Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Baby Zoom Wifi Monitor Firmware HIGH 8.8
CVE-2015-2889

Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to gain privileges via manual entry of a Settings URL.

No fix yet
Fix from $1,950 2017-04-10
Liebert Multilink Automated Shutdown HIGH 7.8
CVE-2015-7260

Liebert MultiLink Automated Shutdown v4.2.4 allows local users to gain privileges by replacing the LiebertM executable file.

Patch available
Fix from $1,950 2017-04-10
Integrated Remote Access Controller Firmware HIGH 8.8
CVE-2015-7274

Dell Integrated Remote Access Controller (iDRAC) 6 before 2.80 allows remote attackers to execute arbitrary administrative HTTP commands.

Fix: after 1.99
Fix from $1,950 2017-04-10
Cyberoam Cr25ing Utm Firmware HIGH 8.8
CVE-2016-7786EPSS 7%

Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demo…

No fix yet
Fix from $1,950 2017-04-07
Aironet Access Point MEDIUM 6.7
CVE-2016-9196

A vulnerability in login authentication management in Cisco Aironet 1800, 2800, and 3800 Series Access Point platforms could allow an authenticated, …

Mitigation only
Fix from $1,600 2017-04-07
Mobility Services Engine MEDIUM 6.7
CVE-2016-9197

A vulnerability in the CLI command parser of the Cisco Mobility Express 2800 and 3800 Series Wireless LAN Controllers could allow an authenticated, l…

Mitigation only
Fix from $1,600 2017-04-07
Jviews CRITICAL 9.8
CVE-2015-8965

Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, suc…

Fix: after 8.8
Fix from $2,300 2017-04-06
Wireless Lan Controller Firmware HIGH 7.5
CVE-2017-3832

A vulnerability in the web management interface of Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, remote attacker to ca…

Mitigation only
Fix from $1,950 2017-04-06
Linux Kernel MEDIUM 6.5
CVE-2016-10318

A missing authorization check in the fscrypt_process_policy function in fs/crypto/policy.c in the ext4 and f2fs filesystem encryption support in the …

Fix: after 4.7.3
Fix from $1,600 2017-04-04
Linux Kernel HIGH 7.8
CVE-2014-9922

The eCryptfs subsystem in the Linux kernel before 3.18 allows local users to gain privileges via a large filesystem stack that includes an overlayfs …

Fix: after 7.1.1
Fix from $1,950 2017-04-04
Utps Firmware MEDIUM 6.7
CVE-2016-8769

Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the truncation of UTPS service qu…

No fix yet
Fix from $1,600 2017-04-02
Fusionstorage HIGH 7.5
CVE-2016-8803

The maintenance module in Huawei FusionStorage V100R003C30U1 allows attackers to create documents according to special rules to obtain the OS root pr…

Mitigation only
Fix from $1,950 2017-04-02
Espace Meeting HIGH 7.0
CVE-2014-3222

In Huawei eSpace Meeting with software V100R001C03SPC201 and the earlier versions, attackers that obtain the permissions assigned to common users can…

Mitigation only
Fix from $1,950 2017-04-02
Tecal E9000 Chassis Firmware HIGH 8.8
CVE-2014-9695

The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions could allow a non-super-domain user w…

Mitigation only
Fix from $1,950 2017-04-02
Tecal E9000 Chassis Firmware HIGH 8.8
CVE-2014-9696

The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions allows the operator to modify the use…

Mitigation only
Fix from $1,950 2017-04-02
Logcenter HIGH 8.8
CVE-2015-8671

Huawei LogCenter V100R001C10 could allow an authenticated attacker to tamper with requests using a tool and submit a request to the server for privil…

No fix yet
Fix from $1,950 2017-04-02
S5700 Firmware HIGH 7.5
CVE-2016-2404

Huawei switches S5700, S6700, S7700, S9700 with software V200R001C00SPC300, V200R002C00SPC100, V200R003C00SPC300, V200R005C00SPC500, V200R006C00; S12…

Mitigation only
Fix from $1,950 2017-04-02
Anti Malware Scan Engine HIGH 7.3
CVE-2016-8031

Software Integrity Attacks vulnerability in Intel Security Anti-Virus Engine (AVE) 5200 through 5800 allows local users to bypass local security prot…

Patch available
Fix from $1,950 2017-03-28
Hesiod CRITICAL 9.8
CVE-2016-10152EPSS 7%

The read_config_file function in lib/hesiod.c in Hesiod 3.2.1 falls back to the ".athena.mit.edu" default domain when opening the configuration file …

Fix: after 3.2.1
Fix from $2,300 2017-03-28
GitLab HIGH 8.2
CVE-2016-9469

Multiple versions of GitLab expose a dangerous method to any authenticated user that could lead to the deletion of all Issue and MergeRequest objects…

Patch available
Fix from $1,950 2017-03-28
Cognos Business Intelligence HIGH 8.8
CVE-2016-8960

IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by in…

Patch available
Fix from $1,950 2017-03-27
Galaxy App HIGH 8.0
CVE-2015-0863

GALAXY Apps (aka Samsung Apps, Samsung Updates, or com.sec.android.app.samsungapps) before 14120405.03.012 allows man-in-the-middle attackers to obta…

Mitigation only
Fix from $1,950 2017-03-27
Galaxy App HIGH 8.0
CVE-2015-0864

Samsung Account (AKA com.osp.app.signin) before 1.6.0069 and 2.x before 2.1.0069 allows man-in-the-middle attackers to obtain sensitive information a…

Mitigation only
Fix from $1,950 2017-03-27
Linux 3.4 Sunxi HIGH 7.8
CVE-2016-10225

The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice…

Patch available
Fix from $1,950 2017-03-27
Hadoop MEDIUM 6.5
CVE-2014-0229

Apache Hadoop 0.23.x before 0.23.11 and 2.x before 2.4.1, as used in Cloudera CDH 5.0.x before 5.0.2, do not check authorization for the (1) refreshN…

Mitigation only
Fix from $1,600 2017-03-23
Konke Smart Plug Firmware CRITICAL 9.8
CVE-2014-7279EPSS 12%

The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority"…

No fix yet
Fix from $2,300 2017-03-23
Debian Linux HIGH 7.8
CVE-2016-9775

The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1u…

Mitigation only
Fix from $1,950 2017-03-23
Access Governance Suite HIGH 8.8
CVE-2016-1597

A logged-in user in NetIQ Access Governance Suite 6.0 through 6.4 could escalate privileges to administrator.

Mitigation only
Fix from $1,950 2017-03-23
Edirectory HIGH 7.5
CVE-2016-9167

NDSD in Novell eDirectory before 9.0.2 did not calculate ACLs on LDAP objects across partition boundaries correctly, which could lead to a privilege …

Fix: after 9.0.1
Fix from $1,950 2017-03-23
L2switch MEDIUM 5.3
CVE-2015-1610

hosttracker in OpenDaylight l2switch allows remote attackers to change the host location information by spoofing the MAC address, aka "topology spoof…

Mitigation only
Fix from $1,600 2017-03-20