Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X HIGH 9.3
CVE-2015-3704EPSS 9%

runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows at…

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3673EPSS 6%

Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Safari MEDIUM 6.8
CVE-2015-3659

The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple i…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Showbiz Pro HIGH 7.5
CVE-2014-9735EPSS 76%

The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not prope…

Fix: after 3.0.95
Fix from $1,950 2015-06-30
Infosphere Datastage HIGH 7.2
CVE-2015-1900

IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obta…

Patch available
Fix from $1,950 2015-06-29
Tivoli Directory Server MEDIUM 6.5
CVE-2015-1974

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6…

Patch available
Fix from $1,600 2015-06-28
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-4211

Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a cr…

Mitigation only
Fix from $1,950 2015-06-24
Unified Infrastructure Manager\/provisioning HIGH 10.0
CVE-2015-0546

EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid account name.

Mitigation only
Fix from $1,950 2015-06-17
Services MEDIUM 5.0
CVE-2015-4394

The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private fi…

Patch available
Fix from $1,600 2015-06-15
Services Basic Authentication MEDIUM 5.0
CVE-2015-4344

The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vect…

Fix: after 7.x-1.3
Fix from $1,600 2015-06-15
Milkystep Light MEDIUM 6.4
CVE-2015-2958

Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify s…

Fix: after 1.82
Fix from $1,600 2015-06-13
Milkystep Light MEDIUM 5.0
CVE-2015-2953

Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read fil…

Fix: after 1.82
Fix from $1,600 2015-06-13
iOS MEDIUM 6.9
CVE-2015-4185

The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session ver…

Mitigation only
Fix from $1,600 2015-06-13
Identity Services Engine Software MEDIUM 5.5
CVE-2015-4182

The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restr…

Mitigation only
Fix from $1,600 2015-06-12
Prime Network Control System MEDIUM 6.5
CVE-2015-0768

The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implem…

Mitigation only
Fix from $1,600 2015-06-12
Firesight System Software MEDIUM 5.5
CVE-2015-0773

Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deleti…

Mitigation only
Fix from $1,600 2015-06-12
Xcloner MEDIUM 5.0
CVE-2014-8605EPSS 7%

The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient…

No fix yet
Fix from $1,600 2015-06-10
Geekbuddy HIGH 7.2
CVE-2014-7872

Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server.

Fix: after 4.18.120
Fix from $1,950 2015-06-09
Sysaid HIGH 7.5
CVE-2015-2993EPSS 55%

SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator ac…

Fix: after 15.1
Fix from $1,950 2015-06-08
Adaptive Server Enterprise HIGH 7.5
CVE-2014-6284

SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and response mechani…

Fix: after 15.7
Fix from $1,950 2015-06-08
Edge 340 Firmware HIGH 7.2
CVE-2015-0767

Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified commands, aka Bug ID CSCur18132.

Mitigation only
Fix from $1,950 2015-06-07
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-0761

Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions…

Fix: after 3.1
Fix from $1,950 2015-06-04
Xen HIGH 7.8
CVE-2015-4104

Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (…

Mitigation only
Fix from $1,950 2015-06-03
Wpmembership MEDIUM 6.5
CVE-2015-4038EPSS 8%

The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_sett…

No fix yet
Fix from $1,600 2015-06-03
Afaria HIGH 7.5
CVE-2015-4161

SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privil…

No fix yet
Fix from $1,950 2015-06-02
Cloud Station MEDIUM 6.8
CVE-2015-2851

client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary f…

Mitigation only
Fix from $1,600 2015-05-30
Netcharts Server HIGH 10.0
CVE-2015-4032

projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently exec…

Mitigation only
Fix from $1,950 2015-05-29
Kerberos 5 MEDIUM 5.8
CVE-2015-2694

The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validat…

Patch available
Fix from $1,600 2015-05-25
Security Siteprotector System HIGH 9.0
CVE-2015-0160

IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbit…

Mitigation only
Fix from $1,950 2015-05-25
Optim Workload Replay MEDIUM 5.0
CVE-2015-1895

IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass i…

Patch available
Fix from $1,600 2015-05-25