Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Windows 10 HIGH 8.8
CVE-2016-0009EPSS 15%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitr…

Mitigation only
Fix from $1,950 2016-01-13
Windows 10 HIGH 7.8
CVE-2016-0007EPSS 5%

The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server …

Patch available
Fix from $1,950 2016-01-13
Windows 10 HIGH 7.3
CVE-2016-0006

The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server …

Patch available
Fix from $1,950 2016-01-13
Vcn500 HIGH 7.1
CVE-2015-8333

The Operation and Maintenance Unit (OMU) in Huawei VCN500 with software before V100R002C00SPC200 allows remote authenticated users to change the IP a…

Mitigation only
Fix from $1,950 2016-01-11
Mac Os X HIGH 7.8
CVE-2015-6980

Directory Utility in Apple OS X before 10.11.1 mishandles authentication for new sessions, which allows local users to gain privileges via unspecifie…

Fix: after 10.11.0
Fix from $1,950 2016-01-11
Mollom HIGH 7.5
CVE-2015-8754

The Mollom module 6.x-2.7 before 6.x-2.15 for Drupal allows remote attackers to bypass intended access restrictions and modify the mollom blacklist v…

Patch available
Fix from $1,950 2016-01-08
Afaria CRITICAL 9.1
CVE-2015-8753

SAP Afaria 7.0.6001.5 allows remote attackers to bypass authorization checks and wipe or lock mobile devices via a crafted request, related to "Insec…

Mitigation only
Fix from $2,300 2016-01-08
Blueman HIGH 8.4
CVE-2015-8612EPSS 6%

The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users to gain privileges via the d…

Fix: after 2.0
Fix from $1,950 2016-01-08
Forticlient HIGH 7.8
CVE-2015-7362

Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory that is world readable and executable, allows local …

Mitigation only
Fix from $1,950 2016-01-08
Pre Boot Authentication Driver HIGH 7.8
CVE-2015-6856

Dell Pre-Boot Authentication Driver (PBADRV.sys) 1.0.1.5 allows local users to write to arbitrary physical memory locations and gain privileges via a…

No fix yet
Fix from $1,950 2016-01-08
Android HIGH 7.8
CVE-2015-6647

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafte…

No fix yet
Fix from $1,950 2016-01-06
Android MEDIUM 5.0
CVE-2015-6645

SyncManager in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to cause a denial of service (continuous rebooting) via a craft…

Mitigation only
Fix from $1,600 2016-01-06
Android MEDIUM 6.6
CVE-2015-6643

Setup Wizard in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows physically proximate attackers to modify settings or bypass a reset …

Mitigation only
Fix from $1,600 2016-01-06
Android CRITICAL 9.8
CVE-2015-6642

The kernel in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to obtain sensitive information, and consequently bypass an unsp…

Mitigation only
Fix from $2,300 2016-01-06
Android HIGH 7.8
CVE-2015-6640

The prctl_set_vma_anon_name function in kernel/sys.c in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 does not ensure that only one vma is ac…

Mitigation only
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6639EPSS 7%

The Widevine QSEE TrustZone application in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafte…

No fix yet
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6638

The Imagination Technologies driver in Android 5.x before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted ap…

Mitigation only
Fix from $1,950 2016-01-06
Android HIGH 7.8
CVE-2015-6637

The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, a…

Mitigation only
Fix from $1,950 2016-01-06
Eucalyptus HIGH 7.5
CVE-2015-6861

HPE Helion Eucalyptus 3.4.0 through 4.2.0 allows remote authenticated users to bypass an intended AssumeRole permission requirement and assume an IAM…

Mitigation only
Fix from $1,950 2016-01-05
Network Switch Software HIGH 8.4
CVE-2015-6860

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different …

Fix: after 15.18.0
Fix from $1,950 2016-01-05
Network Switch Software HIGH 7.8
CVE-2015-6859

HPE Network Switches with software 15.16.x and 15.17.x allow local users to bypass intended access restrictions via unspecified vectors, a different …

Fix: after 15.18.0
Fix from $1,950 2016-01-05
Jg786a Hp Flexfabric 12500 4 Port 100gbe Cfp Fd MEDIUM 6.5
CVE-2015-5434

HPE Networking Products, originally branded as Comware 5, Comware 7, H3C, or HP, allow remote attackers to bypass intended access restrictions or cau…

Patch available
Fix from $1,600 2016-01-05
Eucalyptus MEDIUM 6.8
CVE-2014-5040

HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restr…

Mitigation only
Fix from $1,600 2016-01-05
Hadoop HIGH 8.4
CVE-2015-7430

The Hadoop connector 1.1.1, 2.4, 2.5, and 2.7.0-0 before 2.7.0-3 for IBM Spectrum Scale and General Parallel File System (GPFS) allows local users to…

Mitigation only
Fix from $1,950 2016-01-02
Maximo Asset Management MEDIUM 5.4
CVE-2015-7396

The Scheduler in IBM Maximo Asset Management 7.5 before 7.5.0.8 IF6 and 7.6 before 7.6.0.1 FP1 and Maximo Asset Management 7.5 before 7.5.0.8 IF6, 7.…

Mitigation only
Fix from $1,600 2016-01-02
Installation Manager HIGH 7.0
CVE-2015-7442

consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows l…

Fix: after 1.7.4.3
Fix from $1,950 2016-01-02
Spss Statistics HIGH 7.8
CVE-2015-7489

IBM SPSS Statistics 22.0.0.2 before IF10 and 23.0.0.2 before IF7 uses weak permissions (Everyone: Write) for Python scripts, which allows local users…

Mitigation only
Fix from $1,950 2016-01-01
Gs1900 10hp Firmware CRITICAL 9.8
CVE-2015-5989

Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain adminis…

Fix: 2.50+
Fix from $2,300 2015-12-31
Pmg5318 B20a Firmware HIGH 8.0
CVE-2015-6020

ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the…

Mitigation only
Fix from $1,950 2015-12-31
Pmg5318 B20a Firmware CRITICAL 9.8
CVE-2015-6018EPSS 21%

The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary com…

No fix yet
Fix from $2,300 2015-12-31