Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Commonspot Content Server MEDIUM 6.5
CVE-2014-2862

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated user…

Fix: after 7.0.1
Fix from $1,600 2014-04-15
Commonspot Content Server HIGH 7.5
CVE-2014-2865

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demons…

Fix: after 7.0.1
Fix from $1,950 2014-04-15
Documentum Content Server MEDIUM 5.5
CVE-2014-0642

EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass …

Fix: after 6.7
Fix from $1,600 2014-04-15
Camiapp MEDIUM 5.8
CVE-2014-1986

The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intended access restrictions and rea…

Fix: after 1.21.1
Fix from $1,600 2014-04-15
Adobe Reader HIGH 9.3
CVE-2014-0514EPSS 72%

The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute ar…

Fix: after 11.1.3
Fix from $1,950 2014-04-15
Xalan Java HIGH 7.5
CVE-2014-0107EPSS 14%

The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en…

Fix: after 2.7.1
Fix from $1,950 2014-04-15
Compute MEDIUM 6.0
CVE-2014-0167

The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R…

Patch available
Fix from $1,600 2014-04-15
Web Appliance Firmware HIGH 8.5
CVE-2014-2849EPSS 60%

The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass…

Fix: after 3.8.1.1
Fix from $1,950 2014-04-11
Tigase HIGH 7.8
CVE-2014-2746

net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which allows remote attackers to caus…

Fix: after 5.2.0
Fix from $1,950 2014-04-11
Mongooseim HIGH 7.8
CVE-2014-2829

Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers …

Fix: after 1.3.1
Fix from $1,950 2014-04-11
Metronome HIGH 7.8
CVE-2014-2743

plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows re…

Fix: after 3.4
Fix from $1,950 2014-04-11
Prosody HIGH 7.8
CVE-2014-2745

Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service…

Fix: after 0.9.3
Fix from $1,950 2014-04-11
Openfire HIGH 7.8
CVE-2014-2741

nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements, which al…

Fix: after 3.9.1
Fix from $1,950 2014-04-11
M Link HIGH 7.8
CVE-2014-2742

Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of s…

Mitigation only
Fix from $1,950 2014-04-11
Business Process Manager MEDIUM 6.0
CVE-2014-0908

The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does …

Mitigation only
Fix from $1,600 2014-04-10
Netweaver HIGH 7.5
CVE-2013-7364

An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri…

Mitigation only
Fix from $1,950 2014-04-10
Enterprise Portal HIGH 7.5
CVE-2013-7367

SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u…

Mitigation only
Fix from $1,950 2014-04-10
Enhancement Package HIGH 7.5
CVE-2014-2748

The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes …

Mitigation only
Fix from $1,950 2014-04-10
Adaptive Security Appliance Software HIGH 8.5
CVE-2014-2126

Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 befor…

Mitigation only
Fix from $1,950 2014-04-10
Adobe Air Sdk MEDIUM 5.0
CVE-2014-0508

Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR be…

Fix: after 11.2.202.346
Fix from $1,600 2014-04-08
Rendezvous MEDIUM 5.0
CVE-2014-2541

The Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO…

Fix: after 8.7.0
Fix from $1,600 2014-04-08
Barclamp HIGH 7.5
CVE-2014-0592

Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instan…

Patch available
Fix from $1,950 2014-04-04
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2014-0093

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by…

Mitigation only
Fix from $1,600 2014-04-03
Keystone MEDIUM 5.0
CVE-2014-2237

The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i…

Mitigation only
Fix from $1,600 2014-04-01
Commons Fileupload HIGH 7.5
CVE-2014-0050EPSS 83%

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c…

Fix: after 1.3
Fix from $1,950 2014-04-01
Superuser HIGH 7.6
CVE-2013-6770

The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /sys…

No fix yet
Fix from $1,950 2014-03-31
Supersu HIGH 10.0
CVE-2013-6775

The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacter…

Mitigation only
Fix from $1,950 2014-03-31
PostgreSQL MEDIUM 6.5
CVE-2014-0061

The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7,…

Fix: after 8.4.19
Fix from $1,600 2014-03-31
Manageengine Opstor MEDIUM 6.5
CVE-2014-0344EPSS 6%

Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obta…

Fix: after 8.3
Fix from $1,600 2014-03-29
Firefox MEDIUM 5.0
CVE-2014-1516

The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s…

Fix: after 28.0.1
Fix from $1,600 2014-03-29