Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Windows 10 HIGH 7.2
CVE-2015-6132EPSS 85%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Patch available
Fix from $1,950 2015-12-09
Android HIGH 9.3
CVE-2015-6623

Wi-Fi in Android 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or Signa…

Mitigation only
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6621

SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated …

Mitigation only
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6620

libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrate…

Fix: 5.1.1+
Fix from $1,950 2015-12-08
Android HIGH 9.3
CVE-2015-6619

The kernel in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, aka internal bug 2…

Fix: 5.1.1+
Fix from $1,950 2015-12-08
Big Iq Security HIGH 9.0
CVE-2015-3628EPSS 68%

The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.0 before 11.6.0 HF6, BIG-IP A…

No fix yet
Fix from $1,950 2015-12-07
Ubuntu Linux HIGH 7.2
CVE-2015-1344

The do_write_pids function in lxcfs.c in LXCFS before 0.12 does not properly check permissions, which allows local users to gain privileges by writin…

Fix: after 0.11
Fix from $1,950 2015-12-07
Chrome HIGH 7.5
CVE-2015-6772

The DOM implementation in Blink, as used in Google Chrome before 47.0.2526.73, does not prevent javascript: URL navigation while a document is being …

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6770

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a diffe…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6769

The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attac…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Chrome HIGH 7.5
CVE-2015-6768

The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a diffe…

Fix: after 46.0.2490.86
Fix from $1,950 2015-12-06
Ios Xe HIGH 7.2
CVE-2015-6383

Cisco IOS XE 15.4(3)S on ASR 1000 devices improperly loads software packages, which allows local users to bypass license restrictions and obtain cert…

Mitigation only
Fix from $1,950 2015-12-03
Simatic Cp 443 1 Firmware HIGH 9.7
CVE-2015-8214

A vulnerability has been identified in SIMATIC NET CP 342-5 (incl. SIPLUS variants) (All versions), SIMATIC NET CP 343-1 Advanced (incl. SIPLUS varia…

Fix: after 3.0
Fix from $1,950 2015-11-27
Jenkins MEDIUM 5.0
CVE-2015-5324

Jenkins before 1.638 and LTS before 1.625.2 allow remote attackers to obtain sensitive information via a direct request to queue/api.

Fix: after 3.1
Fix from $1,600 2015-11-25
Openshift MEDIUM 6.5
CVE-2015-5323

Jenkins before 1.638 and LTS before 1.625.2 do not properly restrict access to API tokens which might allow remote administrators to gain privileges …

Fix: after 3.1
Fix from $1,600 2015-11-25
Jenkins MEDIUM 6.8
CVE-2014-3665

Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers t…

Fix: after 1.586
Fix from $1,600 2015-11-25
Fedora HIGH 7.2
CVE-2015-7496

GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.

Fix: after 3.18.0
Fix from $1,950 2015-11-24
Eos HIGH 10.0
CVE-2015-8236

Arista EOS before 4.11.12, 4.12 before 4.12.11, 4.13 before 4.13.14M, 4.14 before 4.14.5FX.5, and 4.15 before 4.15.0FX1.1 allows remote attackers to …

Fix: after 4.11.11
Fix from $1,950 2015-11-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-8023

The server implementation of the EAP-MSCHAPv2 protocol in the eap-mschapv2 plugin in strongSwan 4.2.12 through 5.x before 5.3.4 does not properly val…

Mitigation only
Fix from $1,600 2015-11-18
Sudo HIGH 7.2
CVE-2015-5602

sudoedit in Sudo before 1.8.15 allows local users to gain privileges via a symlink attack on a file whose full path is defined using multiple wildcar…

Fix: after 1.8.14
Fix from $1,950 2015-11-17
Ipsilon MEDIUM 5.5
CVE-2015-5301

providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.2 and 1.1.x before 1.1.1 does not properly check permissio…

Mitigation only
Fix from $1,600 2015-11-17
System Networking Switch Center HIGH 7.2
CVE-2015-7818

The administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows loca…

Fix: after 8.1.1.0
Fix from $1,950 2015-11-12
Flash Player HIGH 7.8
CVE-2015-7662

Adobe Flash Player before 18.0.0.261 and 19.x before 19.0.0.245 on Windows and OS X and before 11.2.202.548 on Linux, Adobe AIR before 19.0.0.241, Ad…

Fix: after 19.0.0.213
Fix from $1,950 2015-11-11
Windows 10 MEDIUM 6.9
CVE-2015-6100

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,600 2015-11-11
Windows 10 MEDIUM 6.9
CVE-2015-6101

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,600 2015-11-11
Access HIGH 9.3
CVE-2015-2503EPSS 17%

Microsoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…

Mitigation only
Fix from $1,950 2015-11-11
Windows 10 HIGH 7.2
CVE-2015-2478

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT G…

Patch available
Fix from $1,950 2015-11-11
Security Guardium HIGH 7.2
CVE-2015-5043

diag in IBM Security Guardium 8.2 before p6015, 9.0 before p6015, 9.1, 9.5, and 10.0 before p6015 allows local users to obtain root access via unspec…

Mitigation only
Fix from $1,950 2015-11-08
Sterling B2b Integrator MEDIUM 5.5
CVE-2015-5019

IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9 allow remote authenticated users to read or upload file…

Mitigation only
Fix from $1,600 2015-11-08
Powerha System Mirror HIGH 8.5
CVE-2015-5005

CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the c…

Mitigation only
Fix from $1,950 2015-11-08