Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Websphere Application Server MEDIUM 5.0
CVE-2014-3070

The addFileRegistryAccount Virtual Member Manager (VMM) SPI Admin Task in IBM WebSphere Application Server (WAS) 8.0.x before 8.0.0.10 and 8.5.x befo…

Mitigation only
Fix from $1,600 2014-08-22
Websphere Application Server MEDIUM 5.0
CVE-2014-3083

IBM WebSphere Application Server (WAS) 7.0.x before 7.0.0.35, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.3 does not properly restrict resource acc…

Mitigation only
Fix from $1,600 2014-08-22
Rails HIGH 7.5
CVE-2014-3514

activerecord/lib/active_record/relation/query_methods.rb in Active Record in Ruby on Rails 4.0.x before 4.0.9 and 4.1.x before 4.1.5 allows remote at…

Mitigation only
Fix from $1,950 2014-08-20
Documentum Content Server HIGH 8.5
CVE-2014-4618

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07 allows remote authenticated users to gain privileges via a user-created syste…

Fix: after 6.7
Fix from $1,950 2014-08-20
Documentum D2 HIGH 8.5
CVE-2014-2515

EMC Documentum D2 3.1 before P24, 3.1SP1 before P02, 4.0 before P11, 4.1 before P16, and 4.2 before P05 does not properly restrict tickets provided b…

Mitigation only
Fix from $1,950 2014-08-20
Documentum Content Server MEDIUM 6.3
CVE-2014-2520

EMC Documentum Content Server before 6.7 SP2 P16 and 7.x before 7.1 P07, when Oracle Database is used, does not properly restrict DQL hints, which al…

Fix: after 6.7
Fix from $1,600 2014-08-20
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2014-3464

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not proper…

Mitigation only
Fix from $1,600 2014-08-19
Blackberry Os MEDIUM 6.1
CVE-2014-2388

The Storage and Access service in BlackBerry OS 10.x before 10.2.1.1925 on Q5, Q10, Z10, and Z30 devices does not enforce the password requirement fo…

Fix: after 10.1.0.2354
Fix from $1,600 2014-08-18
Infosphere Master Data Management HIGH 7.5
CVE-2014-3063

IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1-FP11 and 11.x before 11.0-FP5 and InfoSphere Master Data Management Se…

Patch available
Fix from $1,950 2014-08-17
Adobe Air Sdk HIGH 10.0
CVE-2014-0540

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Flash Player HIGH 10.0
CVE-2014-0541EPSS 6%

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Adobe Air HIGH 10.0
CVE-2014-0542

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Flash Player HIGH 10.0
CVE-2014-0543

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Flash Player HIGH 10.0
CVE-2014-0544

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Flash Player HIGH 10.0
CVE-2014-0545

Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on …

Fix: after 14.0.0.137
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-0318

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-1814

The Windows Installer in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows …

Patch available
Fix from $1,950 2014-08-12
Windows 7 HIGH 7.2
CVE-2014-1819

win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-08-12
Sharepoint Foundation HIGH 9.3
CVE-2014-2816EPSS 16%

Microsoft SharePoint Server 2013 Gold and SP1 and SharePoint Foundation 2013 Gold and SP1 allow remote authenticated users to gain privileges via a T…

Mitigation only
Fix from $1,950 2014-08-12
Nx Os MEDIUM 5.0
CVE-2014-3330

Cisco NX-OS 6.1(2)I2(1) on Nexus 9000 switches does not properly process packet-drop policy checks for logged packets, which allows remote attackers …

Mitigation only
Fix from $1,600 2014-08-11
Unity Connection HIGH 9.0
CVE-2014-3333

The server in Cisco Unity Connection 9.1(1) and 9.1(2) allows remote authenticated users to obtain privileged access by conducting an "HTTP Intercept…

Mitigation only
Fix from $1,950 2014-08-11
Teampass HIGH 7.5
CVE-2014-3771

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via the language file path in a (1) request to index.php or (2) "change_…

Fix: after 2.1.20
Fix from $1,950 2014-08-07
Teampass HIGH 7.5
CVE-2014-3772

TeamPass before 2.1.20 allows remote attackers to bypass access restrictions via a request to index.php followed by a direct request to a file that c…

Fix: after 2.1.20
Fix from $1,950 2014-08-07
Ctdb HIGH 7.5
CVE-2013-4159

ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulner…

Fix: after 2.2
Fix from $1,950 2014-08-06
Android Msm HIGH 7.2
CVE-2014-0972

The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other produ…

Mitigation only
Fix from $1,950 2014-08-01
Hana Extended Application Services MEDIUM 5.0
CVE-2014-5173

SAP HANA Extend Application Services (XS) allows remote attackers to bypass access restrictions via a request to a private IU5 SDK application that w…

No fix yet
Fix from $1,600 2014-07-31
Embedded Websphere Application Server MEDIUM 6.9
CVE-2014-3020

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable …

Mitigation only
Fix from $1,600 2014-07-29
Ubuntu Linux MEDIUM 5.0
CVE-2014-5031

The web interface in CUPS before 2.0 does not check that files have world-readable permissions, which allows remote attackers to obtains sensitive in…

Fix: after 1.7.4
Fix from $1,600 2014-07-29
Moodle MEDIUM 5.0
CVE-2014-3546

Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 does not enforce certain capability requir…

Fix: after 2.3.11
Fix from $1,600 2014-07-29
Resin MEDIUM 5.0
CVE-2014-2966

The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended…

Fix: after 4.0.39
Fix from $1,600 2014-07-26