Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cacti HIGH 8.8
CVE-2016-2313

auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging …

Fix: after 0.8.8f
Fix from $1,950 2016-04-13
.net Framework HIGH 7.8
CVE-2016-0148EPSS 14%

Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET F…

No fix yet
Fix from $1,950 2016-04-12
Windows 10 HIGH 7.8
CVE-2016-0143

The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R…

No fix yet
Fix from $1,950 2016-04-12
Policy Center Firmware HIGH 8.8
CVE-2016-2405

Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cause a denial of service (syste…

Mitigation only
Fix from $1,950 2016-04-12
Ubuntu Linux HIGH 7.8
CVE-2016-3157

The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which all…

Patch available
Fix from $1,950 2016-04-12
Debian Linux HIGH 8.1
CVE-2016-3169

The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code tha…

Patch available
Fix from $1,950 2016-04-12
Gpu Driver R340 HIGH 8.4
CVE-2016-2557

The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows lo…

Mitigation only
Fix from $1,950 2016-04-12
Gpu Driver R340 HIGH 7.8
CVE-2016-2556

The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperl…

Fix: after 431.61
Fix from $1,950 2016-04-12
Ranger MEDIUM 6.5
CVE-2015-5167

The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API.

Fix: after 0.5.0
Fix from $1,600 2016-04-12
Openstack HIGH 7.3
CVE-2015-5329

The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R…

Mitigation only
Fix from $1,950 2016-04-11
Ranger HIGH 8.8
CVE-2016-0735

Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand…

Mitigation only
Fix from $1,950 2016-04-11
Ranger HIGH 7.1
CVE-2015-0266

The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod…

Fix: after 0.4.0.
Fix from $1,950 2016-04-11
PostgreSQL CRITICAL 9.1
CVE-2016-3065

The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to …

Patch available
Fix from $2,300 2016-04-11
Debian Linux HIGH 8.8
CVE-2016-1235

The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via …

Fix: after 2.5.6
Fix from $1,950 2016-04-11
Fingerprint Manager HIGH 7.8
CVE-2016-2393

Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows…

Fix: after 8.01.56
Fix from $1,950 2016-04-11
Jetspeed HIGH 7.5
CVE-2016-2171EPSS 43%

The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to …

Fix: after 2.3.0
Fix from $1,950 2016-04-11
Prepopulate HIGH 7.3
CVE-2016-3188

The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions,…

Patch available
Fix from $1,950 2016-04-08
Prepopulate HIGH 7.3
CVE-2016-3187

The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspe…

Patch available
Fix from $1,950 2016-04-08
Exim HIGH 7.0
CVE-2016-1531EPSS 6%

Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.

Fix: after 4.86
Fix from $1,950 2016-04-07
Jenkins CRITICAL 9.8
CVE-2016-0788EPSS 12%

The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener.

Fix: after 1.649
Fix from $2,300 2016-04-07
Ucs Invicta C3124sa Appliance CRITICAL 9.8
CVE-2016-1313

Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default…

Mitigation only
Fix from $2,300 2016-04-06
Evolved Programmable Network Manager HIGH 8.1
CVE-2016-1290

The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated …

Mitigation only
Fix from $1,950 2016-04-06
Cogent Datahub HIGH 7.8
CVE-2016-2288

Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file.

Fix: after 7.3.9
Fix from $1,950 2016-03-29
Ios Xr MEDIUM 6.5
CVE-2016-1366

The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which …

Mitigation only
Fix from $1,600 2016-03-24
Iphone Os HIGH 7.8
CVE-2016-1751

The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restrict the execute permission, which allows attackers…

Fix: 2.2 / 9.2+
Fix from $1,950 2016-03-24
Iphone Os MEDIUM 6.8
CVE-2016-1734

AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged co…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Panel Builder 800 HIGH 7.2
CVE-2016-2281

Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working …

Mitigation only
Fix from $1,950 2016-03-18
Endpoint Protection Manager HIGH 8.8
CVE-2015-8154EPSS 5%

The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4…

Fix: after 12.1
Fix from $1,950 2016-03-18
Tivoli Netview Access Services HIGH 8.8
CVE-2014-9768

IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" …

Mitigation only
Fix from $1,950 2016-03-18
Arcsight Enterprise Security Manager HIGH 7.8
CVE-2016-1990

HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to…

Fix: after 5.6
Fix from $1,950 2016-03-16