Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome MEDIUM 6.4
CVE-2015-1291

The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 45.0.2454.85, does not check wh…

Fix: after 44.0.2403
Fix from $1,600 2015-09-03
Forticlient HIGH 7.2
CVE-2015-5737

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishield.sys drivers in Fortinet FortiClient before 5.…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Forticlient HIGH 7.2
CVE-2015-5736

The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitrary code with kernel privileges by setting the ca…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Forticlient HIGH 7.2
CVE-2015-5735

The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users…

Fix: after 5.2.3
Fix from $1,950 2015-09-03
Ippusbxd HIGH 7.5
CVE-2015-6520

IPPUSBXD before 1.22 listens on all interfaces, which allows remote attackers to obtain access to USB connected printers via a direct request.

Fix: after 1.21.2
Fix from $1,950 2015-09-01
Enterprise Linux Desktop HIGH 7.2
CVE-2015-5157

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during user…

Fix: 3.12.47 / 3.14.54+
Fix from $1,950 2015-08-31
Linux Kernel HIGH 7.2
CVE-2015-3290

arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform improperly relies on espfix64 during nested NMI processing, which a…

Fix: 3.12.47 / 3.14.54+
Fix from $1,950 2015-08-31
Hspa\+ Gobi 4g MEDIUM 6.9
CVE-2015-5367

The HP lt4112 LTE/HSPA+ Gobi 4G module with firmware before 12.500.00.15.1803 on EliteBook, ElitePad, Elite, ProBook, Spectre, ZBook, and mt41 Thin C…

Mitigation only
Fix from $1,600 2015-08-27
Systems Insight Manager HIGH 7.2
CVE-2015-5402

HP Systems Insight Manager (SIM) before 7.5.0, as used in HP Matrix Operating Environment before 7.5.0 and other products, allows local users to gain…

Fix: after 7.4
Fix from $1,950 2015-08-27
Openshift HIGH 8.5
CVE-2015-5222

Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute a…

Mitigation only
Fix from $1,950 2015-08-24
Openssh HIGH 7.2
CVE-2015-6565

sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial of service (terminal disrupti…

No fix yet
Fix from $1,950 2015-08-24
Openssh HIGH 7.0
CVE-2015-6564

Use-after-free vulnerability in the mm_answer_pam_free_ctx function in monitor.c in sshd in OpenSSH before 7.0 on non-OpenBSD platforms might allow l…

Fix: after 6.9
Fix from $1,950 2015-08-24
Wn G54\/r2 Firmware MEDIUM 5.0
CVE-2015-2984

I-O DATA DEVICE WN-G54/R2 routers with firmware before 1.03 and NP-BBRS routers allow remote attackers to cause a denial of service (SSDP reflection)…

Fix: after 1.02
Fix from $1,600 2015-08-22
Documentum Content Server HIGH 7.5
CVE-2015-4535

Java Method Server (JMS) in EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02, w…

Mitigation only
Fix from $1,950 2015-08-20
Documentum Content Server HIGH 9.0
CVE-2015-4533

EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check author…

Mitigation only
Fix from $1,950 2015-08-20
Documentum Content Server HIGH 9.0
CVE-2015-4532

EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check author…

Mitigation only
Fix from $1,950 2015-08-20
Documentum Content Server HIGH 9.0
CVE-2015-4531

EMC Documentum Content Server before 6.7SP1 P32, 6.7SP2 before P25, 7.0 before P19, 7.1 before P16, and 7.2 before P02 does not properly check author…

Mitigation only
Fix from $1,950 2015-08-20
Telepresence Video Communication Server Software MEDIUM 6.5
CVE-2015-4303

Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobo…

Mitigation only
Fix from $1,600 2015-08-20
Content Security Management Appliance MEDIUM 5.5
CVE-2015-4322

Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authent…

Mitigation only
Fix from $1,600 2015-08-19
Hybridauth Social Login MEDIUM 5.0
CVE-2015-5511

The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only c…

Patch available
Fix from $1,600 2015-08-18
Administration Views MEDIUM 6.0
CVE-2015-5509

The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to admini…

Patch available
Fix from $1,600 2015-08-18
Shipwire Api MEDIUM 5.0
CVE-2015-5498

The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), …

Patch available
Fix from $1,600 2015-08-18
Pass2pdf MEDIUM 5.0
CVE-2015-5496

The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecifie…

Patch available
Fix from $1,600 2015-08-18
Entityform Block MEDIUM 5.0
CVE-2015-5493

The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remot…

Patch available
Fix from $1,600 2015-08-18
Mac Os X HIGH 9.3
CVE-2015-5784EPSS 9%

runner in Install.framework in the Install Framework Legacy component in Apple OS X before 10.10.5 does not properly drop privileges, which allows at…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Iphone Os MEDIUM 5.8
CVE-2015-5770

MobileInstallation in Apple iOS before 8.4.1 does not ensure the uniqueness of universal provisioning profile bundle IDs, which allows attackers to r…

Fix: after 8.4
Fix from $1,600 2015-08-17
Mac Os X HIGH 7.2
CVE-2015-3772

IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified …

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Mac Os X HIGH 7.2
CVE-2015-3767

udf in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption and application crash) via a m…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
Mac Os X HIGH 7.2
CVE-2015-3761

The kernel in Apple OS X before 10.10.5 does not properly validate pathnames in the environment, which allows local users to gain privileges via unsp…

Fix: after 10.10.4
Fix from $1,950 2015-08-16
.net Framework HIGH 9.3
CVE-2015-2480EPSS 14%

The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execu…

Mitigation only
Fix from $1,950 2015-08-15