Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X MEDIUM 6.8
CVE-2014-4437

LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handle…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Mac Os X MEDIUM 6.8
CVE-2014-4441

NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attacker…

Fix: after 10.9.5
Fix from $1,600 2014-10-18
Adaptive Server Enterprise MEDIUM 6.5
CVE-2014-6283

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, whi…

No fix yet
Fix from $1,600 2014-10-17
Jenkins MEDIUM 6.5
CVE-2014-2058

BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary job…

Fix: after 1.550
Fix from $1,600 2014-10-17
Jenkins MEDIUM 6.0
CVE-2014-3663

Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and c…

Fix: after 3.1
Fix from $1,600 2014-10-16
Twiki MEDIUM 6.8
CVE-2014-7237EPSS 20%

lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload f…

Fix: after 6.0.0
Fix from $1,600 2014-10-16
.net Framework HIGH 10.0
CVE-2014-4073EPSS 23%

Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, whi…

Mitigation only
Fix from $1,950 2014-10-15
Firefox HIGH 7.5
CVE-2014-1575EPSS 5%

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory…

Fix: after 32.0
Fix from $1,950 2014-10-15
Fedora MEDIUM 5.0
CVE-2014-1572

The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before …

Patch available
Fix from $1,600 2014-10-13
Cryoserver Security Appliance MEDIUM 6.8
CVE-2014-4867

Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging acces…

Mitigation only
Fix from $1,600 2014-10-10
X2engine MEDIUM 5.0
CVE-2014-5298

FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blac…

Fix: after 4.1.7
Fix from $1,600 2014-10-10
Network Automation HIGH 7.2
CVE-2014-2646

Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors.

Mitigation only
Fix from $1,950 2014-10-10
Joomla\! HIGH 7.5
CVE-2014-7984

Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G…

Mitigation only
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-3189

The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate imag…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome HIGH 7.5
CVE-2014-3196

base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory…

Fix: after 38.0.2125.7
Fix from $1,950 2014-10-08
Chrome MEDIUM 5.0
CVE-2014-3197

The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, d…

Fix: after 38.0.2125.7
Fix from $1,600 2014-10-08
Neutron HIGH 7.6
CVE-2014-3632

The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stac…

Fix: after 2014.1.2
Fix from $1,950 2014-10-07
Vyatta 5400 Vrouter Software MEDIUM 5.0
CVE-2014-4869

The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging members…

Mitigation only
Fix from $1,600 2014-10-07
Cloudforms 3.0.1 Management Engine MEDIUM 6.5
CVE-2014-3642

vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated …

Fix: after 5.2.5
Fix from $1,600 2014-10-06
Conga MEDIUM 5.5
CVE-2014-3521

The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re…

Mitigation only
Fix from $1,600 2014-10-06
Ios Xr HIGH 7.5
CVE-2014-3396

Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass…

Mitigation only
Fix from $1,950 2014-10-05
Powermail HIGH 7.5
CVE-2014-6288

The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to bypass the CAPTCHA protection mechanism via unspecified vectors.

Mitigation only
Fix from $1,950 2014-10-03
Yet Another Gallery HIGH 7.5
CVE-2014-6289

The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension befo…

Fix: after 3.0.0
Fix from $1,950 2014-10-03
Debian Linux MEDIUM 5.8
CVE-2014-7155

The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which al…

Fix: after 4.4.0
Fix from $1,600 2014-10-02
Websphere Mq MEDIUM 6.5
CVE-2014-4793

IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the C…

Patch available
Fix from $1,600 2014-10-02
Hibernate Validator MEDIUM 5.0
CVE-2014-3558

ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 …

Fix: 4.3.2 / 5.1.2+
Fix from $1,600 2014-09-30
Drupal MEDIUM 6.8
CVE-2014-5267

modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declar…

Patch available
Fix from $1,600 2014-09-30
Plone MEDIUM 6.5
CVE-2012-5489

The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 bef…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5498

queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted req…

Fix: after 4.2.2
Fix from $1,600 2014-09-30
Plone MEDIUM 5.0
CVE-2012-5501

at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom conten…

Fix: after 4.2.2
Fix from $1,600 2014-09-30