Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Smart Travel Router MEDIUM 5.8
CVE-2013-6918

The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP addre…

Mitigation only
Fix from $1,600 2013-11-30
Linux Kernel MEDIUM 6.9
CVE-2013-6383

The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which …

Fix: 3.2.53 / 3.4.69+
Fix from $1,600 2013-11-27
Exclusion MEDIUM 5.5
CVE-2013-6373

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and r…

Fix: after 0.8
Fix from $1,600 2013-11-25
Adaptive Server Enterprise HIGH 9.0
CVE-2013-6863

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows re…

Mitigation only
Fix from $1,950 2013-11-23
Enterprise Linux HIGH 7.2
CVE-2013-1813

util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows lo…

Fix: after 1.20.2
Fix from $1,950 2013-11-23
Xen HIGH 7.9
CVE-2013-6375

Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, whi…

Mitigation only
Fix from $1,950 2013-11-23
Mail Secure 5099sk HIGH 7.2
CVE-2013-6831

PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which al…

No fix yet
Fix from $1,950 2013-11-20
Netweaver MEDIUM 6.4
CVE-2013-6823

GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.

No fix yet
Fix from $1,600 2013-11-20
Debian Linux HIGH 7.6
CVE-2013-4559EPSS 11%

lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run a…

Fix: 1.4.33+
Fix from $1,950 2013-11-20
Netweaver Logviewer MEDIUM 6.4
CVE-2013-6818

SAP NetWeaver Logviewer 6.30, when running on Windows, allows remote attackers to bypass intended access restrictions via unspecified vectors.

No fix yet
Fix from $1,600 2013-11-20
Dsl 2740b Firmware HIGH 7.6
CVE-2013-2271

The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and …

No fix yet
Fix from $1,950 2013-11-19
Network Security Services MEDIUM 5.8
CVE-2013-5606

The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return va…

Mitigation only
Fix from $1,600 2013-11-18
Workstation HIGH 7.2
CVE-2013-5972

VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users t…

Patch available
Fix from $1,950 2013-11-18
Chrome MEDIUM 5.8
CVE-2013-6802

Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demo…

Fix: after 31.0.1650.57
Fix from $1,600 2013-11-18
Nexus 1000v MEDIUM 6.8
CVE-2013-5556

The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.…

Fix: after 4.2
Fix from $1,600 2013-11-18
Server Provisioner MEDIUM 5.0
CVE-2013-3407

The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allow…

Fix: after 6.4.0
Fix from $1,600 2013-11-18
Blackberry Link MEDIUM 5.8
CVE-2013-6798

BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer M…

Fix: after 1.2.0.28
Fix from $1,600 2013-11-18
Fedora MEDIUM 5.0
CVE-2013-2032

MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and S…

Fix: after 1.19.5
Fix from $1,600 2013-11-18
Unified Ip Phone Firmware MEDIUM 6.6
CVE-2013-6685

The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privile…

Mitigation only
Fix from $1,600 2013-11-13
iOS MEDIUM 6.4
CVE-2013-5552

Cisco IOS 12.4(24)MDB9 and earlier on Content Services Gateway (CSG) devices does not properly implement the "parse error drop" feature, which allows…

Fix: after 12.4
Fix from $1,600 2013-11-13
Coldfusion HIGH 7.8
CVE-2013-5328

Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.

Fix: after 10.0
Fix from $1,950 2013-11-13
Openssh MEDIUM 6.0
CVE-2013-4548

The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memo…

Mitigation only
Fix from $1,600 2013-11-08
Bind MEDIUM 6.8
CVE-2013-6230EPSS 6%

The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P…

Mitigation only
Fix from $1,600 2013-11-08
Mail Secure HIGH 8.5
CVE-2013-4987

PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters …

Fix: after 3.69
Fix from $1,950 2013-11-08
Wp Ultimate Email Marketer Plugin MEDIUM 6.4
CVE-2013-3264

The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaig…

Fix: after 1.1.0
Fix from $1,600 2013-11-05
Libguestfs MEDIUM 6.8
CVE-2013-4419

The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership o…

Fix: after 1.22.7
Fix from $1,600 2013-11-05
Havana MEDIUM 6.4
CVE-2013-4497

The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an…

Mitigation only
Fix from $1,600 2013-11-05
Xendesktop MEDIUM 5.8
CVE-2013-6077

Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass …

Mitigation only
Fix from $1,600 2013-11-05
Salt HIGH 10.0
CVE-2013-6617

The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to …

Mitigation only
Fix from $1,950 2013-11-05
Linux Kernel MEDIUM 6.9
CVE-2013-4470

The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows loc…

Fix: after 3.11.7
Fix from $1,600 2013-11-04