Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Unifi Video MEDIUM 6.0
CVE-2014-2227

The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 d…

Fix: after 2.1.3
Fix from $1,600 2014-07-25
Bozohttpd MEDIUM 5.0
CVE-2014-5015

bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote att…

Fix: after 20140201
Fix from $1,600 2014-07-24
Simatic Pcs7 MEDIUM 6.0
CVE-2014-4684

The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via…

Fix: after 8.0
Fix from $1,600 2014-07-24
Firefox MEDIUM 5.8
CVE-2014-1552

Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote at…

Fix: after 30.0
Fix from $1,600 2014-07-23
Firefox MEDIUM 5.8
CVE-2014-1561

Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to al…

Fix: after 30.0
Fix from $1,600 2014-07-23
Debian Linux MEDIUM 6.8
CVE-2014-3160

The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly…

Mitigation only
Fix from $1,600 2014-07-20
Chrome HIGH 7.5
CVE-2014-3161

The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android…

Fix: after 36.0.1985.106
Fix from $1,950 2014-07-20
Garoon HIGH 7.5
CVE-2014-1996

Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial o…

Mitigation only
Fix from $1,950 2014-07-20
Entity Api MEDIUM 5.0
CVE-2013-7391

The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restrict…

Fix: after 7.x-1.1
Fix from $1,600 2014-07-19
Storwize Unified V7000 Software MEDIUM 6.5
CVE-2014-3043

IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service ac…

Mitigation only
Fix from $1,600 2014-07-19
Scrutinizer MEDIUM 5.5
CVE-2014-4976

Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p…

No fix yet
Fix from $1,600 2014-07-16
Zxv10 W300 Firmware MEDIUM 5.0
CVE-2014-4154EPSS 7%

ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows…

No fix yet
Fix from $1,600 2014-07-16
Junos HIGH 9.0
CVE-2014-3816

Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 b…

Mitigation only
Fix from $1,950 2014-07-11
Docker HIGH 7.2
CVE-2014-3499

Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified…

Mitigation only
Fix from $1,950 2014-07-11
iOS MEDIUM 5.0
CVE-2014-3309

The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows…

Mitigation only
Fix from $1,600 2014-07-09
Adobe Air Sdk HIGH 7.5
CVE-2014-0537

Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on …

Fix: after 14.0.0.110
Fix from $1,950 2014-07-09
Adobe Air HIGH 7.5
CVE-2014-0539

Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on …

Fix: after 14.0.0.110
Fix from $1,950 2014-07-09
Windows 7 HIGH 7.6
CVE-2014-2781EPSS 6%

Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows …

Patch available
Fix from $1,950 2014-07-08
Safeguard HIGH 9.3
CVE-2014-2956

ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 1…

Fix: after 18.1.7
Fix from $1,950 2014-07-08
Unified Cdm Application Software HIGH 7.5
CVE-2014-3300EPSS 22%

The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not p…

Fix: after 8.1.4
Fix from $1,950 2014-07-07
Unified Cdm Application Software HIGH 9.0
CVE-2014-2197

The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 doe…

Fix: after 8.1
Fix from $1,950 2014-07-07
Vios HIGH 7.2
CVE-2014-3074

The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, b…

No fix yet
Fix from $1,950 2014-07-02
Sametime Meeting Server MEDIUM 5.5
CVE-2014-3088

stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST re…

No fix yet
Fix from $1,600 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1373

Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitr…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1376

Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code…

Fix: after 10.9.3
Fix from $1,950 2014-07-01
Mac Os X HIGH 10.0
CVE-2014-1381

Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary cod…

Mitigation only
Fix from $1,950 2014-07-01
Tvos MEDIUM 5.5
CVE-2014-1383

Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspeci…

Fix: after 6.1.1
Fix from $1,600 2014-07-01
Openpages Grc Platform MEDIUM 6.4
CVE-2011-1381

Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown…

Mitigation only
Fix from $1,600 2014-06-27
Linux Kernel MEDIUM 6.2
CVE-2014-4014

The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows…

Fix: 3.14.8+
Fix from $1,600 2014-06-23
Pureapplication System MEDIUM 6.6
CVE-2014-0960

IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictio…

Mitigation only
Fix from $1,600 2014-06-14