Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Dotnetnuke CRITICAL 9.8
CVE-2015-2794EPSS 75%

The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct …

Fix: after 07.04.00
Fix from $2,300 2017-02-06
Linux Kernel CRITICAL 9.8
CVE-2016-10150EPSS 10%

Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4.8.13 allows host OS users to…

Fix: 4.8.13+
Fix from $2,300 2017-02-06
Emc Data Domain Os MEDIUM 6.7
CVE-2016-8216

EMC Data Domain OS (DD OS) 5.4 all versions, EMC Data Domain OS (DD OS) 5.5 family all versions prior to 5.5.5.0, EMC Data Domain OS (DD OS) 5.6 fami…

Mitigation only
Fix from $1,600 2017-02-03
Isilon Onefs HIGH 7.2
CVE-2016-9871

EMC Isilon OneFS 7.2.1.0 - 7.2.1.3, EMC Isilon OneFS 7.2.0.x, EMC Isilon OneFS 7.1.1.0 - 7.1.1.10, EMC Isilon OneFS 7.1.0.x is affected by a privileg…

No fix yet
Fix from $1,950 2017-02-03
Aix HIGH 7.8
CVE-2016-3053

IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges.

No fix yet
Fix from $1,950 2017-02-01
Merge System CRITICAL 9.8
CVE-2016-9403

newreply.php in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 allows remote attackers to have unspecified impact by leve…

Fix: after 1.8.6
Fix from $2,300 2017-01-31
Smart Protection Server HIGH 7.8
CVE-2016-6268

Trend Micro Smart Protection Server 2.5 before build 2200, 2.6 before build 2106, and 3.0 before build 1330 allows local webserv users to execute arb…

Patch available
Fix from $1,950 2017-01-30
Xen HIGH 7.8
CVE-2016-10013

Xen through 4.8.x allows local 64-bit x86 HVM guest OS users to gain privileges by leveraging mishandling of SYSCALL singlestep during emulation.

Fix: after 4.8.0
Fix from $1,950 2017-01-26
Cloudvision Portal HIGH 8.8
CVE-2016-9012

CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the manageme…

Fix: after 2016.1.2.0
Fix from $1,950 2017-01-23
Xenserver HIGH 7.8
CVE-2016-9382

Xen 4.0.x through 4.7.x mishandle x86 task switches to VM86 mode, which allows local 32-bit x86 HVM guest OS users to gain privileges or cause a deni…

Patch available
Fix from $1,950 2017-01-23
Xenserver HIGH 7.8
CVE-2016-9386

The x86 emulator in Xen does not properly treat x86 NULL segments as unusable when accessing memory, which might allow local HVM guest users to gain …

Patch available
Fix from $1,950 2017-01-23
GitLab HIGH 8.8
CVE-2016-4340EPSS 10%

The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8.3.8, and 8.2.0 through 8.2.4…

Patch available
Fix from $1,950 2017-01-23
Skype HIGH 7.8
CVE-2016-5720

Multiple untrusted search path vulnerabilities in Microsoft Skype allow local users to execute arbitrary code and conduct DLL hijacking attacks via a…

Mitigation only
Fix from $1,950 2017-01-23
Owncloud MEDIUM 5.9
CVE-2016-5876

ownCloud server before 8.2.6 and 9.x before 9.0.3, when the gallery app is enabled, allows remote attackers to download arbitrary images via a direct…

Fix: after 8.2.5
Fix from $1,600 2017-01-23
Systemd HIGH 7.8
CVE-2016-10156

A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd timers features, allowing local …

Patch available
Fix from $1,950 2017-01-23
Moodle MEDIUM 5.3
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

Fix: after 2.7.16
Fix from $1,600 2017-01-20
Service Desk Management HIGH 8.1
CVE-2016-10086

RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify tas…

Patch available
Fix from $1,950 2017-01-18
Android HIGH 7.0
CVE-2014-9909

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.0
Fix from $1,950 2017-01-18
Android HIGH 7.0
CVE-2014-9910

An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the …

Fix: after 7.1.0
Fix from $1,950 2017-01-18
Samsung Mobile HIGH 7.8
CVE-2016-6526

The SpamCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (cr…

Mitigation only
Fix from $1,950 2017-01-18
Samsung Mobile HIGH 7.8
CVE-2016-6527

The SmartCall Activity component in Telecom application on Samsung Note device L(5.0/5.1) and M(6.0) allows attackers to cause a denial of service (c…

Mitigation only
Fix from $1,950 2017-01-18
Liferay Portal HIGH 8.8
CVE-2010-5327

Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.

Fix: after 6.2.10
Fix from $1,950 2017-01-13
Android MEDIUM 5.5
CVE-2016-8467

An elevation of privilege vulnerability in the bootloader could enable a local attacker to execute arbitrary modem commands on the device. This issue…

Fix: after 7.1.0
Fix from $1,600 2017-01-13
Storm CRITICAL 9.8
CVE-2015-3188EPSS 14%

The UI daemon in Apache Storm 0.10.0 before 0.10.0-beta1 allows remote attackers to execute arbitrary code via unspecified vectors.

No fix yet
Fix from $2,300 2017-01-13
Android HIGH 7.8
CVE-2016-6492

The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted application th…

Fix: after 7.1.0
Fix from $1,950 2017-01-12
Xclarity Administrator HIGH 7.0
CVE-2016-8221

Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/outp…

Fix: after 1.1.1
Fix from $1,950 2017-01-12
Android HIGH 7.0
CVE-2016-8445

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious applica…

Fix: after 7.1.0
Fix from $1,950 2017-01-12
Android HIGH 7.0
CVE-2016-8446

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious applica…

Fix: after 7.1.0
Fix from $1,950 2017-01-12
Android HIGH 7.0
CVE-2016-8447

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious applica…

Fix: after 7.1.0
Fix from $1,950 2017-01-12
Android HIGH 7.0
CVE-2016-8448

An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious applica…

Fix: after 7.1.0
Fix from $1,950 2017-01-12