUM 6.1 CVE-2020-4080 HCL Verse v10 and v11 is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper handling of message content. An unauthentic… Domino Patch available Fix from $1,6002020-12-18 HIGH 8.8 CVE-2020-14232 A vulnerability in the input parameter handling of HCL Notes v9 could potentially be exploited by an authenticated attacker resulting in a stack buff… Notes Mitigation only Fix from $1,9502020-12-18 HIGH 7.5 CVE-2020-14254 TLS-RSA cipher suites are not disabled in HCL BigFix Inventory up to v10.0.2. If TLS 2.0 and secure ciphers are not enabled then an attacker can pass… Bigfix Platform after 10.0.2 Fix from $1,9502020-12-16 MEDIUM 5.3 CVE-2020-14248 BigFix Inventory up to v10.0.2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http… Bigfix Platform after 10.0.2 Fix from $1,6002020-12-16 CRITICAL 9.8 CVE-2020-14244 A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker r… Domino 10.0.1+ Fix from $2,3002020-12-14 CRITICAL 9.8 CVE-2020-14268 A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker re… Notes 9.0.1 / 10.0.1+ Fix from $2,3002020-12-14 CRITICAL 9.8 CVE-2020-14260 HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an at… Domino after 11.0.1 Fix from $2,3002020-12-02 MEDIUM 6.7 CVE-2020-4102 HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an att… Notes after 9.0.1 Fix from $1,6002020-12-02 MEDIUM 5.3 CVE-2020-4128 HCL Domino is susceptible to a lockout policy bypass vulnerability in the ID Vault service. An unauthenticated attacker could use this vulnerability … Domino after 11.0.1 Fix from $1,6002020-12-01