Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Twig MEDIUM 6.8
CVE-2015-7809

The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary …

Fix: after 1.19.0
Fix from $1,600 2015-11-06
Big Iq Device HIGH 9.0
CVE-2015-7394

The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP A…

Mitigation only
Fix from $1,950 2015-11-06
Mobility Services Engine MEDIUM 6.9
CVE-2015-4282

Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root pr…

Mitigation only
Fix from $1,600 2015-11-06
Firefox MEDIUM 5.0
CVE-2015-7197

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allow…

Fix: after 41.0.2
Fix from $1,600 2015-11-05
Arcsight Connector Appliance HIGH 7.2
CVE-2015-6030

HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute …

Fix: after 7.1.3
Fix from $1,950 2015-11-04
Infosphere Information Server MEDIUM 5.5
CVE-2015-5021

IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain s…

Patch available
Fix from $1,600 2015-11-04
Tivoli Storage Manager HIGH 7.2
CVE-2015-4927

The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses…

Mitigation only
Fix from $1,950 2015-11-04
Android MEDIUM 5.8
CVE-2015-6614

Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, pe…

Mitigation only
Fix from $1,600 2015-11-03
Android HIGH 9.3
CVE-2015-6612

libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 235…

Fix: 5.1.1+
Fix from $1,950 2015-11-03
Ambari MEDIUM 6.5
CVE-2015-3270

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl…

Mitigation only
Fix from $1,600 2015-11-02
Xen HIGH 7.2
CVE-2015-7835

The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV gues…

Mitigation only
Fix from $1,950 2015-10-30
Enisys Gw MEDIUM 5.0
CVE-2015-5671

Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbitrary uploaded files via unsp…

Fix: after 1.4.0
Fix from $1,600 2015-10-29
Websphere Portal MEDIUM 6.8
CVE-2015-4997

IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request.

Patch available
Fix from $1,600 2015-10-29
Network Utility MEDIUM 6.9
CVE-2015-6034

EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a Trojan ho…

Patch available
Fix from $1,600 2015-10-28
Image Registry And Delivery Service \(glance\) MEDIUM 6.8
CVE-2015-5286

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q…

Fix: after 2014.2.3
Fix from $1,600 2015-10-26
Image Registry And Delivery Service \(glance\) MEDIUM 5.5
CVE-2015-5251

OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of …

Fix: after 2014.2.3
Fix from $1,600 2015-10-26
Wireless Lan Controller Software MEDIUM 5.0
CVE-2015-6341

The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a deni…

Mitigation only
Fix from $1,600 2015-10-25
Firesight System Software HIGH 9.0
CVE-2015-6335

The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to b…

Mitigation only
Fix from $1,950 2015-10-25
Mac Os X HIGH 7.6
CVE-2015-7016

The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, whi…

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Mac Os X MEDIUM 6.8
CVE-2015-7003

coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code …

Fix: after 10.11.0
Fix from $1,600 2015-10-23
Mac Os X HIGH 7.2
CVE-2015-5945

The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Mac Os X Server MEDIUM 5.0
CVE-2015-7031

The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass …

Fix: after 5.0.14
Fix from $1,600 2015-10-23
Radia Client Automation MEDIUM 5.0
CVE-2015-7862

Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based …

Mitigation only
Fix from $1,600 2015-10-19
Radia Client Automation HIGH 10.0
CVE-2015-7861EPSS 5%

Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code…

Mitigation only
Fix from $1,950 2015-10-19
Junos MEDIUM 6.9
CVE-2015-7751

Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 bef…

Fix: after 12.1x44
Fix from $1,600 2015-10-19
Jenkins HIGH 7.5
CVE-2015-1814

The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token chang…

Fix: after 3.1
Fix from $1,950 2015-10-16
Jenkins MEDIUM 6.5
CVE-2015-1806

The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permissi…

Fix: after 3.1
Fix from $1,600 2015-10-16
Vios MEDIUM 6.9
CVE-2015-4948

netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vect…

Mitigation only
Fix from $1,600 2015-10-16
Log And Event Manager HIGH 7.5
CVE-2015-7840

The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code vi…

Fix: after 6.1
Fix from $1,950 2015-10-15
Chrome HIGH 7.5
CVE-2015-6755

The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a …

Fix: after 45.0.2454.101
Fix from $1,950 2015-10-15