Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Workstation MEDIUM 6.9
CVE-2013-1662

vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host…

Mitigation only
Fix from $1,600 2013-08-24
Rt MEDIUM 6.8
CVE-2013-3370

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remot…

Patch available
Fix from $1,600 2013-08-23
Websphere Portal MEDIUM 5.0
CVE-2013-3016

IBM WebSphere Portal 6.1, 7.0, and 8.0 allows remote attackers to access the user directory via a crafted request for a servlet, related to the serve…

Mitigation only
Fix from $1,600 2013-08-21
Monster Menus MEDIUM 6.0
CVE-2013-4230

The mm_webform submodule in the Monster Menus module 6.x-6.x before 6.x-6.61 and 7.x-1.x before 7.x-1.13 for Drupal does not properly restrict access…

Patch available
Fix from $1,600 2013-08-21
Debian Linux MEDIUM 5.0
CVE-2013-2905

The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which …

Fix: after 29.0.1547.56
Fix from $1,600 2013-08-21
Puppet Enterprise MEDIUM 5.0
CVE-2013-4964

Puppet Enterprise before 3.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to…

Fix: after 3.0.0
Fix from $1,600 2013-08-20
Citectscada MEDIUM 6.9
CVE-2013-2796

Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read …

Fix: after 7.20
Fix from $1,600 2013-08-09
Comos HIGH 7.2
CVE-2013-4943

The client application in Siemens COMOS before 9.1 Update 458, 9.2 before 9.2.0.6.37, and 10.0 before 10.0.3.0.19 allows local users to gain privileg…

Mitigation only
Fix from $1,950 2013-08-09
Firefox MEDIUM 5.4
CVE-2013-1717

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20…

Fix: after 22.0
Fix from $1,600 2013-08-07
Unified Computing System MEDIUM 5.0
CVE-2013-1190

The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remot…

Mitigation only
Fix from $1,600 2013-08-02
Bitcoin Core MEDIUM 5.0
CVE-2013-3219

bitcoind and Bitcoin-Qt 0.8.x before 0.8.1 do not enforce a certain block protocol rule, which allows remote attackers to bypass intended access rest…

Mitigation only
Fix from $1,600 2013-08-02
Web Gateway HIGH 7.2
CVE-2013-4672

The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 has an incorrect sudoers file, which allows local users to bypass int…

Fix: after 5.1
Fix from $1,950 2013-08-01
Client HIGH 7.2
CVE-2013-3956EPSS 8%

The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows…

No fix yet
Fix from $1,950 2013-07-31
Openstack MEDIUM 6.0
CVE-2013-2113EPSS 21%

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or …

Fix: after 1.2.0
Fix from $1,600 2013-07-31
Chrome MEDIUM 5.8
CVE-2013-2881

Google Chrome before 28.0.1500.95 does not properly handle frames, which allows remote attackers to bypass the Same Origin Policy via a crafted web s…

Fix: after 28.0.1500.94
Fix from $1,600 2013-07-31
FreeBSD MEDIUM 6.4
CVE-2013-4851

The vfs_hang_addrlist function in sys/kern/vfs_export.c in the NFS server implementation in the kernel in FreeBSD 8.3 and 9.x through 9.1-RELEASE-p5 …

Mitigation only
Fix from $1,600 2013-07-29
Identity Services Engine MEDIUM 5.0
CVE-2013-3445

The firewall subsystem in Cisco Identity Services Engine has an incorrect rule for open ports, which allows remote attackers to cause a denial of ser…

Mitigation only
Fix from $1,600 2013-07-29
Unified Meetingplace Web Conferencing MEDIUM 5.0
CVE-2013-3438

The web framework in the server in Cisco Unified MeetingPlace Web Conferencing allows remote attackers to bypass intended access restrictions and rea…

No fix yet
Fix from $1,600 2013-07-24
Jboss Enterprise Application Platform HIGH 7.5
CVE-2013-2165EPSS 13%

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform …

Fix: after 2.2.0
Fix from $1,950 2013-07-23
System Management Homepage MEDIUM 5.0
CVE-2013-2355

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via …

Fix: after 7.2
Fix from $1,600 2013-07-22
System Management Homepage MEDIUM 5.0
CVE-2012-5217

HP System Management Homepage (SMH) before 7.2.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via …

Fix: after 7.2
Fix from $1,600 2013-07-22
Avamar Server HIGH 9.0
CVE-2013-3274

EMC Avamar Server and Avamar Virtual Edition before 7.0 on Data Store Gen3, Gen4, and Gen4s platforms do not properly determine authorization for cal…

Fix: after 6.1
Fix from $1,950 2013-07-19
iOS MEDIUM 5.0
CVE-2013-3436

The default configuration of the Group Encrypted Transport VPN (GET VPN) feature on Cisco IOS uses an improper mechanism for enabling Group Domain of…

Mitigation only
Fix from $1,600 2013-07-19
Parallels Plesk Panel HIGH 7.5
CVE-2013-4878EPSS 31%

The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias direct…

Mitigation only
Fix from $1,950 2013-07-18
Glass MEDIUM 6.9
CVE-2013-4872

Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuratio…

Mitigation only
Fix from $1,600 2013-07-18
Unified Ip Phones 9900 Series Firmware MEDIUM 5.0
CVE-2013-3426

The Serviceability servlet on Cisco 9900 IP phones does not properly restrict paths, which allows remote attackers to read arbitrary files by specify…

Mitigation only
Fix from $1,600 2013-07-18
Commons MEDIUM 5.0
CVE-2013-1907

The Commons Group module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which …

Fix: after 7.x-3.0
Fix from $1,600 2013-07-16
Commons MEDIUM 5.0
CVE-2013-1908

The Commons Wikis module before 7.x-3.1 for Drupal, as used in the Commons module before 7.x-3.1, does not properly restrict access to groups, which …

Fix: after 7.x-3.0
Fix from $1,600 2013-07-16
Edit Limit MEDIUM 5.0
CVE-2013-2122

The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with t…

Mitigation only
Fix from $1,600 2013-07-16
Blackberry Os MEDIUM 6.2
CVE-2013-3692

BlackBerry 10 OS before 10.0.10.648 on BlackBerry Z10 smartphones uses weak permissions for a BlackBerry Protect object, which allows physically prox…

Fix: after 10.0.10.261
Fix from $1,600 2013-07-13