Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Telepresence Advanced Media Gateway HIGH 9.0
CVE-2015-0713

The web framework in Cisco TelePresence Advanced Media Gateway Series Software before 1.1(1.40), Cisco TelePresence IP Gateway Series Software, Cisco…

Mitigation only
Fix from $1,950 2015-05-25
Hosted Collaboration Solution MEDIUM 6.5
CVE-2015-0750

The administrative web interface in Cisco Hosted Collaboration Solution (HCS) 10.6(1) and earlier allows remote authenticated users to execute arbitr…

Mitigation only
Fix from $1,600 2015-05-23
Debian Linux MEDIUM 5.0
CVE-2015-1254

core/dom/Document.cpp in Blink, as used in Google Chrome before 43.0.2357.65, enables the inheritance of the designMode attribute, which allows remot…

Fix: after 42.0.2311.152
Fix from $1,600 2015-05-20
Docker HIGH 7.2
CVE-2015-3630

Docker Engine before 1.6.1 uses weak permissions for (1) /proc/asound, (2) /proc/timer_stats, (3) /proc/latency_stats, and (4) /proc/fs, which allows…

Fix: after 1.6
Fix from $1,950 2015-05-18
Unified Communications Manager MEDIUM 6.9
CVE-2015-0717

Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug…

Mitigation only
Fix from $1,600 2015-05-16
Air MEDIUM 6.4
CVE-2015-3085

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Flash Player MEDIUM 6.4
CVE-2015-3083EPSS 41%

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Air MEDIUM 6.4
CVE-2015-3082EPSS 43%

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Flash Player MEDIUM 5.0
CVE-2015-3079EPSS 5%

Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and before 11.2.202.460 on Linux, Adobe AIR before 1…

Fix: after 17.0.0.144
Fix from $1,600 2015-05-13
Windows 7 MEDIUM 6.9
CVE-2015-1702

The Service Control Manager (SCM) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows…

Patch available
Fix from $1,600 2015-05-13
.net Framework HIGH 9.3
CVE-2015-1673EPSS 17%

The Windows Forms (aka WinForms) libraries in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 allow user-assisted rem…

Mitigation only
Fix from $1,950 2015-05-13
System Update HIGH 7.2
CVE-2015-2219

Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privil…

Fix: after 5.06.0027
Fix from $1,950 2015-05-12
Samsung Security Manager HIGH 10.0
CVE-2015-3435EPSS 10%

Samsung Security Manager (SSM) before 1.31 allows remote attackers to execute arbitrary code by uploading a file with an HTTP (1) PUT or (2) MOVE req…

Fix: after 1.30
Fix from $1,950 2015-05-01
Enterprise Virtualization Manager MEDIUM 6.8
CVE-2015-0237

Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between …

Fix: after 3.5.0
Fix from $1,600 2015-05-01
Rsa Identity Management And Governance HIGH 7.5
CVE-2015-0532

EMC RSA Identity Management and Governance (IMG) 6.9 before P04 and 6.9.1 before P01 does not properly restrict password resets, which allows remote …

No fix yet
Fix from $1,950 2015-05-01
Lifecare Pcainfusion Firmware HIGH 10.0
CVE-2015-3459EPSS 5%

The communication module on the Hospira LifeCare PCA Infusion System before 7.0 does not require authentication for root TELNET sessions, which allow…

Fix: after 5.0
Fix from $1,950 2015-04-29
Websphere Application Server HIGH 9.3
CVE-2015-1885

WebSphereOauth20SP.ear in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, 8.5 Liberty Profile before 8.5.5.5, and 8.…

Patch available
Fix from $1,950 2015-04-27
Websphere Application Server MEDIUM 5.5
CVE-2015-0175

IBM WebSphere Application Server (WAS) 8.5 Liberty Profile before 8.5.5.5 does not properly implement authData elements, which allows remote authenti…

Patch available
Fix from $1,600 2015-04-27
Curl MEDIUM 5.0
CVE-2015-3143EPSS 13%

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unau…

Fix: after 10.9.5
Fix from $1,600 2015-04-24
Chrome HIGH 7.5
CVE-2015-3335

The NaClSandbox::InitializeLayerTwoSandbox function in components/nacl/loader/sandbox_linux/nacl_sandbox_linux.cc in Google Chrome before 42.0.2311.9…

Fix: after 42.0.2311.60
Fix from $1,950 2015-04-19
Ubuntu Linux MEDIUM 5.0
CVE-2015-1235

The ContainerNode::parserRemoveChild function in core/dom/ContainerNode.cpp in the HTML parser in Blink, as used in Google Chrome before 42.0.2311.90…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Ubuntu Linux MEDIUM 5.5
CVE-2015-1856

OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an…

Fix: after 2.2.2
Fix from $1,600 2015-04-17
Apport HIGH 7.2
CVE-2015-1318

The crash reporting feature in Apport 2.13 through 2.17.x before 2.17.1 allows local users to gain privileges via a crafted usr/share/apport/apport f…

Patch available
Fix from $1,950 2015-04-17
Secure Desktop HIGH 9.3
CVE-2015-0691

A certain Cisco JAR file, as distributed in Cache Cleaner in Cisco Secure Desktop (CSD), allows remote attackers to execute arbitrary commands via a …

Mitigation only
Fix from $1,950 2015-04-17
Windows 7 HIGH 7.2
CVE-2015-1644

Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 …

Patch available
Fix from $1,950 2015-04-14
Windows 7 HIGH 7.2
CVE-2015-1643

Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 G…

Patch available
Fix from $1,950 2015-04-14
Glpi MEDIUM 5.0
CVE-2014-5032

GLPI before 0.84.7 does not properly restrict access to cost information, which allows remote attackers to obtain sensitive information via the cost …

Fix: after 0.84.6
Fix from $1,600 2015-04-14
Web Security Appliance HIGH 7.2
CVE-2015-0692

Cisco Web Security Appliance (WSA) devices with software 8.5.0-ise-147 do not properly restrict use of the pickle Python module during certain tunnel…

Mitigation only
Fix from $1,950 2015-04-11
Xcode MEDIUM 5.0
CVE-2015-3027

Clang in LLVM, as used in Apple Xcode before 6.3, performs incorrect register allocation in a way that triggers stack storage for stack cookie pointe…

Fix: after 6.2
Fix from $1,600 2015-04-10
Junos HIGH 7.2
CVE-2015-3003

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X47-D20, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D10, 13.…

Mitigation only
Fix from $1,950 2015-04-10