Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Office MEDIUM 5.4
CVE-2016-1152

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions, and read or write to plan data, via unsp…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8486

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary report titles via unsp…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8485

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended access restrictions and read arbitrary posting titles via uns…

Mitigation only
Fix from $1,600 2016-02-17
Office MEDIUM 5.4
CVE-2015-8484

Cybozu Office 9.9.0 through 10.3.0 allows remote authenticated users to bypass intended calendar-viewing restrictions via unspecified vectors, a diff…

Mitigation only
Fix from $1,600 2016-02-17
Debian Linux HIGH 8.8
CVE-2016-1627

The Developer Tools (aka DevTools) subsystem in Google Chrome before 48.0.2564.109 does not validate URL schemes and ensure that the remoteBase param…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Debian Linux HIGH 8.8
CVE-2016-1623

The DOM implementation in Google Chrome before 48.0.2564.109 does not properly restrict frame-attach operations from occurring during or after frame-…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Chrome HIGH 8.8
CVE-2016-1622

The Extensions subsystem in Google Chrome before 48.0.2564.109 does not prevent use of the Object.defineProperty method to override intended extensio…

Fix: after 48.0.2564.103
Fix from $1,950 2016-02-14
Firefox HIGH 8.8
CVE-2016-1949

Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass…

Fix: after 44.0.1
Fix from $1,950 2016-02-13
Spark MEDIUM 5.3
CVE-2016-1324

The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page,…

Mitigation only
Fix from $1,600 2016-02-12
Spark HIGH 7.5
CVE-2016-1322

The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via un…

Mitigation only
Fix from $1,950 2016-02-12
Prime Collaboration MEDIUM 6.7
CVE-2016-1320

The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges,…

Mitigation only
Fix from $1,600 2016-02-12
Windows 10 HIGH 7.8
CVE-2016-0051EPSS 23%

The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Wi…

No fix yet
Fix from $1,950 2016-02-10
Windows 10 HIGH 7.8
CVE-2016-0048

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Mitigation only
Fix from $1,950 2016-02-10
Windows 10 HIGH 8.1
CVE-2016-0036EPSS 11%

The Remote Desktop Protocol (RDP) implementation in Microsoft Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows remo…

Patch available
Fix from $1,950 2016-02-10
Linux Kernel HIGH 7.0
CVE-2015-8709

kernel/ptrace.c in the Linux kernel through 4.4.1 mishandles uid and gid mappings, which allows local users to gain privileges by establishing a user…

Fix: after 4.4.1
Fix from $1,950 2016-02-08
Android MEDIUM 6.1
CVE-2016-0813

packages/SystemUI/src/com/android/systemui/recents/AlternateRecentsComponent.java in Setup Wizard in Android 5.1.x before 5.1.1 LMY49G and 6.x before…

Mitigation only
Fix from $1,600 2016-02-07
Android MEDIUM 6.1
CVE-2016-0812

The interceptKeyBeforeDispatching function in policy/src/com/android/internal/policy/impl/PhoneWindowManager.java in Setup Wizard in Android 5.1.x be…

Mitigation only
Fix from $1,600 2016-02-07
Android HIGH 7.8
CVE-2016-0810

media/libmedia/SoundPool.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 mishandles locking requir…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.8
CVE-2016-0809

Use-after-free vulnerability in the wifi_cleanup function in bcmdhd/wifi_hal/wifi_hal.cpp in Wi-Fi in Android 6.x before 2016-02-01 allows attackers …

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0807

The get_build_id function in elf_utils.cpp in Debuggerd in Android 6.x before 2016-02-01 allows attackers to gain privileges via a crafted applicatio…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0806

The Qualcomm Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows attackers to gain priv…

Mitigation only
Fix from $1,950 2016-02-07
Android HIGH 8.4
CVE-2016-0805

The performance event manager for Qualcomm ARM processors in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows atta…

Mitigation only
Fix from $1,950 2016-02-07
Kubernetes CRITICAL 9.8
CVE-2016-1906

Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not al…

Patch available
Fix from $2,300 2016-02-03
Radicale MEDIUM 5.3
CVE-2015-8748

Radicale before 1.1 allows remote authenticated users to bypass owner_write and owner_only limitations via regex metacharacters in the user name, as …

Fix: after 1.0.1
Fix from $1,600 2016-02-03
Printer Firmware CRITICAL 9.8
CVE-2016-1896

Race condition in the initialization process on Lexmark printers with firmware ATL before ATL.02.049, CB before CB.02.049, PP before PP.02.049, and Y…

Mitigation only
Fix from $2,300 2016-01-27
Fuse HIGH 7.8
CVE-2016-1233

An unspecified udev rule in the Debian fuse package in jessie before 2.9.3-15+deb8u2, in stretch before 2.9.5-1, and in sid before 2.9.5-1 sets world…

Fix: after 2.9.3-14
Fix from $1,950 2016-01-26
Fortios CRITICAL 9.8
CVE-2016-1909EPSS 71%

Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before …

Fix: after 4.3.16
Fix from $2,300 2016-01-15
Webaccess HIGH 7.5
CVE-2016-0852

Advantech WebAccess before 8.1 allows remote attackers to bypass an intended administrative requirement and obtain file or folder access via unspecif…

Fix: after 8.0
Fix from $1,950 2016-01-15
Web Viewer HIGH 8.6
CVE-2015-8279EPSS 51%

Web Viewer 1.0.0.193 on Samsung SRN-1670D devices allows remote attackers to read arbitrary files via a request to an unspecified PHP script.

Fix: after 1.0.0.193
Fix from $1,950 2016-01-15
Acrobat Dc HIGH 8.8
CVE-2016-0943EPSS 7%

Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous befo…

Fix: after 15.009.20077
Fix from $1,950 2016-01-14