Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Revive Adserver MEDIUM 5.0
CVE-2015-7371

Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possib…

Fix: after 3.2.1
Fix from $1,600 2015-10-14
Windows 10 HIGH 7.2
CVE-2015-2554

The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain p…

Patch available
Fix from $1,950 2015-10-14
Windows 10 HIGH 7.2
CVE-2015-2553

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2015-10-14
Windows 10 HIGH 7.2
CVE-2015-2550

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,950 2015-10-14
Aironet Access Point Software HIGH 7.2
CVE-2015-6315

Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694.

Mitigation only
Fix from $1,950 2015-10-13
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2015-6322

The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move…

Mitigation only
Fix from $1,600 2015-10-12
Telepresence Video Communication Server Software MEDIUM 6.9
CVE-2015-4325

The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges …

Mitigation only
Fix from $1,600 2015-10-12
Web Threat Detection HIGH 7.2
CVE-2015-4548

EMC RSA Web Threat Detection before 5.1 SP1 allows local users to obtain root privileges by leveraging access to a service account and writing comman…

Fix: after 5.1
Fix from $1,950 2015-10-12
Manageengine Opmanager HIGH 9.0
CVE-2015-7766EPSS 81%

PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comme…

Fix: after 11.5
Fix from $1,950 2015-10-09
Mac Os X HIGH 7.2
CVE-2015-5889EPSS 5%

rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables.

Fix: after 10.10.5
Fix from $1,950 2015-10-09
Mac Os X HIGH 7.2
CVE-2015-5888

The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged exe…

Fix: after 10.10.5
Fix from $1,950 2015-10-09
Mac Os X MEDIUM 6.8
CVE-2015-5849

The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Android HIGH 9.3
CVE-2015-7717

mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal …

Fix: after 5.1
Fix from $1,950 2015-10-06
Vpn Client HIGH 7.2
CVE-2015-7600

Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrar…

No fix yet
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-6606

The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted…

Fix: after 5.1
Fix from $1,950 2015-10-06
SQLite MEDIUM 6.8
CVE-2015-6607

SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586.

Fix: after 3.8.8.3
Fix from $1,600 2015-10-06
Android HIGH 9.3
CVE-2015-6596

mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a …

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-3879

Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325.

Fix: after 5.1
Fix from $1,950 2015-10-06
Android HIGH 9.3
CVE-2015-3865

The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sign…

Fix: after 5.1
Fix from $1,950 2015-10-06
Android MEDIUM 6.4
CVE-2015-3847

Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270.

Fix: after 5.1
Fix from $1,600 2015-10-06
Matchasns MEDIUM 6.5
CVE-2015-5645

ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.

Fix: after 1.3.6
Fix from $1,600 2015-10-06
Basercms MEDIUM 6.5
CVE-2015-5640

baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.

Fix: after 3.0.7
Fix from $1,600 2015-10-06
Urbancode Deploy MEDIUM 6.0
CVE-2015-4964

IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allow…

Patch available
Fix from $1,600 2015-10-06
Western Digital Arkeia HIGH 10.0
CVE-2015-7709EPSS 79%

The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and exec…

Fix: after 11.0.12
Fix from $1,950 2015-10-05
Openfire MEDIUM 6.5
CVE-2015-7707EPSS 6%

Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp.

No fix yet
Fix from $1,600 2015-10-05
Android HIGH 9.3
CVE-2015-3858

The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an au…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android HIGH 9.3
CVE-2015-3849

The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return value…

Fix: after 5.1
Fix from $1,950 2015-10-01
Android MEDIUM 6.8
CVE-2015-3845

The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identif…

Fix: after 5.1
Fix from $1,600 2015-10-01
Android MEDIUM 6.8
CVE-2015-3844

The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 …

Fix: after 5.1
Fix from $1,600 2015-10-01
Android HIGH 9.3
CVE-2015-3843

The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM command…

Fix: after 5.1
Fix from $1,950 2015-10-01