Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Linux Kernel HIGH 7.2
CVE-2014-7822

The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a si…

Fix: after 3.15.8
Fix from $1,950 2015-03-16
Bacnet Opc Server HIGH 7.5
CVE-2015-0981

The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbi…

Fix: after 2.1.359.22
Fix from $1,950 2015-03-14
Fedora HIGH 7.2
CVE-2015-2151

The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local gu…

Patch available
Fix from $1,950 2015-03-12
Windows 8 HIGH 7.2
CVE-2015-0078

win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prop…

Patch available
Fix from $1,950 2015-03-11
Windows 2003 Server HIGH 7.2
CVE-2015-0075

The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain…

Mitigation only
Fix from $1,950 2015-03-11
Windows 7 HIGH 7.2
CVE-2015-0073

The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows …

Patch available
Fix from $1,950 2015-03-11
Chrome MEDIUM 5.0
CVE-2015-1226

The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properl…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Chrome MEDIUM 5.0
CVE-2014-9689

content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate …

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Chrome MEDIUM 5.0
CVE-2011-5319

content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accel…

Fix: after 40.0.2214.115
Fix from $1,600 2015-03-09
Gpu Driver R304 HIGH 7.2
CVE-2015-1170

The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client …

Fix: after 347.51
Fix from $1,950 2015-03-06
Secure Access Control System MEDIUM 6.5
CVE-2014-2130

Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authentic…

Mitigation only
Fix from $1,600 2015-03-06
Businessobjects Edge MEDIUM 5.0
CVE-2015-2075

SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011…

No fix yet
Fix from $1,600 2015-02-27
Firefox MEDIUM 6.8
CVE-2015-0821

Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges…

Fix: after 35.0.1
Fix from $1,600 2015-02-25
Kie Workbench MEDIUM 6.5
CVE-2014-8115

The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac…

Patch available
Fix from $1,600 2015-02-20
Uberfire MEDIUM 6.8
CVE-2014-8114

The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte…

Patch available
Fix from $1,600 2015-02-20
Defensewall Personal Firewall HIGH 7.2
CVE-2015-1515

The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequentl…

No fix yet
Fix from $1,950 2015-02-19
Activematrix Management Agent MEDIUM 6.4
CVE-2014-5286

The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1…

Mitigation only
Fix from $1,600 2015-02-19
Samsung Security Manager HIGH 8.5
CVE-2015-1499

The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial …

Fix: after 1.30
Fix from $1,950 2015-02-16
Radia Client Automation HIGH 10.0
CVE-2015-1498

Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user …

Mitigation only
Fix from $1,950 2015-02-16
Motorola Scanner Sdk HIGH 7.2
CVE-2015-1496

Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local …

Mitigation only
Fix from $1,950 2015-02-16
Documentum D2 HIGH 9.0
CVE-2015-0518

The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows …

Mitigation only
Fix from $1,950 2015-02-14
Tivoli Storage Manager HIGH 7.2
CVE-2014-6185

dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict sh…

Patch available
Fix from $1,950 2015-02-13
Wss4j MEDIUM 5.0
CVE-2015-0227EPSS 8%

Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors …

Fix: after 1.6.16
Fix from $1,600 2015-02-12
Telepresence System Software Ix MEDIUM 6.5
CVE-2015-0611

The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-…

Mitigation only
Fix from $1,600 2015-02-12
Windows 7 HIGH 7.2
CVE-2015-0062

Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local…

Patch available
Fix from $1,950 2015-02-11
Windows 7 MEDIUM 6.9
CVE-2015-0059EPSS 11%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2…

Patch available
Fix from $1,600 2015-02-11
Windows 7 HIGH 7.2
CVE-2015-0057EPSS 13%

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2015-02-11
Virtual Machine Manager MEDIUM 6.9
CVE-2015-0012

Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users…

Patch available
Fix from $1,600 2015-02-11
Ubuntu Linux MEDIUM 5.0
CVE-2014-9675

bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers…

No fix yet
Fix from $1,600 2015-02-08
Data Loss Prevention Endpoint MEDIUM 6.9
CVE-2015-1305

McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privilege…

Fix: after 9.3.300
Fix from $1,600 2015-02-06