Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Sametime MEDIUM 5.0
CVE-2013-3981

The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users v…

Mitigation only
Fix from $1,600 2014-05-26
Nx Os HIGH 7.1
CVE-2013-1191

Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…

Mitigation only
Fix from $1,950 2014-05-26
Nx Os HIGH 7.1
CVE-2014-2200

Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga…

Mitigation only
Fix from $1,950 2014-05-26
Documentum D2 HIGH 9.0
CVE-2014-2504

EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass …

Mitigation only
Fix from $1,950 2014-05-26
Imember360 MEDIUM 5.0
CVE-2014-3848EPSS 9%

The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials vi…

Fix: after 3.9.000
Fix from $1,600 2014-05-23
Nullmailer MEDIUM 5.0
CVE-2013-4223

The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut…

Mitigation only
Fix from $1,600 2014-05-23
Cloudplatform HIGH 7.5
CVE-2013-2757

Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network…

Patch available
Fix from $1,950 2014-05-23
Color Picker MEDIUM 5.0
CVE-2014-3844

The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings…

Fix: after 1.1
Fix from $1,600 2014-05-22
TYPO3 MEDIUM 5.5
CVE-2013-4320

The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenti…

Mitigation only
Fix from $1,600 2014-05-20
X2go Server HIGH 9.0
CVE-2013-7383

x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vect…

Fix: after 4.0.0.7
Fix from $1,950 2014-05-20
Mahara MEDIUM 5.5
CVE-2013-4431

Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users …

Fix: after 1.5.11
Fix from $1,600 2014-05-19
Quicktabs MEDIUM 5.0
CVE-2013-4406

The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions…

Patch available
Fix from $1,600 2014-05-19
Skybox View Appliance Iso HIGH 8.5
CVE-2014-2084

Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin in…

No fix yet
Fix from $1,950 2014-05-17
Workspace Streaming HIGH 7.9
CVE-2014-1649EPSS 42%

The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLR…

Fix: after 7.5.0
Fix from $1,950 2014-05-16
Windows 7 HIGH 7.2
CVE-2014-1807

The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win…

Patch available
Fix from $1,950 2014-05-14
Office MEDIUM 6.8
CVE-2014-1809EPSS 10%

The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypas…

Mitigation only
Fix from $1,600 2014-05-14
Flash Player HIGH 7.5
CVE-2014-0520

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…

Fix: 11.2.202.359 / 13.0.0.111+
Fix from $1,950 2014-05-14
Acrobat Reader HIGH 10.0
CVE-2014-0525EPSS 6%

The API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X does not prevent access to unmapped memory, which…

Mitigation only
Fix from $1,950 2014-05-14
Flash Player HIGH 7.5
CVE-2014-0516

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…

Fix: 11.2.202.359 / 13.0.0.111+
Fix from $1,950 2014-05-14
Flash Player HIGH 7.5
CVE-2014-0517

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…

Fix: 11.2.202.359 / 13.0.0.111+
Fix from $1,950 2014-05-14
Flash Player HIGH 7.5
CVE-2014-0518

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…

Fix: 11.2.202.359 / 13.0.0.111+
Fix from $1,950 2014-05-14
Flash Player HIGH 7.5
CVE-2014-0519

Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi…

Fix: 11.2.202.359 / 13.0.0.111+
Fix from $1,950 2014-05-14
Icedtea Web MEDIUM 6.8
CVE-2011-2514

The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef…

Fix: after 1.8.8
Fix from $1,600 2014-05-14
Quiz MEDIUM 5.0
CVE-2013-4501

The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vecto…

Patch available
Fix from $1,600 2014-05-13
Foreman MEDIUM 5.0
CVE-2014-0192

Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive inf…

Patch available
Fix from $1,600 2014-05-08
Foreman MEDIUM 6.5
CVE-2013-0187

Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.

Fix: after 1.0
Fix from $1,600 2014-05-08
Policycoreutils MEDIUM 6.9
CVE-2014-3215

seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the s…

Mitigation only
Fix from $1,600 2014-05-08
Symantec Critical System Protection HIGH 7.6
CVE-2013-5016

Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to b…

Fix: after 5.2.8
Fix from $1,950 2014-05-08
Struts MEDIUM 5.8
CVE-2014-0116EPSS 7%

CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me…

Mitigation only
Fix from $1,600 2014-05-08
Xen MEDIUM 6.7
CVE-2014-3124

The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or poss…

Patch available
Fix from $1,600 2014-05-07