Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Fso Frameworkd HIGH 7.8
CVE-2014-8156

The D-Bus security policy files in /etc/dbus-1/system.d/*.conf in fso-gsmd 0.12.0-3, fso-frameworkd 0.9.5.9+git20110512-4, and fso-usaged 0.12.0-2 as…

Mitigation only
Fix from $1,950 2017-09-26
Android HIGH 7.0
CVE-2016-5868

drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted app…

Fix: after 8.0
Fix from $1,950 2017-09-25
Kupu MEDIUM 6.8
CVE-2015-7317

Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.

Fix: after 1.4.16
Fix from $1,600 2017-09-25
Unified Customer Voice Portal HIGH 8.8
CVE-2017-12214

A vulnerability in the Operations, Administration, Maintenance, and Provisioning (OAMP) credential reset functionality for Cisco Unified Customer Voi…

Mitigation only
Fix from $1,950 2017-09-21
Security Siteprotector System HIGH 7.0
CVE-2015-0162

IBM Security SiteProtector System 3.0, 3.1, and 3.1.1 allows local users to gain privileges.

No fix yet
Fix from $1,950 2017-09-20
Realpresence Resource Manager CRITICAL 9.8
CVE-2015-4683EPSS 7%

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by lever…

Fix: after 8.3.2
Fix from $2,300 2017-09-19
Realpresence Resource Manager HIGH 7.0
CVE-2015-4685

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /va…

Fix: after 8.3.2
Fix from $1,950 2017-09-19
Netsweeper MEDIUM 5.3
CVE-2014-9610

Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from th…

Fix: after 3.1.9
Fix from $1,600 2017-09-19
Malware Analysis Appliance CRITICAL 9.3
CVE-2015-4523

Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechani…

Fix: after 4.2
Fix from $2,300 2017-09-11
Ossec HIGH 7.0
CVE-2015-3222

syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.

No fix yet
Fix from $1,950 2017-09-07
E5756s Firmware CRITICAL 9.8
CVE-2015-4629

Huawei E5756S before V200R002B146D23SP00C00 allows remote attackers to read device configuration information, enable PIN/PUK authentication, and perf…

Mitigation only
Fix from $2,300 2017-09-07
Kamailio HIGH 7.8
CVE-2015-1590

The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.

Fix: after 4.2.8
Fix from $1,950 2017-09-07
Googlemaps HIGH 7.5
CVE-2013-7432

The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.

Fix: after 3.0
Fix from $1,950 2017-08-29
Load Balancer CRITICAL 9.8
CVE-2014-8428

Privilege escalation vulnerability in Barracuda Load Balancer 5.0.0.015 via the use of an improperly protected SSH key.

No fix yet
Fix from $2,300 2017-08-28
Fortimanager Firmware HIGH 7.8
CVE-2015-3617

Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.

Mitigation only
Fix from $1,950 2017-08-22
Nshield Connect Firmware MEDIUM 6.8
CVE-2015-1878

Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary d…

Fix: after 11.30
Fix from $1,600 2017-08-18
Attic MEDIUM 6.5
CVE-2015-4082

attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted …

Fix: after 0.14
Fix from $1,600 2017-08-18
Android HIGH 7.0
CVE-2016-5853

In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not …

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.0
CVE-2016-5859

In a sound driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length…

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.0
CVE-2016-5860

In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large lengt…

Patch available
Fix from $1,950 2017-08-16
Android HIGH 8.8
CVE-2016-5861

In a display driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, a variable controlled by userspace is used to …

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.0
CVE-2016-5862

When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type …

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.8
CVE-2016-5863

In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, several sanity checks are missing which can le…

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.8
CVE-2016-5864

In an audio driver function in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, some parameters are from userspace, an…

Patch available
Fix from $1,950 2017-08-16
Android HIGH 7.0
CVE-2016-5867

In a sound driver in Android for MSM, Firefox OS for MSM, QRD Android, some variables are from userspace and values can be chosen that could result i…

Patch available
Fix from $1,950 2017-08-16
Elasticsearch HIGH 7.5
CVE-2015-4165

The snapshot API in Elasticsearch before 1.6.0 when another application exists on the system that can read Lucene files and execute code from them, i…

No fix yet
Fix from $1,950 2017-08-09
Mod Nss CRITICAL 9.8
CVE-2015-5244

The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.

Fix: after 1.0.11
Fix from $2,300 2017-08-07
Duplicator HIGH 8.2
CVE-2014-9262EPSS 7%

The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.

Fix: after 0.5.8
Fix from $1,950 2017-08-07
Grml Debootstrap HIGH 7.5
CVE-2015-1378

cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is wr…

Mitigation only
Fix from $1,950 2017-08-07
Ctools HIGH 7.5
CVE-2015-7875

ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are use…

Mitigation only
Fix from $1,950 2017-08-07