Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Ruby MEDIUM 6.4
CVE-2013-2065

(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native function…

Patch available
Fix from $1,600 2013-11-02
Libvirt HIGH 8.5
CVE-2013-4401

The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi…

Patch available
Fix from $1,950 2013-11-02
Firefox HIGH 8.3
CVE-2013-5598

PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remo…

Fix: after 24.0
Fix from $1,950 2013-10-30
Nginx HIGH 7.5
CVE-2013-0337

The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, whic…

Fix: after 1.3.13
Fix from $1,950 2013-10-27
Mediawiki MEDIUM 5.0
CVE-2013-4302

(1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php…

Patch available
Fix from $1,600 2013-10-27
Flex System Manager MEDIUM 6.8
CVE-2013-5424

IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by…

Mitigation only
Fix from $1,600 2013-10-25
Kingview MEDIUM 5.8
CVE-2013-6128

The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveT…

Fix: after 6.52
Fix from $1,600 2013-10-25
Rsa Authentication Agent HIGH 7.5
CVE-2013-3280

EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to by…

Mitigation only
Fix from $1,950 2013-10-25
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5521

Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service …

Mitigation only
Fix from $1,600 2013-10-25
iOS MEDIUM 6.8
CVE-2013-5522

Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service M…

Mitigation only
Fix from $1,600 2013-10-25
Linux Kernel MEDIUM 6.0
CVE-2013-4299

Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive i…

Fix: after 3.11.6
Fix from $1,600 2013-10-24
Keynote HIGH 7.2
CVE-2013-5148

Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows …

Fix: after 5.3
Fix from $1,950 2013-10-24
Mac Os X MEDIUM 5.0
CVE-2013-5178

LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to …

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Mac Os X HIGH 7.5
CVE-2013-5179

App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices int…

Fix: after 10.8.5
Fix from $1,950 2013-10-24
Mac Os X MEDIUM 5.8
CVE-2013-5189

Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-depend…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Quest One Password Manager MEDIUM 5.0
CVE-2013-6246EPSS 6%

The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's ful…

No fix yet
Fix from $1,600 2013-10-24
Mac Os X MEDIUM 6.4
CVE-2013-5165

socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers…

Fix: after 10.8.5
Fix from $1,600 2013-10-24
Websphere Datapower Xc10 Appliance HIGH 7.1
CVE-2013-5428

IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2013-10-22
Vcenter Server MEDIUM 6.8
CVE-2013-5971

Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web se…

Fix: after 5.0
Fix from $1,600 2013-10-21
Vbulletin HIGH 7.5
CVE-2013-6129EPSS 52%

The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password…

No fix yet
Fix from $1,950 2013-10-19
Di 524up HIGH 10.0
CVE-2013-6026EPSS 8%

The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-…

Mitigation only
Fix from $1,950 2013-10-19
Unified Computing System MEDIUM 6.8
CVE-2012-4112

The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary command…

Mitigation only
Fix from $1,600 2013-10-19
Identity Services Engine Software MEDIUM 5.0
CVE-2013-5538

The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary …

Mitigation only
Fix from $1,600 2013-10-16
Zoneflex 2942 Firmware HIGH 7.2
CVE-2013-5030

Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain conf…

Mitigation only
Fix from $1,950 2013-10-16
Nx Os MEDIUM 6.8
CVE-2012-4121

Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, …

Mitigation only
Fix from $1,600 2013-10-14
Nx Os MEDIUM 6.8
CVE-2012-4077

Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651.

Mitigation only
Fix from $1,600 2013-10-14
Imc Service Operation Management Software Module HIGH 7.5
CVE-2013-4825

Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers t…

Mitigation only
Fix from $1,950 2013-10-13
Firewall Services Module Software MEDIUM 6.6
CVE-2013-5506

The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context…

Mitigation only
Fix from $1,600 2013-10-13
Adaptive Security Appliance Software HIGH 10.0
CVE-2013-5509

The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypas…

Mitigation only
Fix from $1,950 2013-10-13
Unified Computing System MEDIUM 6.8
CVE-2012-4106

The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows l…

Mitigation only
Fix from $1,600 2013-10-13