Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-8675 | 1 Soplanning | 1 Soplanning | 2017-09-05 | 5.0 MEDIUM | 7.5 HIGH |
Soplanning 1.32 and earlier generates static links for sharing ICAL calendars with embedded login information, which allows remote attackers to obtain a calendar owner's password via a brute-force attack on the embedded password hash. | |||||
CVE-2017-12870 | 1 Simplesamlphp | 1 Simplesamlphp | 2017-09-05 | 4.3 MEDIUM | 5.9 MEDIUM |
SimpleSAMLphp 1.14.12 and earlier make it easier for man-in-the-middle attackers to obtain sensitive information by leveraging use of the aesEncrypt and aesDecrypt methods in the SimpleSAML/Utils/Crypto class to protect session identifiers in replies to non-HTTPS service providers. | |||||
CVE-2017-3154 | 1 Apache | 1 Atlas | 2017-09-05 | 5.0 MEDIUM | 7.5 HIGH |
Error responses from Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating included stack trace, exposing excessive information. | |||||
CVE-2016-2970 | 1 Ibm | 1 Sametime | 2017-09-04 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Sametime 8.5 and 9.0 meetings server may provide detailed information in an error message that may provide details about the application to possible attackers. IBM X-Force ID: 113851. | |||||
CVE-2016-0358 | 1 Ibm | 1 Sametime | 2017-09-03 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Sametime 8.5.2 and 9.0 could allow an unauthorized authenticated user to enumerate group chat ID numbers and join meetings that he was not invited to. IBM X-Force ID: 111928. | |||||
CVE-2016-8016 | 1 Mcafee | 1 Virusscan Enterprise | 2017-09-02 | 3.5 LOW | 3.4 LOW |
Information exposure in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to obtain the existence of unauthorized files on the system via a URL parameter. | |||||
CVE-2016-6689 | 1 Google | 1 Android | 2017-09-02 | 4.3 MEDIUM | 5.5 MEDIUM |
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via a crafted application, aka internal bug 30768347. | |||||
CVE-2016-5677 | 2 Netgear, Nuuo | 3 Readynas Surveillance, Nvrmini 2, Nvrsolo | 2017-09-02 | 5.0 MEDIUM | 7.5 HIGH |
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request. | |||||
CVE-2016-6435 | 1 Cisco | 1 Firepower Management Center | 2017-09-02 | 4.0 MEDIUM | 6.5 MEDIUM |
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via crafted parameters, aka Bug ID CSCva30376. | |||||
CVE-2016-10175 | 1 Netgear | 2 Wnr2000v5, Wnr2000v5 Firmware | 2017-09-02 | 5.0 MEDIUM | 9.8 CRITICAL |
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. This serial number allows a user to obtain the administrator username and password, when used in combination with the CVE-2016-10176 vulnerability that allows resetting the answers to the password-recovery questions. | |||||
CVE-2016-2964 | 1 Ibm | 1 Sametime | 2017-09-02 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM Sametime 8.5.2 and 9.0 under certain conditions provides an error message to a user that is too detailed and may reveal details about the application. IBM X-Force ID: 113813. | |||||
CVE-2016-2966 | 1 Ibm | 1 Sametime | 2017-09-02 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Sametime 8.5.1 and 9.0 could allow an authenticated user to enumerate meeting rooms by guessing the meeting room id. IBM X-Force ID: 113847. | |||||
CVE-2016-2976 | 1 Ibm | 1 Sametime | 2017-09-02 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting invitee to obtain previously cleared sensitive information by viewing the meeting report history. IBM X-Force ID: 113936. | |||||
CVE-2016-2978 | 1 Ibm | 1 Sametime | 2017-09-02 | 2.1 LOW | 3.3 LOW |
IBM Sametime 8.5.2 and 9.0 could store potentially sensitive information from the browser cache locally that could be available to a local user. IBM X-Force ID: 113938. | |||||
CVE-2016-3473 | 1 Oracle | 1 Business Intelligence Publisher | 2017-09-02 | 4.0 MEDIUM | 7.7 HIGH |
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality via unknown vectors. | |||||
CVE-2017-1110 | 1 Ibm | 1 Curam Social Program Management | 2017-09-02 | 4.0 MEDIUM | 6.5 MEDIUM |
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 contains an unspecified vulnerability that could allow an authenticated user to view the incidents of a higher privileged user. IBM X-Force ID: 120915. | |||||
CVE-2016-2974 | 1 Ibm | 1 Sametime | 2017-09-01 | 2.1 LOW | 3.3 LOW |
IBM Sametime Connect 8.5.2 and 9.0, after uninstalling the Sametime Rich Client, could disclose potentially sensitive information related to the Sametime environment as well as other users on the local machine of the user. IBM X-Force ID: 113934. | |||||
CVE-2013-7431 | 1 Mapsplugin | 1 Googlemaps | 2017-09-01 | 5.0 MEDIUM | 5.3 MEDIUM |
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!. | |||||
CVE-2017-0038 | 1 Microsoft | 8 Windows 10, Windows 7, Windows 8.1 and 5 more | 2017-08-31 | 4.3 MEDIUM | 5.5 MEDIUM |
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows remote attackers to obtain sensitive information from process heap memory via a crafted EMF file, as demonstrated by an EMR_SETDIBITSTODEVICE record with modified Device Independent Bitmap (DIB) dimensions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220. | |||||
CVE-2016-5306 | 1 Symantec | 1 Endpoint Protection Manager | 2017-08-31 | 5.0 MEDIUM | 5.3 MEDIUM |
Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6 MP5 does not properly implement the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by sniffing the network for unintended HTTP traffic on port 8445. |