Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Sharetronix HIGH 7.5
CVE-2013-5356

Sharetronix 3.1.1.3, 3.1.1, and earlier does not properly restrict access to unspecified AJAX functionality, which allows remote attackers to bypass …

Fix: after 3.1.1
Fix from $1,950 2014-06-13
Monkey MEDIUM 5.8
CVE-2013-2182EPSS 6%

The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as …

Fix: after 1.4.0
Fix from $1,600 2014-06-13
Flash Player HIGH 7.5
CVE-2014-0534EPSS 6%

Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Ad…

Fix: after 13.0.0.214
Fix from $1,950 2014-06-11
Adobe Air Sdk HIGH 7.5
CVE-2014-0535EPSS 10%

Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Ad…

Fix: after 13.0.0.111
Fix from $1,950 2014-06-11
Dcmtk HIGH 7.2
CVE-2013-6825

(1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in d…

Fix: after 3.6.1
Fix from $1,950 2014-06-10
Netweaver HIGH 7.5
CVE-2014-4003

The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system.

No fix yet
Fix from $1,950 2014-06-09
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3278

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack…

Mitigation only
Fix from $1,600 2014-06-08
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3281

The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack…

Mitigation only
Fix from $1,600 2014-06-08
Webex Meetings Server MEDIUM 5.0
CVE-2014-3286

The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2014-06-08
Documentum Content Server HIGH 8.5
CVE-2014-2506

EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to obtain …

Fix: after 6.7
Fix from $1,950 2014-06-08
Condor HIGH 10.0
CVE-2012-5390

The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privil…

Mitigation only
Fix from $1,950 2014-06-06
Xen HIGH 7.4
CVE-2014-3969

Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to …

Patch available
Fix from $1,950 2014-06-05
Ct50 Firmware HIGH 8.3
CVE-2013-4860

Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the oper…

Fix: after 1.4.64
Fix from $1,950 2014-06-05
Owncloud HIGH 7.5
CVE-2014-3834

ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access the contacts of other users v…

Fix: after 6.0.2
Fix from $1,950 2014-06-04
Owncloud Server MEDIUM 5.5
CVE-2014-3835

ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated …

Fix: after 5.0.15
Fix from $1,600 2014-06-04
Nodeaccesskeys MEDIUM 5.8
CVE-2013-4596

The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access res…

Patch available
Fix from $1,600 2014-06-02
Ubuntu Linux HIGH 7.6
CVE-2013-6433

The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which a…

Fix: after 2013.2.3
Fix from $1,950 2014-06-02
Vcenter Server Appliance HIGH 9.0
CVE-2014-3790

Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping fro…

Mitigation only
Fix from $1,950 2014-06-01
Db2 HIGH 8.5
CVE-2013-6744

The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated us…

Mitigation only
Fix from $1,950 2014-05-30
Unified Communications Domain Manager MEDIUM 5.0
CVE-2014-3279

The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implem…

Fix: after 9.0
Fix from $1,600 2014-05-29
Uportal MEDIUM 6.5
CVE-2014-3416

uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by lever…

Fix: after 4.0.13
Fix from $1,600 2014-05-29
Uportal MEDIUM 6.5
CVE-2014-3417

uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging th…

Fix: after 4.0.13
Fix from $1,600 2014-05-29
Ga Login MEDIUM 5.0
CVE-2013-4177

The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, whi…

Patch available
Fix from $1,600 2014-05-29
Freeipa MEDIUM 5.0
CVE-2013-0199

The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,…

Patch available
Fix from $1,600 2014-05-29
Mod Wsgi MEDIUM 6.2
CVE-2014-0240

The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain L…

Fix: after 3.4
Fix from $1,600 2014-05-27
Gcc MEDIUM 5.0
CVE-2013-4598

The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which allows remote attackers to ac…

Patch available
Fix from $1,600 2014-05-27
Moodle MEDIUM 5.0
CVE-2014-0216

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2…

Fix: after 2.3.11
Fix from $1,600 2014-05-27
Maximo Asset Management MEDIUM 6.0
CVE-2014-0849

IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authent…

Mitigation only
Fix from $1,600 2014-05-26
Maximo Asset Management MEDIUM 6.0
CVE-2013-5464

IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7…

Mitigation only
Fix from $1,600 2014-05-26
Maximo Asset Management MEDIUM 6.5
CVE-2013-5465

IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x bef…

Mitigation only
Fix from $1,600 2014-05-26