Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-1580 | 1 Mozilla | 1 Firefox | 2016-12-21 | 5.0 MEDIUM | N/A |
Mozilla Firefox before 33.0 does not properly initialize memory for GIF images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers a sequence of rendering operations for truncated GIF data within a CANVAS element. | |||||
CVE-2015-4503 | 1 Mozilla | 1 Firefox | 2016-12-21 | 5.0 MEDIUM | N/A |
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application. | |||||
CVE-2015-4961 | 1 Ibm | 1 Tealeaf Customer Experience | 2016-12-21 | 2.9 LOW | 2.6 LOW |
IBM Tealeaf Customer Experience 8.x before 8.7.1.8847 FP10, 8.8.x before 8.8.0.9049 FP9, 9.0.0 and 9.0.1 before 9.0.1.1117 FP5, 9.0.1A before 9.0.1.5108 FP5, 9.0.2 before 9.0.2.1223 FP3, and 9.0.2A before 9.0.2.5224 FP3 does not encrypt connections between internal servers, which allows remote attackers to obtain sensitive information by sniffing the network for HTTP traffic. | |||||
CVE-2015-4980 | 1 Ibm | 1 Websphere Commerce | 2016-12-21 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in IBM WebSphere Commerce 7.0.0.6 through 7.0.0.9 allows remote authenticated users to obtain sensitive personal information via unknown vectors. | |||||
CVE-2016-1787 | 1 Apple | 1 Mac Os X Server | 2016-12-19 | 5.0 MEDIUM | 5.3 MEDIUM |
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors. | |||||
CVE-2016-6852 | 1 Open-xchange | 1 Open-xchange Appsuite | 2016-12-16 | 4.3 MEDIUM | 4.3 MEDIUM |
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev8. Users can provide local file paths to the RSS reader; the response and error code give hints about whether the provided file exists or not. Attackers may discover specific system files or library versions on the middleware server to prepare further attacks. | |||||
CVE-2016-6364 | 1 Cisco | 1 Unified Communications Manager | 2016-12-12 | 5.0 MEDIUM | 7.5 HIGH |
The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified API calls, aka Bug ID CSCux67855. | |||||
CVE-2015-5864 | 1 Apple | 1 Mac Os X | 2016-12-09 | 2.1 LOW | N/A |
IOAudioFamily in Apple OS X before 10.11 allows local users to obtain sensitive kernel memory-layout information via unspecified vectors. | |||||
CVE-2015-5836 | 1 Apple | 1 Mac Os X | 2016-12-09 | 4.3 MEDIUM | N/A |
Apple Online Store Kit in Apple OS X before 10.11 improperly validates iCloud keychain item ACLs, which allows attackers to obtain access to keychain items via a crafted app. | |||||
CVE-2015-5853 | 1 Apple | 1 Mac Os X | 2016-12-09 | 3.3 LOW | N/A |
AirScan in Apple OS X before 10.11 allows man-in-the-middle attackers to obtain eSCL packet payload data via unspecified vectors. | |||||
CVE-2015-5854 | 1 Apple | 1 Mac Os X | 2016-12-09 | 2.1 LOW | N/A |
The backup implementation in Time Machine in Apple OS X before 10.11 allows local users to obtain access to keychain items via unspecified vectors. | |||||
CVE-2015-5865 | 1 Apple | 1 Mac Os X | 2016-12-09 | 4.3 MEDIUM | N/A |
IOGraphics in Apple OS X before 10.11 allows attackers to obtain sensitive kernel memory-layout information via a crafted app. | |||||
CVE-2015-5870 | 1 Apple | 1 Mac Os X | 2016-12-09 | 2.1 LOW | N/A |
The debugging interfaces in the kernel in Apple OS X before 10.11 allow local users to obtain sensitive memory-layout information via unspecified vectors. | |||||
CVE-2015-5878 | 1 Apple | 1 Mac Os X | 2016-12-09 | 2.1 LOW | N/A |
Notes in Apple OS X before 10.11 misparses links, which allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-6328 | 1 Cisco | 1 Prime Collaboration Assurance | 2016-12-09 | 6.8 MEDIUM | N/A |
The web framework in Cisco Prime Collaboration Assurance (PCA) 10.5(1) allows remote authenticated users to bypass intended access restrictions and read arbitrary files via a crafted URL, aka Bug ID CSCus88380. | |||||
CVE-2015-4543 | 1 Emc | 1 Rsa Archer Grc | 2016-12-08 | 4.0 MEDIUM | N/A |
EMC RSA Archer GRC 5.x before 5.5.3 uses cleartext for stored passwords in unspecified circumstances, which allows remote authenticated users to obtain sensitive information by reading database fields. | |||||
CVE-2015-6843 | 1 Emc | 1 Sourceone Email Supervisor | 2016-12-08 | 5.0 MEDIUM | N/A |
Reviewer in EMC SourceOne Email Supervisor before 7.2 does not properly limit attempts to authenticate, which makes it easier for remote attackers to obtain access via a brute-force approach. | |||||
CVE-2015-7032 | 1 Apple | 4 Iwork, Keynote, Numbers and 1 more | 2016-12-08 | 4.3 MEDIUM | N/A |
The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document. | |||||
CVE-2015-7322 | 1 Juniper | 1 Pulse Connect Secure | 2016-12-07 | 5.0 MEDIUM | N/A |
The Secure Meeting (Pulse Collaboration) in Pulse Connect Secure (formerly Juniper Junos Pulse) before 7.1R22.1, 7.4, 8.0 before 8.0R11, and 8.1 before 8.1R3 provides different messages for attempts to join a meeting depending on the status of the meeting, which allows remote attackers to enumerate valid meeting ids via a series of requests. | |||||
CVE-2015-5884 | 1 Apple | 1 Mac Os X | 2016-12-07 | 3.3 LOW | N/A |
The Mail Drop feature in Mail in Apple OS X before 10.11 mishandles encryption parameters for attachments, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during transmission of an S/MIME e-mail message with a large attachment. |