Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Business Process Manager MEDIUM 6.5
CVE-2014-4844

The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows re…

Mitigation only
Fix from $1,600 2014-12-17
Docker HIGH 10.0
CVE-2014-9357EPSS 6%

Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (…

Mitigation only
Fix from $1,950 2014-12-16
Zenoss Core HIGH 7.5
CVE-2014-9249

The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po…

Fix: after 4.2.5
Fix from $1,950 2014-12-15
Android HIGH 7.2
CVE-2014-8609

The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not prope…

Fix: after 4.4.4
Fix from $1,950 2014-12-15
Android HIGH 7.2
CVE-2014-7911EPSS 25%

luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deseri…

Fix: after 4.4.4
Fix from $1,950 2014-12-15
Zenoss Core MEDIUM 5.0
CVE-2014-6257

Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me…

Fix: after 5.0.0
Fix from $1,600 2014-12-15
Zenoss Core HIGH 7.5
CVE-2014-6256

Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2…

Fix: after 5.0.0
Fix from $1,950 2014-12-15
Docker MEDIUM 5.0
CVE-2014-6408

Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applyin…

Mitigation only
Fix from $1,600 2014-12-12
Track It\! MEDIUM 5.0
CVE-2014-8270EPSS 20%

BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy…

Mitigation only
Fix from $1,600 2014-12-12
Vcloud Automation Center HIGH 9.0
CVE-2014-8373

The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain pri…

No fix yet
Fix from $1,950 2014-12-11
Acrobat MEDIUM 5.0
CVE-2014-8453EPSS 13%

Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to bypass the Same Origin Policy via …

Mitigation only
Fix from $1,600 2014-12-10
Media Server HIGH 7.5
CVE-2014-9304EPSS 8%

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrati…

Fix: after 0.9.9.2
Fix from $1,950 2014-12-07
N5200 Active Network Control Panel HIGH 7.8
CVE-2014-8868EPSS 7%

EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username an…

No fix yet
Fix from $1,950 2014-12-07
Plasma Desktop HIGH 7.2
CVE-2014-8651

The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafte…

Fix: after 5.1
Fix from $1,950 2014-12-06
Documentum Content Server HIGH 9.0
CVE-2014-4629

EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via…

No fix yet
Fix from $1,950 2014-12-06
P2 6011 Firmware HIGH 7.2
CVE-2014-2273

The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecifie…

No fix yet
Fix from $1,950 2014-12-05
Fixed Assets Cs HIGH 7.2
CVE-2014-9141

The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute ar…

Fix: after 13.1.4
Fix from $1,950 2014-12-03
Prosystem Fx Engagement HIGH 7.2
CVE-2014-9113

CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the…

Fix: after 7.1
Fix from $1,950 2014-12-02
Ossec HIGH 7.2
CVE-2014-5284

host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modi…

Fix: after 2.8.0
Fix from $1,950 2014-12-02
Packstack MEDIUM 5.0
CVE-2014-3703

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration …

Mitigation only
Fix from $1,600 2014-12-02
Fasttoggle MEDIUM 5.8
CVE-2014-5268

The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link.

Patch available
Fix from $1,600 2014-12-01
Codemeter Runtime HIGH 7.2
CVE-2014-8419

Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to…

Fix: after 5.10c
Fix from $1,950 2014-11-26
Channel Platform MEDIUM 6.5
CVE-2014-8558

JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters.

No fix yet
Fix from $1,600 2014-11-25
Airwave HIGH 9.0
CVE-2014-8368

The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbit…

Fix: 7.7.14 / 8.0.5+
Fix from $1,950 2014-11-25
Drupal MEDIUM 6.8
CVE-2014-9015

Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to …

Fix: 6.34 / 7.34+
Fix from $1,600 2014-11-24
Certified Asterisk HIGH 9.0
CVE-2014-8418

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified …

Fix: 11.14.1 / 12.7.1+
Fix from $1,950 2014-11-24
Asterisk MEDIUM 6.5
CVE-2014-8417

ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote au…

Fix: 11.14.1 / 12.7.1+
Fix from $1,600 2014-11-24
Asterisk HIGH 7.5
CVE-2014-8413

The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.co…

Fix: 12.7.1 / 13.0.1+
Fix from $1,950 2014-11-24
Certified Asterisk MEDIUM 5.0
CVE-2014-8412

The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1,…

Fix: 1.8.32.1 / 11.14.1+
Fix from $1,600 2014-11-24
Apparmor MEDIUM 6.4
CVE-2014-1424

apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified ve…

Fix: after 2.8.94-0ubuntu1.4
Fix from $1,600 2014-11-24