Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
T Coffee MEDIUM 5.5
CVE-2015-8621

t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.

Fix: after 11.00.8cbe486-1
Fix from $1,600 2017-08-07
Vsn300 Firmware MEDIUM 6.5
CVE-2017-7916

A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger …

Fix: after 1.8.15
Fix from $1,600 2017-08-07
Manageengine Desktop Central CRITICAL 9.8
CVE-2015-2560EPSS 15%

Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModif…

No fix yet
Fix from $2,300 2017-08-02
Gigacc Office MEDIUM 6.5
CVE-2016-7845

GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized …

Mitigation only
Fix from $1,600 2017-08-02
Android MEDIUM 6.2
CVE-2016-10398

Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Tr…

Mitigation only
Fix from $1,600 2017-07-17
Elastic Services Controller CRITICAL 9.8
CVE-2017-6713

A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access …

Mitigation only
Fix from $2,300 2017-07-06
Altavault HIGH 8.1
CVE-2016-3998

NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service vi…

Fix: after 4.1
Fix from $1,950 2017-07-03
Portage HIGH 7.1
CVE-2004-2778

Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to…

Mitigation only
Fix from $1,950 2017-06-27
Kamailio HIGH 7.8
CVE-2015-1591

The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges.

Fix: after 4.2.0-1.1
Fix from $1,950 2017-06-27
Gluster Storage HIGH 7.8
CVE-2015-1795

Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root.

Mitigation only
Fix from $1,950 2017-06-27
Qradar Security Information And Event Manager MEDIUM 5.9
CVE-2016-9972

IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport …

Patch available
Fix from $1,600 2017-06-27
Forticlient HIGH 8.8
CVE-2016-8493

In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.

Mitigation only
Fix from $1,950 2017-06-26
Kibana MEDIUM 6.5
CVE-2016-10364

With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any …

Mitigation only
Fix from $1,600 2017-06-16
Android HIGH 7.8
CVE-2016-10341

In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended.

No fix yet
Fix from $1,950 2017-06-13
Maximo Asset Management HIGH 8.8
CVE-2016-9984

IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM…

Mitigation only
Fix from $1,950 2017-06-13
Mouse Suite HIGH 7.8
CVE-2015-4596

Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges.

Fix: after 6.72
Fix from $1,950 2017-06-13
Device Data Encryption Program HIGH 7.8
CVE-2016-7818

Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program V…

Patch available
Fix from $1,950 2017-06-09
Cloudforms HIGH 8.8
CVE-2016-4471

ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code.

Fix: after 4.0
Fix from $1,950 2017-06-08
Anyconnect Secure Mobility Client HIGH 7.8
CVE-2017-6638

A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to …

Fix: after 4.4.00243
Fix from $1,950 2017-06-08
Prime Data Center Network Manager CRITICAL 9.8
CVE-2017-6640EPSS 11%

A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administr…

Mitigation only
Fix from $2,300 2017-06-08
Lenovo Service Bridge HIGH 7.8
CVE-2016-8228

In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.

Mitigation only
Fix from $1,950 2017-06-04
Cloud Foundry Uaa Bosh HIGH 8.1
CVE-2016-3084

The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server…

Fix: after 236
Fix from $1,950 2017-05-25
Bosh Stemcell CRITICAL 9.0
CVE-2016-4435

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read…

Fix: after 3232.4
Fix from $2,300 2017-05-25
Spring Framework HIGH 7.5
CVE-2016-5007

Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for m…

Mitigation only
Fix from $1,950 2017-05-25
P7 L09 Firmware HIGH 7.8
CVE-2015-8089

The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows loc…

Mitigation only
Fix from $1,950 2017-05-23
Solution Center HIGH 7.8
CVE-2016-1876

The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors.

Fix: after 3.3.0001
Fix from $1,950 2017-05-23
Open Source Security Information Management MEDIUM 6.7
CVE-2015-4045

The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script.

Fix: after 5.0
Fix from $1,600 2017-05-23
Powerplay Gallery HIGH 7.5
CVE-2015-5682

upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targe…

No fix yet
Fix from $1,950 2017-05-23
Marketing Platform HIGH 8.8
CVE-2016-6112

IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain admi…

Mitigation only
Fix from $1,950 2017-05-22
Prime Collaboration Provisioning MEDIUM 6.5
CVE-2017-6635EPSS 10%

A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote …

Mitigation only
Fix from $1,600 2017-05-22