Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Plone HIGH 8.5
CVE-2012-5487

The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privile…

Fix: after 4.2.2
Fix from $1,950 2014-09-30
Ea6500 Firmware HIGH 7.1
CVE-2013-3066

Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients …

No fix yet
Fix from $1,950 2014-09-29
Openmediavault HIGH 8.8
CVE-2013-3632EPSS 57%

The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary command…

No fix yet
Fix from $1,950 2014-09-29
Juniper Installer Service Client HIGH 7.2
CVE-2014-3811

Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via uns…

Fix: after 4.0
Fix from $1,950 2014-09-29
Jigbrowser\+ MEDIUM 5.8
CVE-2014-5318

The jigbrowser+ application 1.8.1 and earlier for iOS allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code.

Fix: after 1.8.1
Fix from $1,600 2014-09-26
Acpi Support HIGH 7.2
CVE-2014-0484

The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment."

No fix yet
Fix from $1,950 2014-09-22
Nokia Asha 501 Software MEDIUM 6.6
CVE-2014-6602

Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mech…

No fix yet
Fix from $1,600 2014-09-22
Clearscada MEDIUM 5.0
CVE-2014-5412

Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access…

Mitigation only
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 6.9
CVE-2014-4368

The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking via vectors related to AssistiveTouch events.

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Gksu MEDIUM 6.8
CVE-2014-2886

GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrar…

No fix yet
Fix from $1,600 2014-09-18
Iphone Os MEDIUM 5.8
CVE-2014-4354

Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions vi…

Fix: after 7.1.2
Fix from $1,600 2014-09-18
Documentum Content Server HIGH 8.5
CVE-2014-4621

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected…

Fix: after 6.7
Fix from $1,950 2014-09-17
Documentum Content Server HIGH 7.1
CVE-2014-4622

EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileg…

Fix: after 6.7
Fix from $1,950 2014-09-17
Integraxor HIGH 9.0
CVE-2014-2375

Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, …

Fix: after 4.1.4392
Fix from $1,950 2014-09-15
Manageengine Eventlog Analyzer MEDIUM 6.5
CVE-2014-6043EPSS 13%

ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote …

No fix yet
Fix from $1,600 2014-09-11
Windows 8 HIGH 7.2
CVE-2014-4074

The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privi…

Patch available
Fix from $1,950 2014-09-10
Flash Player HIGH 10.0
CVE-2014-0557EPSS 5%

Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.…

Fix: after 14.0.0.179
Fix from $1,950 2014-09-10
Adobe Air HIGH 7.5
CVE-2014-0548

Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.…

Fix: after 14.0.0.179
Fix from $1,950 2014-09-10
Cognos Tm1 MEDIUM 5.0
CVE-2014-0877

IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page…

Patch available
Fix from $1,600 2014-09-05
Plack MEDIUM 5.0
CVE-2014-5269

Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of genera…

Fix: after 1.0030
Fix from $1,600 2014-09-04
Android Browser MEDIUM 5.8
CVE-2014-6041EPSS 18%

The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac…

No fix yet
Fix from $1,600 2014-09-02
Android Msm HIGH 7.2
CVE-2013-2595

The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) And…

Mitigation only
Fix from $1,950 2014-08-31
Wordpress Mobile Pack MEDIUM 5.0
CVE-2014-5337EPSS 17%

The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attack…

Fix: after 2.0.1
Fix from $1,600 2014-08-29
Clearpass Policy Manager HIGH 9.0
CVE-2014-2593

The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacte…

Mitigation only
Fix from $1,950 2014-08-29
Monitoring Agent For Unix Logs HIGH 7.2
CVE-2013-5467

Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shar…

Mitigation only
Fix from $1,950 2014-08-29
Transport Gateway Installation Software MEDIUM 5.0
CVE-2014-3345

The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check …

Mitigation only
Fix from $1,600 2014-08-28
Chrome MEDIUM 6.4
CVE-2014-3170

extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote at…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Chrome MEDIUM 6.4
CVE-2014-3172

The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL befo…

Fix: after 37.0.2062.93
Fix from $1,600 2014-08-27
Uplay Pc HIGH 7.2
CVE-2014-5453

Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game …

Fix: after 4.6.3208
Fix from $1,950 2014-08-25
A5s Firmware HIGH 10.0
CVE-2014-5246EPSS 12%

The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator acces…

Mitigation only
Fix from $1,950 2014-08-22