Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cisco Nexus 1000v Intercloud MEDIUM 5.0
CVE-2014-0685

Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2…

Fix: after 5.2
Fix from $1,600 2014-05-07
Fish MEDIUM 6.9
CVE-2014-2905

fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal vari…

Mitigation only
Fix from $1,600 2014-05-02
FreeBSD MEDIUM 5.8
CVE-2014-3001

The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to…

Mitigation only
Fix from $1,600 2014-05-02
Information Enterprise Server MEDIUM 6.8
CVE-2014-3006

Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows…

Mitigation only
Fix from $1,600 2014-05-02
Xen MEDIUM 6.2
CVE-2014-3125

Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the har…

Patch available
Fix from $1,600 2014-05-02
Plone MEDIUM 5.5
CVE-2013-7061

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via …

Mitigation only
Fix from $1,600 2014-05-02
Telepresence Te Software HIGH 7.2
CVE-2014-2173

Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users t…

Mitigation only
Fix from $1,950 2014-05-02
Garoon MEDIUM 6.0
CVE-2014-1989

Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspec…

Mitigation only
Fix from $1,600 2014-05-02
Php Fusion MEDIUM 5.0
CVE-2013-1807EPSS 8%

PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow …

Fix: after 7.02.05
Fix from $1,600 2014-04-30
Netweaver Java Application Server MEDIUM 5.0
CVE-2014-3133

SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o…

Mitigation only
Fix from $1,600 2014-04-30
Super HIGH 7.2
CVE-2014-0470

super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges v…

Mitigation only
Fix from $1,950 2014-04-30
Fortiweb MEDIUM 6.5
CVE-2014-1957

FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

Fix: after 5.0.2
Fix from $1,600 2014-04-30
Fortiauthenticator HIGH 9.0
CVE-2013-6990

FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.

Fix: after 2.2
Fix from $1,950 2014-04-30
Invitation MEDIUM 5.0
CVE-2013-7063

The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspe…

Mitigation only
Fix from $1,600 2014-04-29
Organic Groups MEDIUM 5.8
CVE-2013-7065

The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups v…

Patch available
Fix from $1,600 2014-04-29
Struts HIGH 7.5
CVE-2014-0112EPSS 98%

ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Struts HIGH 7.5
CVE-2014-0113EPSS 78%

CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method…

Fix: 2.3.16.2+
Fix from $1,950 2014-04-29
Ubuntu Linux HIGH 9.0
CVE-2014-0187

The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass secu…

Mitigation only
Fix from $1,950 2014-04-28
Timeline HIGH 7.5
CVE-2014-1217

Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and ob…

Mitigation only
Fix from $1,950 2014-04-28
Xen MEDIUM 5.5
CVE-2014-2915

Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of s…

Mitigation only
Fix from $1,600 2014-04-24
iOS MEDIUM 5.0
CVE-2012-3946

Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an u…

Fix: after 15.3
Fix from $1,600 2014-04-24
Django MEDIUM 5.0
CVE-2014-0473

The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all…

Fix: after 1.4.10
Fix from $1,600 2014-04-23
Mac Os X HIGH 10.0
CVE-2014-1314

WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox …

Fix: after 10.9.2
Fix from $1,950 2014-04-23
Jetpack MEDIUM 5.8
CVE-2014-0173

The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x…

Mitigation only
Fix from $1,600 2014-04-22
Phpfox MEDIUM 5.5
CVE-2013-7195

PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specif…

Mitigation only
Fix from $1,600 2014-04-18
Phpfox MEDIUM 5.5
CVE-2013-7196

static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a privat…

Mitigation only
Fix from $1,600 2014-04-18
Openstack MEDIUM 6.4
CVE-2014-0071

PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int…

Mitigation only
Fix from $1,600 2014-04-17
Grails Resources MEDIUM 5.0
CVE-2014-0053

The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files…

Mitigation only
Fix from $1,600 2014-04-15
Grails Resources MEDIUM 5.0
CVE-2014-2857

The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to file…

Mitigation only
Fix from $1,600 2014-04-15
Commonspot Content Server HIGH 7.5
CVE-2014-2859

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

Fix: after 7.0.1
Fix from $1,950 2014-04-15