Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cordova HIGH 7.5
CVE-2014-1882EPSS 12%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Phonegap HIGH 7.5
CVE-2014-1883

Adobe PhoneGap before 2.6.0 on Android uses the shouldOverrideUrlLoading callback instead of the proper shouldInterceptRequest callback, which allows…

Fix: after 2.5.0
Fix from $1,950 2014-03-03
Cordova HIGH 7.5
CVE-2014-1884EPSS 8%

Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier on Windows Phone 7 and 8 do not properly restrict navigation events, which allo…

Fix: after 3.3.0
Fix from $1,950 2014-03-03
Forzearmate MEDIUM 6.4
CVE-2014-1885

The ForzeArmate application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, …

Mitigation only
Fix from $1,600 2014-03-03
Edinburgh By Bus MEDIUM 6.8
CVE-2014-1886

The Edinburgh by Bus application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript c…

No fix yet
Fix from $1,600 2014-03-03
Proxysgos HIGH 7.9
CVE-2014-2033

The caching feature in SGOS in Blue Coat ProxySG 5.5 through 5.5.11.3, 6.1 through 6.1.6.3, 6.2 through 6.2.15.3, 6.4 through 6.4.6.1, and 6.3 and 6.…

Fix: 6.5.4+
Fix from $1,950 2014-03-02
Security Suite HIGH 7.2
CVE-2014-0816

Unspecified vulnerability in Norman Security Suite 10.1 and earlier allows local users to gain privileges via unknown vectors.

Fix: after 10.1
Fix from $1,950 2014-02-27
Epolicy Orchestrator MEDIUM 6.3
CVE-2014-2205

The Import and Export Framework in McAfee ePolicy Orchestrator (ePO) before 4.6.7 Hotfix 940148 allows remote authenticated users with permissions to…

Fix: after 4.6.7
Fix from $1,600 2014-02-26
Chrome MEDIUM 6.4
CVE-2013-6657

core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certai…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Chrome MEDIUM 5.0
CVE-2013-6660

The drag-and-drop implementation in Google Chrome before 33.0.1750.117 does not properly restrict the information in WebDropData data structures, whi…

Fix: after 33.0.1750.116
Fix from $1,600 2014-02-24
Wemo Home Automation Firmware HIGH 9.3
CVE-2013-6949

The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack conne…

Mitigation only
Fix from $1,950 2014-02-22
Ips Sensor Software HIGH 7.8
CVE-2014-0719

The control-plane access-list implementation in Cisco IPS Software before 7.1(8p2)E4 and 7.2 before 7.2(2)E4 allows remote attackers to cause a denia…

Fix: after 7.1
Fix from $1,950 2014-02-22
Unified Sip Phone 3905 HIGH 10.0
CVE-2014-0721

The Cisco Unified SIP Phone 3905 with firmware before 9.4(1) allows remote attackers to obtain root access via a session on the test interface on TCP…

Mitigation only
Fix from $1,950 2014-02-22
Unified Communications Manager MEDIUM 5.0
CVE-2014-0731

The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authenticatio…

Fix: after 10.0
Fix from $1,600 2014-02-22
Cognos Business Intelligence MEDIUM 5.0
CVE-2014-0854

The server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 befor…

Mitigation only
Fix from $1,600 2014-02-22
Flash Player HIGH 7.8
CVE-2014-0499

Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR…

Fix: 4.0.0.1628 / 11.2.202.341+
Fix from $1,950 2014-02-21
Freepbx HIGH 7.5
CVE-2014-1903EPSS 53%

admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22 does not…

No fix yet
Fix from $1,950 2014-02-18
Puppet MEDIUM 5.5
CVE-2011-0528

Puppet 2.6.0 through 2.6.3 does not properly restrict access to node resources, which allows remote authenticated Puppet nodes to read or modify the …

Mitigation only
Fix from $1,600 2014-02-17
Quic Mobile Station Modem Kernel HIGH 9.3
CVE-2013-4737

The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devi…

Patch available
Fix from $1,950 2014-02-15
Nfs Utils HIGH 7.5
CVE-2011-2500

The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports,…

Fix: after 1.2.3
Fix from $1,950 2014-02-15
Netweaver MEDIUM 5.0
CVE-2014-1960

The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecifie…

Mitigation only
Fix from $1,600 2014-02-14
Lxc HIGH 7.2
CVE-2013-6441

The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local user…

Fix: after 0.9.0
Fix from $1,950 2014-02-14
Piranha MEDIUM 5.8
CVE-2013-6492

The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication…

Mitigation only
Fix from $1,600 2014-02-14
Sametime MEDIUM 5.0
CVE-2013-3978

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwan…

Mitigation only
Fix from $1,600 2014-02-14
Sametime HIGH 7.5
CVE-2013-6742

The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, whic…

Mitigation only
Fix from $1,950 2014-02-14
Websphere Dashboard Framework MEDIUM 5.8
CVE-2013-6728

The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging…

Mitigation only
Fix from $1,600 2014-02-14
Scanning Engine MEDIUM 5.6
CVE-2014-1213

Sophos Anti-Virus engine (SAVi) before 3.50.1, as used in VDL 4.97G 9.7.x before 9.7.9, 10.0.x before 10.0.11, and 10.3.x before 10.3.1 does not set …

Fix: after 3.48
Fix from $1,600 2014-02-10
Enterprise Virtualization MEDIUM 6.8
CVE-2012-3406

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the …

Mitigation only
Fix from $1,600 2014-02-10
Documentum Foundation Services HIGH 9.0
CVE-2014-0622

The web service in EMC Documentum Foundation Services (DFS) 6.5 through 6.7 before 6.7 SP1 P22, 6.7 SP2 before P08, 7.0 before P12, and 7.1 before P0…

Mitigation only
Fix from $1,950 2014-02-06
Systemtap MEDIUM 5.4
CVE-2012-0875

SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel …

Mitigation only
Fix from $1,600 2014-02-04