Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox HIGH 8.0
CVE-2016-9070

A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operati…

Fix: 50+
Fix from $1,950 2018-06-11
Firefox HIGH 7.5
CVE-2016-9073

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox …

Fix: 50.0+
Fix from $1,950 2018-06-11
Firefox CRITICAL 9.8
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This…

Fix: 50.0+
Fix from $2,300 2018-06-11
Firefox HIGH 7.8
CVE-2016-5295

This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozil…

Fix: 50.0+
Fix from $1,950 2018-06-11
Suse Linux Enterprise Server CRITICAL 9.8
CVE-2011-3172

A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are S…

Fix: 12.0+
Fix from $2,300 2018-06-08
Prime Collaboration HIGH 8.8
CVE-2018-0336

A vulnerability in the batch provisioning feature of Cisco Prime Collaboration Provisioning could allow an authenticated, remote attacker to escalate…

Mitigation only
Fix from $1,950 2018-06-07
Wide Area Application Services MEDIUM 6.7
CVE-2018-0352

A vulnerability in the Disk Check Tool (disk-check.sh) for Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local a…

Mitigation only
Fix from $1,600 2018-06-07
Prime Collaboration HIGH 8.8
CVE-2018-0317

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to escalate their …

Fix: after 12.2
Fix from $1,950 2018-06-07
Prime Collaboration HIGH 8.8
CVE-2018-0322

A vulnerability in the web management interface of Cisco Prime Collaboration Provisioning (PCP) could allow an authenticated, remote attacker to modi…

Fix: after 12.1
Fix from $1,950 2018-06-07
Websphere Application Server HIGH 7.8
CVE-2013-3024

IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initializatio…

Fix: after 8.5.0.2
Fix from $1,950 2018-05-24
Jboss Enterprise Application Platform HIGH 7.8
CVE-2016-8656

Jboss jbossas before versions 5.2.0-23, 6.4.13, 7.0.5 is vulnerable to an unsafe file handling in the jboss init script which could result in local p…

Mitigation only
Fix from $1,950 2018-05-22
Webaccess CRITICAL 9.8
CVE-2018-7505

In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAcc…

Fix: 8.3.1+
Fix from $2,300 2018-05-15
Paypal HIGH 8.1
CVE-2013-7202

The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.

Fix: after 5.3
Fix from $1,950 2018-04-27
Enlightenment HIGH 7.8
CVE-2014-1845

An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the…

Fix: 0.17.6+
Fix from $1,950 2018-04-27
Enlightenment HIGH 7.8
CVE-2014-1846

Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.

Fix: 0.17.6+
Fix from $1,950 2018-04-27
Collected Information Export CRITICAL 9.8
CVE-2014-2552

Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers…

Patch available
Fix from $2,300 2018-04-27
V3 Internet Security HIGH 7.8
CVE-2013-3947

Buffer overflow in MedCoreD.sys in AhnLab V3 Internet Security 8.0.7.5 (Build 1373) allows local users to gain privileges via a crafted 0xA3350014 IO…

Mitigation only
Fix from $1,950 2018-04-24
Mdm9206 Firmware HIGH 7.8
CVE-2016-10451

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, M…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware CRITICAL 9.8
CVE-2016-10457

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9650, MSM8909W, S…

Mitigation only
Fix from $2,300 2018-04-18
Fsm9055 Firmware CRITICAL 9.8
CVE-2015-9196

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Small Cell SoC FSM9055, MDM9635M, SD 400, and SD 800, …

Mitigation only
Fix from $2,300 2018-04-18
Mdm9615 Firmware CRITICAL 9.8
CVE-2014-10057

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 21…

Mitigation only
Fix from $2,300 2018-04-18
Sd 210 Firmware HIGH 7.5
CVE-2014-10058

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 425, SD 427, SD 430, SD 4…

Mitigation only
Fix from $1,950 2018-04-18
Mdm9206 Firmware CRITICAL 9.8
CVE-2014-10054

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM96…

Mitigation only
Fix from $2,300 2018-04-18
Openstage Sip HIGH 7.5
CVE-2014-8421

Unify (former Siemens) OpenStage SIP and OpenScape Desk Phone IP V3 devices before R3.32.0 allow remote attackers to gain super-user privileges by le…

Mitigation only
Fix from $1,950 2018-04-12
Buddypress MEDIUM 6.5
CVE-2014-1889EPSS 11%

The Group creation process in the Buddypress plugin before 1.9.2 for WordPress allows remote authenticated users to gain control of arbitrary groups …

Fix: 1.9.2+
Fix from $1,600 2018-04-10
Opendocman HIGH 8.8
CVE-2014-1946

OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restric…

Fix: after 1.2.7
Fix from $1,950 2018-04-10
S3dvt HIGH 7.8
CVE-2013-6876

The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveragi…

Fix: after 0.2.2
Fix from $1,950 2018-04-06
S3dvt HIGH 7.8
CVE-2014-1226

The pipe_init_terminal function in main.c in s3dvt allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and e…

Fix: after 0.2.2
Fix from $1,950 2018-04-06
Android HIGH 7.0
CVE-2015-9016

In blk_mq_tag_to_rq in blk-mq.c in the upstream kernel, there is a possible use after free due to a race condition when a request has been previously…

Patch available
Fix from $1,950 2018-04-05
Android HIGH 7.8
CVE-2016-8482

An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-C…

Patch available
Fix from $1,950 2018-04-05