Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Keystone MEDIUM 5.0
CVE-2013-4294

The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the …

Patch available
Fix from $1,600 2013-09-23
Mediasense MEDIUM 5.0
CVE-2013-5502

The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sens…

Mitigation only
Fix from $1,600 2013-09-23
FreeBSD MEDIUM 6.9
CVE-2013-5691

The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFD…

Patch available
Fix from $1,600 2013-09-23
Linux Imaging And Printing Project MEDIUM 6.9
CVE-2013-4325

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communicatio…

Mitigation only
Fix from $1,600 2013-09-23
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2013-1130

Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a …

Mitigation only
Fix from $1,600 2013-09-20
Dwl 2100ap MEDIUM 6.3
CVE-2013-4706

The SSH implementation on the D-Link Japan DWL-2100AP with firmware before R252JP-RC572 allows remote authenticated users to cause a denial of servic…

Fix: after 2.50
Fix from $1,600 2013-09-20
Des 3810 Firmware MEDIUM 6.3
CVE-2013-4707

The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service…

Mitigation only
Fix from $1,600 2013-09-20
Iphone Os MEDIUM 5.0
CVE-2013-5157

The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post T…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Iphone Os MEDIUM 6.3
CVE-2013-5145

kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) u…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Iphone Os MEDIUM 5.8
CVE-2013-0957

Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Era…

Fix: after 6.1.4
Fix from $1,600 2013-09-19
Firefox MEDIUM 6.2
CVE-2013-1726

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Firefox MEDIUM 5.0
CVE-2013-1737

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d…

Fix: after 23.0.1
Fix from $1,600 2013-09-18
Dvr0404hd A HIGH 10.0
CVE-2013-5754

The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which…

Mitigation only
Fix from $1,950 2013-09-17
Dvr0404hd A HIGH 9.3
CVE-2013-3614EPSS 7%

Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-forc…

No fix yet
Fix from $1,950 2013-09-17
Eucalyptus MEDIUM 5.5
CVE-2013-2296

Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus…

Fix: after 3.2.1
Fix from $1,600 2013-09-17
Nova MEDIUM 6.0
CVE-2013-2256

OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r…

Fix: 2013.1.3+
Fix from $1,600 2013-09-16
Openstack HIGH 7.5
CVE-2013-4182

app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces…

Fix: after 1.2.1
Fix from $1,950 2013-09-16
Mac Os X MEDIUM 6.8
CVE-2013-1027

Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which mig…

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Mac Os X MEDIUM 5.5
CVE-2013-1033

Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging…

Fix: after 10.8.4
Fix from $1,600 2013-09-16
Socialminer MEDIUM 5.0
CVE-2013-5489

The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensit…

Mitigation only
Fix from $1,600 2013-09-13
Xen MEDIUM 6.5
CVE-2013-4329

The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device bef…

Patch available
Fix from $1,600 2013-09-12
Cloudportal Services Manager HIGH 10.0
CVE-2013-2934

Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspeci…

Fix: after 10.0
Fix from $1,950 2013-09-12
Office MEDIUM 6.9
CVE-2013-3859

Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows lo…

Mitigation only
Fix from $1,600 2013-09-11
Web Appliance HIGH 7.2
CVE-2013-4984EPSS 8%

The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain…

Fix: after 3.7.9
Fix from $1,950 2013-09-10
Coursemill Learning Management System MEDIUM 6.0
CVE-2013-3601

Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arb…

Mitigation only
Fix from $1,600 2013-09-06
Rsa Archer Egrc MEDIUM 6.0
CVE-2013-3276

EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deact…

Mitigation only
Fix from $1,600 2013-09-05
Nodeaccess Userreference Module MEDIUM 5.8
CVE-2013-2123

The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content cont…

Patch available
Fix from $1,600 2013-08-28
Fast Permission Administration HIGH 7.5
CVE-2013-2247

The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the moda…

Patch available
Fix from $1,950 2013-08-28
Xen MEDIUM 5.2
CVE-2013-2077

Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unha…

Mitigation only
Fix from $1,600 2013-08-28
Xen HIGH 7.4
CVE-2013-2211

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated ser…

Mitigation only
Fix from $1,950 2013-08-28