Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Moodle MEDIUM 5.5
CVE-2014-7837

mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remo…

Fix: after 2.4.11
Fix from $1,600 2014-11-24
Unified Communications Manager Im And Presence Service MEDIUM 5.0
CVE-2014-8000

Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user…

Mitigation only
Fix from $1,600 2014-11-21
Managed File Transfer Internet Server MEDIUM 6.4
CVE-2014-7194

TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before…

Fix: after 7.2.3
Fix from $1,600 2014-11-21
Protected Pages HIGH 7.5
CVE-2014-9024

The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.

Patch available
Fix from $1,950 2014-11-20
Twilio MEDIUM 5.5
CVE-2014-9023

The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authent…

Mitigation only
Fix from $1,600 2014-11-20
Web Component Roles MEDIUM 6.4
CVE-2014-9022

The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" rest…

Patch available
Fix from $1,600 2014-11-20
Zxhn H108l Firmware MEDIUM 5.0
CVE-2014-8493EPSS 8%

ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1.

No fix yet
Fix from $1,600 2014-11-20
Xprintserver HIGH 10.0
CVE-2014-9002EPSS 5%

Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in …

Mitigation only
Fix from $1,950 2014-11-20
Mule Enterprise Management Console MEDIUM 6.5
CVE-2014-9000EPSS 9%

Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to…

No fix yet
Fix from $1,600 2014-11-20
Iphone Os HIGH 7.5
CVE-2014-4457

The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend…

Fix: after 8.1
Fix from $1,950 2014-11-18
Iphone Os HIGH 7.2
CVE-2014-4451

Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo…

Fix: after 8.1
Fix from $1,950 2014-11-18
Vtiger Crm MEDIUM 5.0
CVE-2014-2268EPSS 31%

views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in…

No fix yet
Fix from $1,600 2014-11-16
Zendopenid MEDIUM 6.4
CVE-2014-2684

The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 d…

Fix: after 2.0.1
Fix from $1,600 2014-11-16
iOS HIGH 7.1
CVE-2014-7998

Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m…

Mitigation only
Fix from $1,950 2014-11-15
Connected Components Workbench HIGH 7.5
CVE-2014-5424EPSS 11%

Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or p…

Fix: after 6.01.00
Fix from $1,950 2014-11-14
Mobile Partner Firmware HIGH 7.2
CVE-2014-8359

Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct D…

No fix yet
Fix from $1,950 2014-11-13
Openshift HIGH 7.5
CVE-2014-3674

Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of …

Fix: after 2.1.8
Fix from $1,950 2014-11-13
Flash Player HIGH 7.5
CVE-2014-8442EPSS 5%

Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.…

Fix: 11.2.202.418 / 13.0.0.252+
Fix from $1,950 2014-11-11
Active Directory Federation Services MEDIUM 5.0
CVE-2014-6331EPSS 20%

Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not pr…

Mitigation only
Fix from $1,600 2014-11-11
Internet Information Services MEDIUM 5.1
CVE-2014-4078EPSS 20%

The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for doma…

Mitigation only
Fix from $1,600 2014-11-11
Firmware MEDIUM 5.0
CVE-2014-8655EPSS 7%

The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass aut…

No fix yet
Fix from $1,600 2014-11-06
Ibackup HIGH 7.2
CVE-2014-5507

iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Tr…

Fix: after 10.0.0.32
Fix from $1,950 2014-11-03
Espocrm MEDIUM 5.0
CVE-2014-7986

install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter.

Fix: after 2.5.2
Fix from $1,600 2014-10-31
Torque Resource Manager MEDIUM 6.8
CVE-2014-3684

The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and e…

Mitigation only
Fix from $1,600 2014-10-30
Deepofix MEDIUM 5.0
CVE-2013-6796EPSS 6%

The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous …

Fix: after 3.3
Fix from $1,600 2014-10-26
6.0 MEDIUM 5.0
CVE-2014-4624

EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which a…

No fix yet
Fix from $1,600 2014-10-25
Banana Dance MEDIUM 5.0
CVE-2012-5243

functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

No fix yet
Fix from $1,600 2014-10-21
Smartphone Pentest Framework MEDIUM 5.0
CVE-2012-5696

Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers…

Fix: after 0.1.2
Fix from $1,600 2014-10-20
Asyncos MEDIUM 5.0
CVE-2014-3381

The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which …

Fix: after 8.5
Fix from $1,600 2014-10-19
Mac Os X HIGH 7.5
CVE-2014-4427

App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.

Fix: after 10.9.5
Fix from $1,950 2014-10-18