Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Iphone Os MEDIUM 6.9
CVE-2015-1117

The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7…

Fix: after 10.10.2
Fix from $1,600 2015-04-10
Advanced Threat Defense MEDIUM 5.5
CVE-2015-3028

McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configur…

Fix: after 3.4.4.14
Fix from $1,600 2015-04-08
Firefox MEDIUM 5.0
CVE-2015-0798

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which…

Fix: after 37.0
Fix from $1,600 2015-04-08
Spectrum HIGH 9.0
CVE-2015-2828

CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain admi…

No fix yet
Fix from $1,950 2015-04-08
Websphere Datapower Xc10 Appliance Firmware MEDIUM 6.8
CVE-2015-1893

The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obt…

Patch available
Fix from $1,600 2015-04-06
Domino HIGH 7.2
CVE-2015-0179

Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege…

Patch available
Fix from $1,950 2015-04-06
X Cart MEDIUM 6.5
CVE-2015-0951

X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove r…

Fix: after 5.1.10
Fix from $1,600 2015-04-05
Inngate Ig 3.00 E HIGH 10.0
CVE-2015-0932EPSS 6%

The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G …

Patch available
Fix from $1,950 2015-04-05
Unified Communications Domain Manager MEDIUM 6.5
CVE-2015-0682

Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka B…

Mitigation only
Fix from $1,600 2015-04-03
Neos MEDIUM 6.5
CVE-2015-2821

TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other edit…

Patch available
Fix from $1,600 2015-04-01
Clinical Task Tracker MEDIUM 6.4
CVE-2015-2814

SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which…

Mitigation only
Fix from $1,600 2015-04-01
Firefox MEDIUM 5.0
CVE-2015-0816EPSS 67%

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0804

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Ubuntu Linux HIGH 7.5
CVE-2015-0803

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value duri…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Ubuntu Linux MEDIUM 5.0
CVE-2015-0802EPSS 67%

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might a…

Fix: after 36.0.4
Fix from $1,600 2015-04-01
Firefox HIGH 7.5
CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and ex…

Fix: after 36.0.4
Fix from $1,950 2015-04-01
Wpml MEDIUM 6.4
CVE-2015-2791EPSS 13%

The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craf…

Fix: after 3.1.8
Fix from $1,600 2015-03-30
Enterprise Linux Desktop MEDIUM 5.0
CVE-2015-2348EPSS 9%

The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a…

Fix: after 10.10.5
Fix from $1,600 2015-03-30
Isilon Onefs HIGH 7.2
CVE-2015-0528

The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local…

Fix: after 7.0.2.12
Fix from $1,950 2015-03-29
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2015-2758

The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain…

Fix: after 9.3.400
Fix from $1,600 2015-03-27
Command Center HIGH 7.5
CVE-2015-2683EPSS 5%

Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX…

No fix yet
Fix from $1,950 2015-03-26
Firewall Security Manager HIGH 10.0
CVE-2015-2284EPSS 73%

userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary cod…

Fix: after 6.6.5
Fix from $1,950 2015-03-24
General Parallel File System HIGH 7.2
CVE-2015-0197

IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges…

Patch available
Fix from $1,950 2015-03-24
Firefox HIGH 7.5
CVE-2015-0818

Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy an…

Fix: after 36.0.3
Fix from $1,950 2015-03-24
Api Management MEDIUM 5.5
CVE-2015-0149

The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote a…

Patch available
Fix from $1,600 2015-03-18
Rational Quality Manager MEDIUM 5.5
CVE-2014-6129

IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2…

Patch available
Fix from $1,600 2015-03-18
Anyconnect Secure Mobility Client MEDIUM 6.6
CVE-2015-0663

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users…

Fix: after 4.0
Fix from $1,600 2015-03-17
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2015-0662

Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of ro…

Fix: after 4.0
Fix from $1,950 2015-03-17
Linux Kernel MEDIUM 5.0
CVE-2015-1593

The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift…

Fix: after 3.18.9
Fix from $1,600 2015-03-16
Linux Kernel MEDIUM 6.9
CVE-2014-8159

The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict…

Fix: 3.2.69 / 3.4.108+
Fix from $1,600 2015-03-16