Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Torque Resource Manager HIGH 9.0
CVE-2013-4319

pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access b…

Fix: after 4.0.2
Fix from $1,950 2013-10-11
Blackberry Enterprise Service HIGH 7.9
CVE-2013-3693

The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Rem…

Mitigation only
Fix from $1,950 2013-10-11
Tl Sc3130 HIGH 7.8
CVE-2013-2581

cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-11
Airlive Wl2600cam HIGH 10.0
CVE-2013-3686EPSS 28%

cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list …

Mitigation only
Fix from $1,950 2013-10-11
Infosphere Optim Data Growth For Oracle E Business Suite MEDIUM 5.2
CVE-2013-0577

The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass inte…

Mitigation only
Fix from $1,600 2013-10-10
Gallery MEDIUM 5.0
CVE-2013-2241

modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive i…

Fix: after 3.0.8
Fix from $1,600 2013-10-10
Enterprise Linux HIGH 7.6
CVE-2013-4342EPSS 6%

xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e…

Patch available
Fix from $1,950 2013-10-10
Xen MEDIUM 5.4
CVE-2013-4356

Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows l…

Mitigation only
Fix from $1,600 2013-10-09
Make Meeting Scheduler Module MEDIUM 6.4
CVE-2013-4379

The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a d…

Patch available
Fix from $1,600 2013-10-09
Office Web Apps MEDIUM 6.8
CVE-2013-3895EPSS 30%

Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parame…

Mitigation only
Fix from $1,600 2013-10-09
Nx Os MEDIUM 6.2
CVE-2012-4141

Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the…

Mitigation only
Fix from $1,600 2013-10-05
Media Control Activex Control HIGH 8.8
CVE-2013-3543

The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwr…

No fix yet
Fix from $1,950 2013-10-04
100ap Device Firmware HIGH 7.8
CVE-2013-3689

Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not …

Fix: after 3.0.6.16c1
Fix from $1,950 2013-10-04
Server Center HIGH 7.2
CVE-2013-5701

Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) …

Fix: after 11.7.4
Fix from $1,950 2013-10-03
Ose HIGH 10.0
CVE-2013-0692

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and RO…

Fix: after 3.50
Fix from $1,950 2013-10-03
Unified Computing System MEDIUM 6.8
CVE-2012-4136

The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service…

Mitigation only
Fix from $1,600 2013-10-03
Infosphere Information Server MEDIUM 5.8
CVE-2013-4067

IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or condu…

Mitigation only
Fix from $1,600 2013-10-02
Tl Sc3130 HIGH 7.1
CVE-2013-3688

The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not prop…

Fix: after 1.6.18p12_sign5
Fix from $1,950 2013-10-01
Clearpass MEDIUM 5.0
CVE-2013-2269

The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows …

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.5
CVE-2013-4027

IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended acce…

Mitigation only
Fix from $1,600 2013-10-01
Maximo Asset Management MEDIUM 6.8
CVE-2012-3323

IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified …

No fix yet
Fix from $1,600 2013-10-01
Byword MEDIUM 5.0
CVE-2013-5725

The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite ar…

No fix yet
Fix from $1,600 2013-10-01
Davfs2 HIGH 7.2
CVE-2013-4362

WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) …

Patch available
Fix from $1,950 2013-09-30
Libvirt MEDIUM 6.9
CVE-2013-4291

The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly …

Patch available
Fix from $1,600 2013-09-30
Struts MEDIUM 5.8
CVE-2013-4310EPSS 8%

Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix.

Patch available
Fix from $1,600 2013-09-30
Node View Permissions MEDIUM 5.0
CVE-2013-5965

The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remot…

Fix: after 7.x-1.1
Fix from $1,600 2013-09-30
Unified Computing System MEDIUM 6.5
CVE-2012-1313

The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macs…

Mitigation only
Fix from $1,600 2013-09-27
Linux Kernel HIGH 7.2
CVE-2013-4300

The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows lo…

Fix: 3.9+
Fix from $1,950 2013-09-25
Android MEDIUM 6.9
CVE-2013-4777

A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that…

No fix yet
Fix from $1,600 2013-09-25
Rational Clearcase MEDIUM 6.9
CVE-2013-5373

The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script,…

Mitigation only
Fix from $1,600 2013-09-25