Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
K7sentry.sys HIGH 7.2
CVE-2014-9643

K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory…

Fix: after 14.2.0.252
Fix from $1,950 2015-02-06
Bdagent.sys HIGH 7.2
CVE-2014-9642

bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write data to arbi…

Fix: after 14.1.287
Fix from $1,950 2015-02-06
Tmeext.sys HIGH 7.2
CVE-2014-9641

The tmeext.sys driver before 2.0.0.1015 in Trend Micro Antivirus Plus, Internet Security, and Maximum Security allows local users to write to arbitra…

Fix: after 2.0.0.1014
Fix from $1,950 2015-02-06
Protection HIGH 7.2
CVE-2014-9632

The TDI driver (avgtdix.sys) in AVG Internet Security before 2013.3495 Hot Fix 18 and 2015.x before 2015.5315 and Protection before 2015.5315 allows …

Fix: 2013.3495 / 2015.5314+
Fix from $1,950 2015-02-06
Oncommand Balance HIGH 10.0
CVE-2014-9353

NetApp OnCommand Balance before 4.2P2 contains a "default privileged account," which allows remote attackers to gain privileges via unspecified vecto…

Fix: after 4.2
Fix from $1,950 2015-02-06
Tower MEDIUM 6.5
CVE-2015-1481EPSS 6%

Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.

Fix: after 2.0.4
Fix from $1,600 2015-02-04
Owncloud MEDIUM 5.0
CVE-2014-9048

The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote attackers to bypass the password-protection for shar…

Fix: after 5.0.17
Fix from $1,600 2015-02-04
Hvg Video Gateway Firmware HIGH 9.0
CVE-2015-1469

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware through 2.2.26a100 allows remote authenticated users to gain privi…

Fix: after 2.2.26a100
Fix from $1,950 2015-02-03
Quidway Firmware HIGH 7.5
CVE-2015-1460

Huawei Quidway switches with firmware before V200R005C00SPC300 allows remote attackers to gain privileges via a crafted packet.

Mitigation only
Fix from $1,950 2015-02-03
Fortiauthenticator MEDIUM 6.9
CVE-2015-1458

Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_she…

No fix yet
Fix from $1,600 2015-02-03
Backup HIGH 7.5
CVE-2014-9633EPSS 8%

The bdisk.sys driver in COMODO Backup before 4.4.1.23 allows remote attackers to gain privileges via a crafted device handle, which triggers a NULL p…

Fix: after 4.4.1
Fix from $1,950 2015-02-03
Qpid MEDIUM 5.0
CVE-2015-0223EPSS 7%

Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related…

Fix: after 0.30
Fix from $1,600 2015-02-02
Ruggedcom Firmware HIGH 10.0
CVE-2015-1448

The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4…

Mitigation only
Fix from $1,950 2015-02-02
Sitescope MEDIUM 5.5
CVE-2014-7882

Unspecified vulnerability in HP SiteScope 11.1x and 11.2x allows remote authenticated users to gain privileges via unknown vectors.

No fix yet
Fix from $1,600 2015-02-02
Tivoli Monitoring HIGH 8.5
CVE-2014-6141

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authe…

Mitigation only
Fix from $1,950 2015-02-02
Np Bbrm HIGH 7.8
CVE-2015-0869

I-O DATA DEVICE NP-BBRM routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests.

Mitigation only
Fix from $1,950 2015-02-01
Portal MEDIUM 6.4
CVE-2014-8268

QPR Portal before 2012.2.1 allows remote attackers to modify or delete notes via a direct request.

Fix: after 2012.2.0
Fix from $1,600 2015-02-01
Encryption Management Server HIGH 9.0
CVE-2014-7288EPSS 8%

Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell …

Fix: after 3.3.2
Fix from $1,950 2015-02-01
Mac Os X MEDIUM 5.0
CVE-2014-8831

security_taskgate in Apple OS X before 10.10.2 allows attackers to read group-ACL-restricted keychain items of arbitrary apps via a crafted app with …

Fix: after 10.10.1
Fix from $1,600 2015-01-30
Mac Os X HIGH 7.5
CVE-2014-8828

Sandbox in Apple OS X before 10.10 allows attackers to write to the sandbox-profile cache via a sandboxed app that includes a com.apple.sandbox segme…

Fix: after 10.9.5
Fix from $1,950 2015-01-30
Iphone Os MEDIUM 5.0
CVE-2014-4496

The mach_port_kobject interface in the kernel in Apple iOS before 8.1.3 and Apple TV before 7.0.3 does not properly restrict kernel-address and heap-…

Fix: after 8.1.2
Fix from $1,600 2015-01-30
Iphone Os HIGH 10.0
CVE-2014-4495

The kernel in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not enforce the read-only attribute of a shared memor…

Fix: after 10.10.1
Fix from $1,950 2015-01-30
Iphone Os HIGH 7.5
CVE-2014-4493

The app-installation functionality in MobileInstallation in Apple iOS before 8.1.3 allows attackers to obtain control of the local app container by l…

Fix: after 8.1.2
Fix from $1,950 2015-01-30
Player MEDIUM 6.4
CVE-2014-8370

VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, VMware Fusion 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allow host OS …

Patch available
Fix from $1,600 2015-01-29
Pixabay Images HIGH 7.5
CVE-2015-1375EPSS 12%

pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows …

Fix: after 2.3
Fix from $1,950 2015-01-28
Opensuse HIGH 7.2
CVE-2014-8148

The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system…

Mitigation only
Fix from $1,950 2015-01-26
Pie Register MEDIUM 5.0
CVE-2014-8802EPSS 8%

The Pie Register plugin before 2.0.14 for WordPress does not properly restrict access to certain functions in pie-register.php, which allows remote a…

Fix: after 2.0.13
Fix from $1,600 2015-01-23
Enterprise Resource Planning HIGH 7.5
CVE-2015-1312

The Dealer Portal in SAP ERP does not properly restrict access, which allows remote attackers to obtain sensitive information, gain privileges, and p…

Mitigation only
Fix from $1,950 2015-01-22
P.dga4001n Firmware HIGH 9.4
CVE-2015-0554EPSS 39%

The ADB (formerly Pirelli Broadband Solutions) P.DGA4001N router with firmware PDG_TEF_SP_4.06L.6 does not properly restrict access to the web interf…

No fix yet
Fix from $1,950 2015-01-21
Symantec Critical System Protection HIGH 7.2
CVE-2014-9226

The management server in Symantec Critical System Protection (SCSP) 5.2.9 through MP6 and Symantec Data Center Security: Server Advanced (SDCS:SA) 6.…

No fix yet
Fix from $1,950 2015-01-21