Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
.net Framework HIGH 9.3
CVE-2015-2481EPSS 14%

The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execu…

Mitigation only
Fix from $1,950 2015-08-15
.net Framework HIGH 9.3
CVE-2015-2479EPSS 17%

The RyuJIT compiler in Microsoft .NET Framework 4.6 produces incorrect code during an attempt at optimization, which allows remote attackers to execu…

Mitigation only
Fix from $1,950 2015-08-15
Windows 7 HIGH 9.3
CVE-2015-2430EPSS 7%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-08-15
Windows 7 HIGH 9.3
CVE-2015-2429EPSS 7%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2015-08-15
Windows 10 MEDIUM 6.6
CVE-2015-1769 KEV

Mount Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and…

Patch available
Fix from $1,600 2015-08-15
Foreman MEDIUM 6.0
CVE-2015-3235

Foreman before 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unsp…

Fix: after 1.8.2
Fix from $1,600 2015-08-14
Activemq HIGH 7.5
CVE-2014-3576EPSS 13%

The processControlCommand function in broker/TransportConnection.java in Apache ActiveMQ before 5.11.0 allows remote attackers to cause a denial of s…

Fix: after 5.10.0
Fix from $1,950 2015-08-14
N300 Dual Band Wi Fi Range Extender Firmware HIGH 9.0
CVE-2015-5536

Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) s…

Patch available
Fix from $1,950 2015-08-13
Fedora HIGH 7.2
CVE-2015-5166

Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users t…

Fix: after 4.5.0
Fix from $1,950 2015-08-12
Openafs MEDIUM 6.8
CVE-2015-3283

OpenAFS before 1.6.13 allows remote attackers to spoof bos commands via unspecified vectors.

Fix: after 1.6.12
Fix from $1,600 2015-08-12
Enterprise Linux High Availability HIGH 7.5
CVE-2015-1867

Pacemaker before 1.1.13 does not properly evaluate added nodes, which allows remote read-only users to gain privileges via an acl command.

Fix: after 1.1.12
Fix from $1,950 2015-08-12
Libuser HIGH 7.2
CVE-2015-3246EPSS 7%

libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in the userhelper program in the usermode package, directly modifies /etc/passwd, which allo…

Fix: after 0.56.13-5
Fix from $1,950 2015-08-11
Openssh HIGH 8.1
CVE-2015-5600EPSS 9%

The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive dev…

Fix: after 6.9
Fix from $1,950 2015-08-03
Bf 630 HIGH 7.5
CVE-2015-5618

Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time…

Mitigation only
Fix from $1,950 2015-08-01
Bf 660c HIGH 7.5
CVE-2015-2871

Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configurati…

Mitigation only
Fix from $1,950 2015-08-01
Endpoint Protection Manager HIGH 8.5
CVE-2015-1489EPSS 25%

The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticated users to gain privileges v…

No fix yet
Fix from $1,950 2015-08-01
Firepower Extensible Operating System MEDIUM 5.0
CVE-2015-4287

Cisco Firepower Extensible Operating System 1.1(1.86) on Firepower 9000 devices allows remote attackers to bypass intended access restrictions and ob…

Mitigation only
Fix from $1,600 2015-07-29
Application Policy Infrastructure Controller \(apic\) HIGH 9.0
CVE-2015-4235

Cisco Application Policy Infrastructure Controller (APIC) devices with software before 1.0(3o) and 1.1 before 1.1(1j) and Nexus 9000 ACI devices with…

Mitigation only
Fix from $1,950 2015-07-24
Gpu Driver HIGH 7.2
CVE-2015-3625

The NVIDIA GPU driver for FreeBSD R352 before 352.09, 346 before 346.72, R349 before 349.16, R343 before 343.36, R340 before 340.76, R337 before 337.…

Fix: 304.125 / 331.113+
Fix from $1,950 2015-07-18
Xen MEDIUM 6.8
CVE-2015-3259

Stack-based buffer overflow in the xl command line utility in Xen 4.1.x through 4.5.x allows local guest administrators to gain privileges via a long…

Patch available
Fix from $1,600 2015-07-16
Windows 2003 Server MEDIUM 6.9
CVE-2015-2371

The Windows Installer service in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, …

Mitigation only
Fix from $1,600 2015-07-14
Windows 2003 Server HIGH 7.2
CVE-2015-2370

The authentication implementation in the RPC subsystem in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 an…

No fix yet
Fix from $1,950 2015-07-14
Windows 7 HIGH 7.2
CVE-2015-2366

win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

No fix yet
Fix from $1,950 2015-07-14
Windows 2003 Server HIGH 7.2
CVE-2015-2365

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows…

No fix yet
Fix from $1,950 2015-07-14
Windows 2003 Server HIGH 7.2
CVE-2015-2363

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows…

Mitigation only
Fix from $1,950 2015-07-14
Windows 2003 Server HIGH 7.2
CVE-2015-2364

The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows…

Mitigation only
Fix from $1,950 2015-07-14
Jboss Fuse MEDIUM 6.0
CVE-2014-8175

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an acco…

Fix: after 6.1.0
Fix from $1,600 2015-07-08
Hp Ux HIGH 7.2
CVE-2015-2126

Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.

Mitigation only
Fix from $1,950 2015-07-06
Nx Os HIGH 7.2
CVE-2015-4234

Cisco NX-OS 6.0(2) and 6.2(2) on Nexus devices has an improper OS configuration, which allows local users to obtain root access via unspecified input…

Mitigation only
Fix from $1,950 2015-07-03
Safari MEDIUM 6.8
CVE-2015-3727

WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple iOS before 8.4 and other products, does not properly re…

Fix: after 10.10.3
Fix from $1,600 2015-07-03