Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Openjpa HIGH 7.5
CVE-2013-1768EPSS 10%

The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace d…

Mitigation only
Fix from $1,950 2013-07-11
Micom S1 Agile MEDIUM 6.6
CVE-2013-2786

Alstom Grid MiCOM S1 Agile before 1.0.3 and Alstom Grid MiCOM S1 Studio use weak permissions for the MiCOM S1 %PROGRAMFILES% directory, which allows …

Fix: after 1.0.2
Fix from $1,600 2013-07-10
Virtualization Experience Client 6000 Series Firmware MEDIUM 6.8
CVE-2013-3408

The firmware on Cisco Virtualization Experience Client 6000 devices sets incorrect operating-system permissions, which allows local users to gain pri…

Mitigation only
Fix from $1,600 2013-07-10
Debian Linux MEDIUM 5.0
CVE-2013-2876

browser/extensions/api/tabs/tabs_api.cc in Google Chrome before 28.0.1500.71 does not properly enforce restrictions on the capture of screenshots by …

Fix: after 28.0.1500.70
Fix from $1,600 2013-07-10
Windows Defender MEDIUM 6.9
CVE-2013-3154

The signature-update functionality in Windows Defender on Microsoft Windows 7 and Windows Server 2008 R2 relies on an incorrect pathname, which allow…

Mitigation only
Fix from $1,600 2013-07-10
Aix HIGH 8.5
CVE-2013-3005

The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file…

Mitigation only
Fix from $1,950 2013-07-06
MongoDB MEDIUM 6.5
CVE-2013-4650

MongoDB 2.4.x before 2.4.5 and 2.5.x before 2.5.1 allows remote authenticated users to obtain internal system privileges by leveraging a username of …

Mitigation only
Fix from $1,600 2013-07-04
phpMyAdmin MEDIUM 5.5
CVE-2013-4729

import.php in phpMyAdmin 4.x before 4.0.4.1 does not properly restrict the ability of input data to specify a file format, which allows remote authen…

Patch available
Fix from $1,600 2013-07-04
Enterprise Virtualization Manager MEDIUM 5.0
CVE-2013-2144

Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attacker…

Fix: after 3.1
Fix from $1,600 2013-07-03
FreeBSD MEDIUM 6.9
CVE-2013-2171EPSS 7%

The vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not properly determ…

Mitigation only
Fix from $1,600 2013-07-02
Dasdec Eas HIGH 10.0
CVE-2013-4735

The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for …

Fix: after 2.0-1
Fix from $1,950 2013-06-30
Dasdec Eas HIGH 7.5
CVE-2013-4733

The web server on the Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 allows rem…

Fix: after 2.0-1
Fix from $1,950 2013-06-30
Nonstop Sql\/mx MEDIUM 6.0
CVE-2013-2323

HP SQL/MX 3.0 through 3.2 on NonStop servers, when SQL/MP Objects are used, allows remote authenticated users to bypass intended access restrictions …

Mitigation only
Fix from $1,600 2013-06-28
Firefox HIGH 9.3
CVE-2013-1687

The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunder…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox MEDIUM 5.0
CVE-2013-1695

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which a…

Fix: after 21.0
Fix from $1,600 2013-06-26
Firefox HIGH 9.3
CVE-2013-1697

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x be…

Fix: after 21.0
Fix from $1,950 2013-06-26
Firefox HIGH 7.2
CVE-2013-1700

The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable…

Fix: after 21.0
Fix from $1,950 2013-06-26
Fortios MEDIUM 6.5
CVE-2013-4604

Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, mo…

Fix: after 5.0.2
Fix from $1,600 2013-06-25
Mg3100 Printer HIGH 7.5
CVE-2013-4613

The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers …

Mitigation only
Fix from $1,950 2013-06-21
Lotus Inotes HIGH 7.2
CVE-2013-0536

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows …

Mitigation only
Fix from $1,950 2013-06-21
Sterling Connect Direct User Interface MEDIUM 5.0
CVE-2013-0529

The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an http…

Mitigation only
Fix from $1,600 2013-06-21
Telepresence Tc Software HIGH 8.3
CVE-2013-3379

The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote…

Fix: after 4.1.2
Fix from $1,950 2013-06-21
Seco Versatile Security Manager HIGH 9.0
CVE-2013-4633

Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a …

Mitigation only
Fix from $1,950 2013-06-20
Redcap MEDIUM 6.5
CVE-2013-4609

REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote a…

Fix: after 5.0.3
Fix from $1,600 2013-06-17
Silver Mobile MEDIUM 6.5
CVE-2013-3315

The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a command, which allows authentica…

Mitigation only
Fix from $1,600 2013-05-31
Android HIGH 7.2
CVE-2013-3666

The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB…

Mitigation only
Fix from $1,950 2013-05-29
Livecd Tools HIGH 7.2
CVE-2013-2069

Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart fil…

Fix: 13.4.4 / 17.17+
Fix from $1,950 2013-05-29
Sterling Connect MEDIUM 6.8
CVE-2013-2989

The file-copying functionality in IBM Sterling Connect:Direct 3.8.00, 4.0.00, and 4.1.0 for UNIX on AIX 6.1 through 7.1 uses incorrect privileges, wh…

Mitigation only
Fix from $1,600 2013-05-28
Moodle MEDIUM 5.0
CVE-2013-2082

Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comm…

Patch available
Fix from $1,600 2013-05-25
Scalance X200irt Firmware HIGH 8.0
CVE-2013-3633

A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) (Versions < V5.0.0 for CVE-2013-3633 and versions < V…

Fix: after 5.0.0
Fix from $1,950 2013-05-24