Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Unified Communications Manager MEDIUM 6.0
CVE-2014-0686

Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file…

Fix: after 9.1
Fix from $1,600 2014-02-04
Cantata MEDIUM 5.0
CVE-2013-7301

Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading th…

Fix: after 1.2.1
Fix from $1,600 2014-02-02
Financial Transaction Manager MEDIUM 5.5
CVE-2014-0833

The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a…

Mitigation only
Fix from $1,600 2014-02-01
Sametime MEDIUM 5.0
CVE-2013-6727

The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att…

Mitigation only
Fix from $1,600 2014-01-31
Access Risk Management Suite MEDIUM 6.5
CVE-2013-2747

The password reset feature in Courion Access Risk Management Suite Version 8 Update 9 allows remote authenticated users to bypass intended Internet E…

Mitigation only
Fix from $1,600 2014-01-29
Tivoli Application Dependency Discovery Manager HIGH 7.5
CVE-2013-2974

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut…

Mitigation only
Fix from $1,950 2014-01-29
Proc\ HIGH 7.2
CVE-2013-7135

The Proc::Daemon module 0.14 for Perl uses world-writable permissions for a file that stores a process ID, which allows local users to have an unspec…

Mitigation only
Fix from $1,950 2014-01-28
Xen HIGH 8.3
CVE-2014-1666

The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix …

Patch available
Fix from $1,950 2014-01-26
Marc Xml MEDIUM 5.0
CVE-2014-1626

XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other pro…

Fix: after 1.0.1
Fix from $1,600 2014-01-26
Ts 550 Evo Firmware MEDIUM 5.0
CVE-2013-7247

cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover…

No fix yet
Fix from $1,600 2014-01-26
Secure Access Control System MEDIUM 5.5
CVE-2014-0678

The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack…

Mitigation only
Fix from $1,600 2014-01-25
Libvirt MEDIUM 5.2
CVE-2013-6457

The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap…

Fix: after 1.2.0
Fix from $1,600 2014-01-24
Spring Framework MEDIUM 6.8
CVE-2013-7315EPSS 5%

The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactor…

Fix: after 3.2.3
Fix from $1,600 2014-01-23
Spring Framework MEDIUM 6.8
CVE-2013-4152EPSS 26%

The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allow…

Fix: after 3.2.3
Fix from $1,600 2014-01-23
Jboss Seam 2 Framework MEDIUM 5.0
CVE-2013-6448

The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote …

Fix: after 2.3.1
Fix from $1,600 2014-01-23
Nx Os MEDIUM 6.8
CVE-2014-0676

Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

Mitigation only
Fix from $1,600 2014-01-22
Asr 5000 Series Software MEDIUM 5.0
CVE-2014-0669

The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker…

Mitigation only
Fix from $1,600 2014-01-22
Ubuntu Linux MEDIUM 6.8
CVE-2013-0339

libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExt…

Fix: after 2.9.1
Fix from $1,600 2014-01-21
Python Keystoneclient MEDIUM 5.5
CVE-2013-2104

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen…

Fix: after 0.2.3
Fix from $1,600 2014-01-21
Plone MEDIUM 5.8
CVE-2013-4200

The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs star…

Patch available
Fix from $1,600 2014-01-21
WordPress MEDIUM 5.8
CVE-2010-5293

wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers…

Fix: after 3.0.1
Fix from $1,600 2014-01-21
WordPress MEDIUM 6.4
CVE-2012-6634

wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restr…

Fix: after 3.3.2
Fix from $1,600 2014-01-21
Moodle MEDIUM 5.5
CVE-2014-0009

course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the…

Fix: after 2.2.11
Fix from $1,600 2014-01-20
Secure Access Control System HIGH 10.0
CVE-2014-0648EPSS 6%

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System HIGH 9.0
CVE-2014-0649

The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot…

Fix: after 5.4.0.46.6
Fix from $1,950 2014-01-16
Secure Access Control System MEDIUM 6.3
CVE-2014-0667

The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated…

Mitigation only
Fix from $1,600 2014-01-16
Flash Player HIGH 10.0
CVE-2014-0492EPSS 6%

Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef…

Fix: 4.0.0.1390 / 11.2.202.335+
Fix from $1,950 2014-01-15
Flash Player HIGH 10.0
CVE-2014-0491EPSS 7%

Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef…

Fix: 4.0.0.1390 / 11.2.202.335+
Fix from $1,950 2014-01-15
Kingalarm\&event MEDIUM 6.4
CVE-2013-2826

WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console ra…

Fix: after 3.1
Fix from $1,600 2014-01-15
Junos HIGH 7.2
CVE-2014-0615

Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 befor…

Mitigation only
Fix from $1,950 2014-01-15