Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Threat Discovery Appliance HIGH 8.8
CVE-2016-8585EPSS 7%

admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8586EPSS 6%

detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary …

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8589EPSS 6%

log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8590EPSS 6%

log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8591EPSS 6%

log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Threat Discovery Appliance HIGH 8.8
CVE-2016-8592EPSS 6%

log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as …

Fix: after 2.6.1062
Fix from $1,950 2017-04-28
Lshell CRITICAL 9.9
CVE-2016-6902EPSS 5%

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

Patch available
Fix from $2,300 2017-04-24
Lshell CRITICAL 9.9
CVE-2016-6903

lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands.

Patch available
Fix from $2,300 2017-04-24
Kallithea MEDIUM 6.5
CVE-2016-3114

Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access.

Mitigation only
Fix from $1,600 2017-04-24
Lenovo System Update HIGH 7.8
CVE-2015-8110

Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to…

Fix: after 5.07.0013
Fix from $1,950 2017-04-24
Cygwin CRITICAL 9.8
CVE-2016-3067

Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges.

Fix: after 2.4.1-1
Fix from $2,300 2017-04-21
Passenger HIGH 7.8
CVE-2016-10345

In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers …

Fix: after 5.0.30
Fix from $1,950 2017-04-18
Android CRITICAL 9.8
CVE-2016-6727

The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.

Fix: after 7.1.1
Fix from $2,300 2017-04-17
Servicedesk Plus HIGH 8.8
CVE-2016-4889

ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict ac…

Fix: after 8.2
Fix from $1,950 2017-04-14
Fedora HIGH 7.8
CVE-2016-6299

The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.

Patch available
Fix from $1,950 2017-04-14
Android CRITICAL 9.8
CVE-2014-7920

mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921.

Mitigation only
Fix from $2,300 2017-04-13
Android CRITICAL 9.8
CVE-2014-7921

mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920.

Mitigation only
Fix from $2,300 2017-04-13
Firejail HIGH 7.8
CVE-2016-10117

Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

Mitigation only
Fix from $1,950 2017-04-13
Firejail HIGH 7.8
CVE-2016-10119

Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

Mitigation only
Fix from $1,950 2017-04-13
Firejail HIGH 7.8
CVE-2016-10120

Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges.

Mitigation only
Fix from $1,950 2017-04-13
Firejail HIGH 7.8
CVE-2016-10121

Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

Mitigation only
Fix from $1,950 2017-04-13
Firejail HIGH 7.8
CVE-2016-10122

Firejail does not properly clean environment variables, which allows local users to gain privileges.

No fix yet
Fix from $1,950 2017-04-13
Firejail HIGH 7.8
CVE-2016-10123

Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

No fix yet
Fix from $1,950 2017-04-13
Setucocms MEDIUM 6.5
CVE-2016-4896

SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecifie…

Mitigation only
Fix from $1,600 2017-04-12
Linux Kernel HIGH 7.0
CVE-2016-5856

Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerabili…

Fix: after 6.0.1
Fix from $1,950 2017-04-12
Hadoop HIGH 8.8
CVE-2016-6811

In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user.

Fix: after 2.7.3
Fix from $1,950 2017-04-11
Customer Care Software Development Kit HIGH 7.8
CVE-2016-8235

Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with …

Fix: after 2.0.16
Fix from $1,950 2017-04-10
Updates HIGH 8.1
CVE-2016-8237

Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code.

Mitigation only
Fix from $1,950 2017-04-10
Photo Station HIGH 7.8
CVE-2016-10323

Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" co…

Fix: 6.3-2958+
Fix from $1,950 2017-04-10
Aleos Firmware HIGH 8.8
CVE-2016-5071

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root.

No fix yet
Fix from $1,950 2017-04-10