Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-7255 | 1 Zte | 12 Gan9.8t101a-b, Gan9.8t101a-b Firmware, Hg110 and 9 more | 2017-09-12 | 5.0 MEDIUM | 7.5 HIGH |
ZTE OX-330P, ZXHN H108N, W300V1.0.0S_ZRD_TR1_D68, HG110, GAN9.8T101A-B, MF28G, ZXHN H108N use non-unique X.509 certificates and SSH host keys, which might allow remote attackers to obtain credentials or other sensitive information via a man-in-the-middle attack, passive decryption attack, or impersonating a legitimate device. | |||||
CVE-2017-13774 | 1 Hikvision | 1 Ivms-4200 | 2017-09-12 | 2.1 LOW | 7.8 HIGH |
Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors. | |||||
CVE-2016-3086 | 1 Apache | 1 Hadoop | 2017-09-11 | 5.0 MEDIUM | 9.8 CRITICAL |
The YARN NodeManager in Apache Hadoop 2.6.x before 2.6.5 and 2.7.x before 2.7.3 can leak the password for credential store provider used by the NodeManager to YARN Applications. | |||||
CVE-2015-5677 | 1 Freebsd | 1 Freebsd | 2017-09-09 | 2.1 LOW | 5.5 MEDIUM |
bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file. | |||||
CVE-2017-9150 | 1 Linux | 1 Linux Kernel | 2017-09-08 | 2.1 LOW | 5.5 MEDIUM |
The do_check function in kernel/bpf/verifier.c in the Linux kernel before 4.11.1 does not make the allow_ptr_leaks value available for restricting the output of the print_bpf_insn function, which allows local users to obtain sensitive address information via crafted bpf system calls. | |||||
CVE-2017-9978 | 1 Osnexus | 1 Quantastor | 2017-09-07 | 5.0 MEDIUM | 5.3 MEDIUM |
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the system by searching for common usernames. | |||||
CVE-2015-0517 | 1 Emc | 1 Documentum D2 | 2017-09-07 | 4.0 MEDIUM | N/A |
The D2-API component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 places the MD5 hash of an encryption passphrase in log files, which allows remote authenticated users to obtain sensitive information by reading a file. | |||||
CVE-2015-0519 | 1 Emc | 1 Captiva Capture | 2017-09-07 | 2.1 LOW | N/A |
The InputAccel Database (IADB) installation process in EMC Captiva Capture 7.0 before patch 25 and 7.1 before patch 13 places a cleartext InputAccel (IA) SQL password in a DAL log file, which allows local users to obtain sensitive information by reading a file. | |||||
CVE-2015-0595 | 1 Cisco | 1 Webex Meetings Server | 2017-09-07 | 5.0 MEDIUM | N/A |
The XMLAPI in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to obtain sensitive information by reading return messages from crafted GET requests, aka Bug ID CSCuj67079. | |||||
CVE-2015-0583 | 1 Cisco | 1 Webex Meeting Center | 2017-09-07 | 5.0 MEDIUM | N/A |
Cisco WebEx Meeting Center does not properly restrict the content of URLs, which allows remote attackers to obtain sensitive information via vectors related to file: URIs, aka Bug ID CSCus18281. | |||||
CVE-2015-0597 | 1 Cisco | 1 Webex Meetings Server | 2017-09-07 | 5.0 MEDIUM | N/A |
The Forgot Password feature in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to enumerate administrative accounts via crafted packets, aka Bug IDs CSCuj67166 and CSCuj67159. | |||||
CVE-2015-0590 | 1 Cisco | 1 Webex Meeting Center | 2017-09-07 | 5.0 MEDIUM | N/A |
Cisco WebEx Meeting Center allows remote attackers to activate disabled meeting attributes, and consequently obtain sensitive information, by providing crafted parameters during a meeting-join action, aka Bug ID CSCuo34165. | |||||
CVE-2015-0602 | 1 Cisco | 3 Unified Ip Phone 9951, Unified Ip Phone 9971, Unified Ip Phones 9900 Series Firmware | 2017-09-07 | 5.0 MEDIUM | N/A |
The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117. | |||||
CVE-2015-0922 | 1 Mcafee | 1 Epolicy Orchestrator | 2017-09-07 | 5.0 MEDIUM | N/A |
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by leveraging knowledge of the encrypted password. | |||||
CVE-2015-1457 | 1 Fortinet | 1 Fortiauthenticator | 2017-09-07 | 4.9 MEDIUM | N/A |
Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the dig command. | |||||
CVE-2017-11356 | 1 Pega | 1 Pega Platform | 2017-09-07 | 4.0 MEDIUM | 6.5 MEDIUM |
The application distribution export functionality in PEGA Platform 7.2 ML0 and earlier allows remote authenticated users with certain privileges to obtain sensitive configuration information by leveraging a missing access control. | |||||
CVE-2016-2513 | 1 Djangoproject | 1 Django | 2017-09-07 | 2.6 LOW | 3.1 LOW |
The password hasher in contrib/auth/hashers.py in Django before 1.8.10 and 1.9.x before 1.9.3 allows remote attackers to enumerate users via a timing attack involving login requests. | |||||
CVE-2014-5448 | 1 Zarafa | 1 Zarafa | 2017-09-07 | 2.1 LOW | N/A |
Zarafa 5.00 uses world-readable permissions for the files in the log directory, which allows local users to obtain sensitive information by reading the log files. | |||||
CVE-2014-5449 | 1 Zarafa | 2 Webaccess, Webapp | 2017-09-07 | 2.1 LOW | N/A |
Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data. | |||||
CVE-2014-6075 | 1 Ibm | 3 Qradar Risk Manager, Qradar Security Information And Event Manager, Qradar Vulnerability Manager | 2017-09-07 | 5.0 MEDIUM | N/A |
IBM Security QRadar SIEM and QRadar Risk Manager 7.1 before MR2 Patch 9 and 7.2 before 7.2.4 Patch 1, and QRadar Vulnerability Manager 7.2 before 7.2.4 Patch 1, place credentials in URLs, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. |