Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-1764 | 1 Apple | 1 Mac Os X | 2016-12-02 | 4.3 MEDIUM | 4.3 MEDIUM |
The Content Security Policy (CSP) implementation in Messages in Apple OS X before 10.11.4 allows remote attackers to obtain sensitive information via a javascript: URL. | |||||
CVE-2016-1637 | 1 Google | 1 Chrome | 2016-12-02 | 4.3 MEDIUM | 6.5 MEDIUM |
The SkATan2_255 function in effects/gradients/SkSweepGradient.cpp in Skia, as used in Google Chrome before 49.0.2623.75, mishandles arctangent calculations, which allows remote attackers to obtain sensitive information via a crafted web site. | |||||
CVE-2016-1035 | 1 Adobe | 1 Robohelp | 2016-12-02 | 5.0 MEDIUM | 7.5 HIGH |
Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1325 | 1 Cisco | 3 Dpc3939 Wireless Residential Voice Gateway, Dpc3939 Wireless Residential Voice Gateway Firmware, Dpc3941 Wireless Residential Voice Gateway | 2016-12-02 | 7.8 HIGH | 7.5 HIGH |
The administration interface on Cisco DPC3939B and DPC3941 devices allows remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCus49506. | |||||
CVE-2016-1360 | 1 Cisco | 1 Prime Lan Management Solution | 2016-12-02 | 3.0 LOW | 7.1 HIGH |
Cisco Prime LAN Management Solution (LMS) through 4.2.5 uses the same database decryption key across different customers' installations, which allows local users to obtain cleartext data by leveraging console connectivity, aka Bug ID CSCuw85390. | |||||
CVE-2016-1378 | 1 Cisco | 1 Ios | 2016-12-02 | 5.0 MEDIUM | 5.3 MEDIUM |
Cisco IOS before 15.2(2)E1 on Catalyst switches allows remote attackers to obtain potentially sensitive software-version information via a request to the Network Mobility Services Protocol (NMSP) port, aka Bug ID CSCum62591. | |||||
CVE-2015-8791 | 1 Matroska | 1 Libebml | 2016-12-02 | 4.3 MEDIUM | 4.3 MEDIUM |
The EbmlElement::ReadCodedSizeValue function in libEBML before 1.3.3 allows context-dependent attackers to obtain sensitive information from process heap memory via a crafted length value in an EBML id, which triggers an invalid memory access. | |||||
CVE-2015-7915 | 1 Sauter | 1 Moduweb Vision | 2016-12-02 | 10.0 HIGH | 9.8 CRITICAL |
Sauter EY-WS505F0x0 moduWeb Vision before 1.6.0 sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
CVE-2015-3231 | 2 Debian, Drupal | 2 Debian Linux, Drupal | 2016-12-02 | 4.0 MEDIUM | N/A |
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache. | |||||
CVE-2015-2855 | 1 Blue Coat | 8 Ssl Visibility Appliance Sv1800, Ssl Visibility Appliance Sv1800 Firmware, Ssl Visibility Appliance Sv2800 and 5 more | 2016-12-02 | 4.3 MEDIUM | N/A |
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, a different vulnerability than CVE-2015-4138. | |||||
CVE-2015-3010 | 1 Ceph | 1 Ceph-deploy | 2016-12-02 | 2.1 LOW | N/A |
ceph-deploy before 1.5.23 uses weak permissions (644) for ceph/ceph.client.admin.keyring, which allows local users to obtain sensitive information by reading the file. | |||||
CVE-2015-2762 | 1 Websense | 1 Triton Ap Web | 2016-12-02 | 5.0 MEDIUM | N/A |
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication. | |||||
CVE-2015-2771 | 1 Websense | 2 Triton Ap Email, V-series Appliances | 2016-12-02 | 5.0 MEDIUM | N/A |
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-2121 | 1 Hp | 1 Network Virtualization | 2016-12-02 | 7.8 HIGH | N/A |
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569. | |||||
CVE-2015-2209 | 1 Dlguard | 1 Dlguard | 2016-12-02 | 5.0 MEDIUM | N/A |
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php. | |||||
CVE-2015-2214 | 1 Netcat | 1 Netcat | 2016-12-02 | 5.0 MEDIUM | N/A |
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php. | |||||
CVE-2015-2335 | 1 Mybb | 1 Mybb | 2016-12-02 | 5.0 MEDIUM | N/A |
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors. | |||||
CVE-2015-1127 | 1 Apple | 1 Safari | 2016-12-02 | 2.1 LOW | N/A |
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries. | |||||
CVE-2014-9759 | 1 Mantisbt | 1 Mantisbt | 2016-12-02 | 5.0 MEDIUM | 5.3 MEDIUM |
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request. | |||||
CVE-2016-8100 | 1 Intel | 1 Integrated Performance Primitives | 2016-12-02 | 2.1 LOW | 5.5 MEDIUM |
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack. |