Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Amberdms Billing System MEDIUM 6.4
CVE-2010-5291

Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier …

Fix: after 1.4.0
Fix from $1,600 2014-01-10
Integraxor MEDIUM 5.0
CVE-2014-0752

The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL.

Fix: after 4.1.4360
Fix from $1,600 2014-01-09
Diskstation Manager HIGH 10.0
CVE-2013-6955EPSS 85%

webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remo…

Mitigation only
Fix from $1,950 2014-01-09
Monitor HIGH 10.0
CVE-2012-0264

op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via un…

Fix: after 5.4.2
Fix from $1,950 2013-12-31
Realvnc HIGH 7.2
CVE-2013-6886

RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) vncserver, (2) vncserver-x11, …

Mitigation only
Fix from $1,950 2013-12-28
Xen MEDIUM 5.2
CVE-2013-4554

Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which …

Mitigation only
Fix from $1,600 2013-12-24
Owncloud MEDIUM 6.8
CVE-2013-6403

The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.

Fix: after 5.0.12
Fix from $1,600 2013-12-24
Suse Lifecycle Management Server HIGH 7.2
CVE-2013-3709

WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret to…

No fix yet
Fix from $1,950 2013-12-23
Enterprise Mrg MEDIUM 6.5
CVE-2013-4404

cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri…

Mitigation only
Fix from $1,600 2013-12-23
Websphere Portal MEDIUM 5.0
CVE-2013-6723

IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, whic…

Patch available
Fix from $1,600 2013-12-22
Websphere Portal MEDIUM 5.0
CVE-2013-6735

IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.…

Patch available
Fix from $1,600 2013-12-22
Og Features MEDIUM 5.8
CVE-2013-7067

The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows rem…

Patch available
Fix from $1,600 2013-12-19
Safari MEDIUM 6.4
CVE-2013-5227

Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofi…

Fix: after 6.1
Fix from $1,600 2013-12-18
Webex Training Center MEDIUM 5.0
CVE-2013-6965

The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem…

Mitigation only
Fix from $1,600 2013-12-14
Android HIGH 8.8
CVE-2013-6271EPSS 8%

Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up…

No fix yet
Fix from $1,950 2013-12-14
Xen MEDIUM 6.8
CVE-2013-6400

Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspeci…

Mitigation only
Fix from $1,600 2013-12-13
Comos MEDIUM 6.9
CVE-2013-6840

Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified ve…

No fix yet
Fix from $1,600 2013-12-10
Cloud Portal MEDIUM 5.0
CVE-2013-6708

Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889.

Mitigation only
Fix from $1,600 2013-12-10
Rsa Netwitness Nextgen MEDIUM 6.8
CVE-2013-6180

EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI…

Mitigation only
Fix from $1,600 2013-12-09
Libvirt HIGH 7.2
CVE-2013-4400

virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm…

Patch available
Fix from $1,950 2013-12-09
Adequate MEDIUM 6.2
CVE-2013-6409

Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOC…

Fix: after 0.8
Fix from $1,600 2013-12-07
Debian Linux HIGH 7.5
CVE-2013-6410

nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces…

Fix: after 3.4
Fix from $1,950 2013-12-07
Rails MEDIUM 6.4
CVE-2013-6417

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in paramete…

Fix: after 3.2.15
Fix from $1,600 2013-12-07
Opensuse HIGH 7.2
CVE-2013-1090

The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, …

Mitigation only
Fix from $1,950 2013-12-06
Jboss Enterprise Application Platform MEDIUM 5.5
CVE-2013-2133

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly …

Fix: after 6.1.0
Fix from $1,600 2013-12-06
Garoon MEDIUM 6.8
CVE-2013-6004

Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 3.7
Fix from $1,600 2013-12-05
Vista HIGH 7.5
CVE-2013-6945

The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doct…

Patch available
Fix from $1,950 2013-12-04
Esxi HIGH 7.9
CVE-2013-3519

lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and…

Mitigation only
Fix from $1,950 2013-12-04
Opensuse HIGH 7.2
CVE-2012-0427

yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain pri…

No fix yet
Fix from $1,950 2013-12-02
Suse Cloud HIGH 10.0
CVE-2012-0434

The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2013-12-02