Total
6955 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2014-9252 | 1 Zenoss | 1 Zenoss Core | 2016-03-21 | 2.1 LOW | N/A |
Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416. | |||||
CVE-2014-9250 | 1 Zenoss | 1 Zenoss Core | 2016-03-21 | 5.0 MEDIUM | N/A |
Zenoss Core through 5 Beta 3 does not include the HTTPOnly flag in a Set-Cookie header for the authentication cookie, which makes it easier for remote attackers to obtain credential information via script access to this cookie, aka ZEN-10418. | |||||
CVE-2014-9247 | 1 Zenoss | 1 Zenoss Core | 2016-03-21 | 4.0 MEDIUM | N/A |
Zenoss Core through 5 Beta 3 allows remote authenticated users to obtain sensitive (1) user account, (2) e-mail address, and (3) role information by visiting the ZenUsers (aka User Manager) page, aka ZEN-15389. | |||||
CVE-2014-9245 | 1 Zenoss | 1 Zenoss Core | 2016-03-21 | 5.0 MEDIUM | N/A |
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382. | |||||
CVE-2016-1562 | 1 Dte Energy | 1 Insight | 2016-03-18 | 4.0 MEDIUM | 4.3 MEDIUM |
The REST API in the DTE Energy Insight application before 1.7.8 for Android allows remote authenticated users to obtain unspecified customer information via a SQL expression in the filter parameter. | |||||
CVE-2016-1357 | 1 Cisco | 1 Cisco Policy Suite | 2016-03-14 | 5.0 MEDIUM | 5.3 MEDIUM |
The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut85211. | |||||
CVE-2016-0811 | 1 Google | 1 Android | 2016-03-14 | 7.8 HIGH | 7.5 HIGH |
Integer overflow in the BnCrypto::onTransact function in media/libmedia/ICrypto.cpp in libmediaplayerservice in Android 6.x before 2016-02-01 allows attackers to obtain sensitive information, and consequently bypass an unspecified protection mechanism, by triggering an improper size calculation, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 25800375. | |||||
CVE-2016-0232 | 1 Ibm | 1 Financial Transaction Manager | 2016-03-10 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading README files. | |||||
CVE-2016-0231 | 1 Ibm | 1 Financial Transaction Manager | 2016-03-10 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Financial Transaction Manager (FTM) for ACH Services, Check Services and Corporate Payment Services (CPS) 3.0.0 before FP12 allows remote authenticated users to obtain sensitive information by reading exception details in error logs. | |||||
CVE-2015-4991 | 1 Ibm | 1 Spss Modeler | 2016-03-10 | 2.1 LOW | 4.0 MEDIUM |
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows local users to obtain sensitive information by reading a dump file. | |||||
CVE-2016-1342 | 1 Cisco | 1 Firepower Management Center | 2016-03-04 | 5.0 MEDIUM | 5.3 MEDIUM |
The device login page in Cisco FirePOWER Management Center 5.3 through 6.0.0.1 allows remote attackers to obtain potentially sensitive software-version information by reading help files, aka Bug ID CSCuy36654. | |||||
CVE-2015-7444 | 1 Ibm | 1 Websphere Commerce | 2016-03-01 | 5.0 MEDIUM | 5.3 MEDIUM |
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-0867 | 1 Carel | 1 Plantvisor Enhanced | 2016-03-01 | 7.8 HIGH | 7.5 HIGH |
CAREL PlantVisorEnhanced allows remote attackers to bypass intended access restrictions via a direct file request. | |||||
CVE-2016-1323 | 1 Cisco | 1 Spark | 2016-02-29 | 4.0 MEDIUM | 4.3 MEDIUM |
The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048. | |||||
CVE-2015-8488 | 1 Cybozu | 1 Office | 2016-02-22 | 4.3 MEDIUM | 4.3 MEDIUM |
Cybozu Office 10.3.0 allows remote attackers to read image files via a crafted e-mail message, a different vulnerability than CVE-2015-8487. | |||||
CVE-2015-8487 | 1 Cybozu | 1 Office | 2016-02-22 | 2.6 LOW | 4.3 MEDIUM |
Cybozu Office 9.0.0 through 10.3 allows remote attackers to discover CSRF tokens via unspecified vectors, a different vulnerability than CVE-2015-8488. | |||||
CVE-2015-7680 | 1 Ipswitch | 1 Moveit Dmz | 2016-02-18 | 5.0 MEDIUM | 5.3 MEDIUM |
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx. | |||||
CVE-2016-0958 | 4 Adobe, Apple, Linux and 1 more | 4 Experience Manager, Mac Os X, Linux Kernel and 1 more | 2016-02-18 | 7.8 HIGH | 7.5 HIGH |
Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0 might allow remote attackers to have an unspecified impact via a crafted serialized Java object. | |||||
CVE-2015-7675 | 1 Ipswitch | 2 Moveit Dmz, Moveit Mobile | 2016-02-18 | 4.0 MEDIUM | 6.5 MEDIUM |
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx. | |||||
CVE-2015-2005 | 1 Ibm | 1 Qradar Security Information And Event Manager | 2016-02-18 | 5.0 MEDIUM | 5.3 MEDIUM |
IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 and 7.2.x before 7.2.5 Patch 6 does not properly expire sessions, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation. |