Total
8075 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-2771 | 1 Websense | 2 Triton Ap Email, V-series Appliances | 2016-12-03 | 5.0 MEDIUM | N/A |
The Mail Server in Websense TRITON AP-EMAIL and V-Series appliances before 8.0.0 uses plaintext credentials, which allows remote attackers to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-2762 | 1 Websense | 1 Triton Ap Web | 2016-12-03 | 5.0 MEDIUM | N/A |
Websense TRITON AP-WEB before 8.0.0 allows remote attackers to enumerate Windows domain user accounts via vectors related to HTTP authentication. | |||||
CVE-2015-2335 | 1 Mybb | 1 Mybb | 2016-12-03 | 5.0 MEDIUM | N/A |
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors. | |||||
CVE-2015-2214 | 1 Netcat | 1 Netcat | 2016-12-03 | 5.0 MEDIUM | N/A |
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php. | |||||
CVE-2015-2209 | 1 Dlguard | 1 Dlguard | 2016-12-03 | 5.0 MEDIUM | N/A |
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php. | |||||
CVE-2015-2121 | 1 Hp | 1 Network Virtualization | 2016-12-03 | 7.8 HIGH | N/A |
HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569. | |||||
CVE-2015-1127 | 1 Apple | 1 Safari | 2016-12-03 | 2.1 LOW | N/A |
The private-browsing implementation in WebKit in Apple Safari before 6.2.5, 7.x before 7.1.5, and 8.x before 8.0.5 places browsing history into an index, which might allow local users to obtain sensitive information by reading index entries. | |||||
CVE-2014-9759 | 1 Mantisbt | 1 Mantisbt | 2016-12-03 | 5.0 MEDIUM | 5.3 MEDIUM |
Incomplete blacklist vulnerability in the config_is_private function in config_api.php in MantisBT 1.3.x before 1.3.0 allows remote attackers to obtain sensitive master salt configuration information via a SOAP API request. | |||||
CVE-2016-8100 | 1 Intel | 1 Integrated Performance Primitives | 2016-12-02 | 2.1 LOW | 5.5 MEDIUM |
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack. | |||||
CVE-2016-7561 | 1 Fortinet | 1 Fortiwlc | 2016-12-02 | 4.0 MEDIUM | 7.2 HIGH |
Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow administrators to obtain sensitive user credentials by reading the pam.log file. | |||||
CVE-2016-7917 | 1 Linux | 1 Linux Kernel | 2016-12-02 | 4.3 MEDIUM | 5.0 MEDIUM |
The nfnetlink_rcv_batch function in net/netfilter/nfnetlink.c in the Linux kernel before 4.5 does not check whether a batch message's length field is large enough, which allows local users to obtain sensitive information from kernel memory or cause a denial of service (infinite loop or out-of-bounds read) by leveraging the CAP_NET_ADMIN capability. | |||||
CVE-2016-1852 | 1 Apple | 1 Iphone Os | 2016-12-02 | 2.1 LOW | 2.4 LOW |
Siri in Apple iOS before 9.3.2 does not block data detectors within results in the lock-screen state, which allows physically proximate attackers to obtain sensitive contact and photo information via unspecified vectors. | |||||
CVE-2016-1853 | 1 Apple | 1 Mac Os X | 2016-12-02 | 5.0 MEDIUM | 7.5 HIGH |
Tcl in Apple OS X before 10.11.5 allows remote attackers to obtain sensitive information by leveraging SSLv2 support. | |||||
CVE-2016-3012 | 1 Ibm | 2 Api Connect, Network Path Manager | 2016-12-01 | 5.0 MEDIUM | 7.5 HIGH |
IBM API Connect (aka APIConnect) before 5.0.3.0 with NPM before 2.2.8 includes certain internal server credentials in the software package, which might allow remote attackers to bypass intended access restrictions by leveraging knowledge of these credentials. | |||||
CVE-2016-2025 | 1 Hp | 1 Service Manager | 2016-12-01 | 5.0 MEDIUM | 7.5 HIGH |
HPE Service Manager 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, and 9.41 allows remote attackers to obtain sensitive information via unspecified vectors, related to the Web Client, Service Request Catalog, and Mobility components. | |||||
CVE-2016-2023 | 1 Hp | 1 Restful Interface Tool | 2016-12-01 | 2.1 LOW | 5.5 MEDIUM |
HPE RESTful Interface Tool 1.40 allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-2015 | 1 Hp | 1 System Management Homepage | 2016-12-01 | 6.6 MEDIUM | 7.1 HIGH |
HPE System Management Homepage before 7.5.5 allows local users to obtain sensitive information or modify data via unspecified vectors. | |||||
CVE-2016-2013 | 1 Hp | 1 Network Node Manager I | 2016-12-01 | 4.0 MEDIUM | 6.5 MEDIUM |
HPE Network Node Manager i (NNMi) 9.20, 9.23, 9.24, 9.25, 10.00, and 10.01 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2016-1849 | 1 Apple | 2 Iphone Os, Safari | 2016-12-01 | 2.1 LOW | 3.3 LOW |
The "Clear History and Website Data" feature in Apple Safari before 9.1.1, as used in iOS before 9.3.2 and other products, mishandles the deletion of browsing history, which might allow local users to obtain sensitive information by leveraging read access to a Safari directory. | |||||
CVE-2016-1796 | 1 Apple | 1 Mac Os X | 2016-12-01 | 4.3 MEDIUM | 3.3 LOW |
Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to obtain sensitive kernel memory-layout information or cause a denial of service (out-of-bounds memory access) via a crafted app. |