Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Acrobat Reader HIGH 10.0
CVE-2014-0512

Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own…

Mitigation only
Fix from $1,950 2014-03-27
Moodle MEDIUM 5.8
CVE-2014-0125

repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, w…

Fix: after 2.3.11
Fix from $1,600 2014-03-24
Connectrix Manager MEDIUM 5.0
CVE-2014-2276

The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to th…

Fix: after 12.1.2
Fix from $1,600 2014-03-21
Camel HIGH 7.5
CVE-2014-0002EPSS 33%

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Camel HIGH 7.5
CVE-2014-0003EPSS 7%

The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit…

Fix: after 2.11.3
Fix from $1,950 2014-03-21
Domain Technologie Control HIGH 7.5
CVE-2011-5275

The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for …

Fix: after 0.32.11
Fix from $1,950 2014-03-21
Ironport Asyncos HIGH 8.5
CVE-2014-2119

The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1…

Fix: after 7.9.1-039
Fix from $1,950 2014-03-21
Firefox MEDIUM 5.8
CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving…

Fix: after 27.0.1
Fix from $1,600 2014-03-19
Qnx Neutrino Rtos HIGH 7.2
CVE-2014-2533

/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comm…

No fix yet
Fix from $1,950 2014-03-18
Owncloud MEDIUM 6.5
CVE-2013-2048

ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified …

Fix: after 5.0.5
Fix from $1,600 2014-03-14
Owncloud Server MEDIUM 5.0
CVE-2014-2049

The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified v…

Fix: after 5.0.14
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2014-1276

IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Tvos MEDIUM 5.8
CVE-2014-1282

The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.8
CVE-2014-1285

Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Contact Form 7 MEDIUM 5.0
CVE-2014-2265

Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omittin…

Fix: after 3.7.1
Fix from $1,600 2014-03-14
Iphone Os HIGH 8.8
CVE-2013-5133

Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c…

Fix: after 7.0.6
Fix from $1,950 2014-03-14
Samba MEDIUM 5.8
CVE-2013-6442

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgr…

Mitigation only
Fix from $1,600 2014-03-14
Iphone Os MEDIUM 5.0
CVE-2013-6835EPSS 7%

TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot…

Fix: after 7.0.6
Fix from $1,600 2014-03-14
Windows 7 HIGH 7.2
CVE-2014-0300

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2…

Patch available
Fix from $1,950 2014-03-12
Plone MEDIUM 5.8
CVE-2013-4191

zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in…

Patch available
Fix from $1,600 2014-03-11
Plone MEDIUM 5.0
CVE-2013-4196

The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restric…

Patch available
Fix from $1,600 2014-03-11
F460 HIGH 10.0
CVE-2014-2321EPSS 59%

web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by …

Mitigation only
Fix from $1,950 2014-03-11
Aix MEDIUM 6.5
CVE-2014-0899

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated …

Mitigation only
Fix from $1,600 2014-03-11
Puppet Enterprise MEDIUM 5.0
CVE-2013-4971

Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive …

Fix: after 3.1.1
Fix from $1,600 2014-03-09
Gnutls MEDIUM 5.8
CVE-2014-1959

lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attack…

Fix: after 3.1.20
Fix from $1,600 2014-03-07
Gnutls MEDIUM 5.8
CVE-2009-5138

GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which …

Fix: after 2.7.5
Fix from $1,600 2014-03-07
Documentum Taskspace HIGH 8.5
CVE-2014-0629

EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 does not properly handle the interaction between the dm_world group and the dm…

Mitigation only
Fix from $1,950 2014-03-06
Chrome MEDIUM 5.8
CVE-2013-6666

The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not veri…

Fix: after 33.0.1750.144
Fix from $1,600 2014-03-05
Android Api MEDIUM 6.8
CVE-2012-6636EPSS 41%

The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary me…

Fix: after 16.0
Fix from $1,600 2014-03-03
Cordova HIGH 7.5
CVE-2014-1881EPSS 11%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03