Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Rabbitmq MEDIUM 5.0
CVE-2014-9494

RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header.

Fix: after 3.3.5
Fix from $1,600 2015-01-20
Sas Raid Module Firmware MEDIUM 5.0
CVE-2014-3019

IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage…

Fix: after 1.3.3.004
Fix from $1,600 2015-01-17
Samba HIGH 8.5
CVE-2014-8143

Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows rem…

Patch available
Fix from $1,950 2015-01-17
Stdlib MEDIUM 6.5
CVE-2015-1029

The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g…

Mitigation only
Fix from $1,600 2015-01-16
Mediawiki MEDIUM 5.0
CVE-2014-9476

MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAX…

Fix: after 1.19.22
Fix from $1,600 2015-01-16
Junos MEDIUM 6.9
CVE-2014-6384

Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 bef…

Mitigation only
Fix from $1,600 2015-01-16
Vios HIGH 7.2
CVE-2014-8904

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variab…

No fix yet
Fix from $1,950 2015-01-15
Firefox HIGH 7.1
CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging acce…

Fix: after 34.0.5
Fix from $1,950 2015-01-14
Windows 7 MEDIUM 6.1
CVE-2015-0006EPSS 12%

The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S…

Mitigation only
Fix from $1,600 2015-01-13
Windows 7 HIGH 7.2
CVE-2015-0004

The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi…

No fix yet
Fix from $1,950 2015-01-13
Windows 7 HIGH 7.2
CVE-2015-0002EPSS 14%

The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, …

No fix yet
Fix from $1,950 2015-01-13
Realarcade Installer HIGH 7.2
CVE-2013-2604

RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for t…

Mitigation only
Fix from $1,950 2015-01-12
Secure Access Control System MEDIUM 6.5
CVE-2014-8027

The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges fo…

Mitigation only
Fix from $1,600 2015-01-09
Tm Ac1900 HIGH 10.0
CVE-2014-9583EPSS 80%

common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other route…

Mitigation only
Fix from $1,950 2015-01-08
Vdg Sense MEDIUM 6.4
CVE-2014-9575

VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin …

Fix: after 2.3.14
Fix from $1,600 2015-01-08
Openstack MEDIUM 5.5
CVE-2014-9493

The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete…

Fix: 2014.1.4 / 2014.2.2+
Fix from $1,600 2015-01-07
Kofax E Transactions Sender Sendbox MEDIUM 6.4
CVE-2011-5294

The SaveMessage method in the LEADeMail.LEADSmtp.20 ActiveX control in LTCML14n.dll 14.0.0.34 in Kofax e-Transactions Sender Sendbox 2.5.0.933 allows…

No fix yet
Fix from $1,600 2015-01-01
Easewe Ftp Ocx Activex Control HIGH 7.5
CVE-2011-5292

The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote …

No fix yet
Fix from $1,950 2015-01-01
Ashampoo 3d Cad Professional 3 MEDIUM 6.4
CVE-2011-5291

The SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx in Ashampoo 3D CAD Professional 3.x before 3.0.2 allows remote atta…

No fix yet
Fix from $1,600 2015-01-01
Idrive Online Backup MEDIUM 6.4
CVE-2011-5290

The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100_EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attacker…

No fix yet
Fix from $1,600 2015-01-01
Atube Catcher MEDIUM 6.4
CVE-2011-5289

The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers t…

No fix yet
Fix from $1,600 2015-01-01
Hiphop Virtual Machine MEDIUM 5.0
CVE-2014-2209

Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-…

Fix: after 3.0.1
Fix from $1,600 2014-12-28
Meraki Mr Firmware HIGH 7.7
CVE-2014-7999

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unsp…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Meraki Mx Firmware HIGH 7.2
CVE-2014-7995

Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's…

Fix: after 2014-09-24
Fix from $1,950 2014-12-24
Security Appscan MEDIUM 5.5
CVE-2014-6122

IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.…

Mitigation only
Fix from $1,600 2014-12-23
Mguard Firmware HIGH 9.0
CVE-2014-9193

Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP conf…

Fix: after 7.6.6
Fix from $1,950 2014-12-20
Otrs Help Desk MEDIUM 6.0
CVE-2014-9324

The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access a…

Mitigation only
Fix from $1,600 2014-12-19
Websphere Application Server MEDIUM 5.1
CVE-2014-8890

IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a s…

Mitigation only
Fix from $1,600 2014-12-18
Businessobjects HIGH 10.0
CVE-2014-9387

SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB…

Mitigation only
Fix from $1,950 2014-12-17
Documentum Content Server HIGH 9.0
CVE-2014-4626

EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain pr…

Fix: after 6.7
Fix from $1,950 2014-12-17