Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Elgg MEDIUM 6.8
CVE-2012-6562

engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbit…

Fix: after 1.8.4
Fix from $1,600 2013-05-23
Vipnet Client HIGH 7.2
CVE-2013-3496

Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNe…

Fix: after 4.1
Fix from $1,950 2013-05-22
Qemu MEDIUM 6.9
CVE-2013-2007

The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows lo…

Mitigation only
Fix from $1,600 2013-05-21
Xen MEDIUM 6.9
CVE-2013-1964

Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to …

Mitigation only
Fix from $1,600 2013-05-21
Vnx Control Station MEDIUM 6.8
CVE-2013-3270

EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, w…

Fix: after 7.1.70.1
Fix from $1,600 2013-05-20
Firefox MEDIUM 6.9
CVE-2013-1672

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x b…

Fix: after 20.0.1
Fix from $1,600 2013-05-16
Firefox MEDIUM 6.9
CVE-2013-1673

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situ…

Fix: after 20.0.1
Fix from $1,600 2013-05-16
Windows Essentials MEDIUM 6.8
CVE-2013-0096EPSS 16%

Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL p…

Mitigation only
Fix from $1,600 2013-05-15
Unified Customer Voice Portal HIGH 7.8
CVE-2013-1225

Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP…

Fix: after 9.0
Fix from $1,950 2013-05-09
Wonderware Information Server HIGH 9.3
CVE-2013-0685

Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which all…

Mitigation only
Fix from $1,950 2013-05-09
Groundwork Monitor MEDIUM 6.5
CVE-2013-3509

html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via…

Mitigation only
Fix from $1,600 2013-05-08
Groundwork Monitor HIGH 7.5
CVE-2013-3499

GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administ…

Mitigation only
Fix from $1,950 2013-05-08
Groundwork Monitor HIGH 7.5
CVE-2013-3500

The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/…

Mitigation only
Fix from $1,950 2013-05-08
Groundwork Monitor HIGH 7.5
CVE-2013-3506

cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which a…

Mitigation only
Fix from $1,950 2013-05-08
Linux Kernel MEDIUM 6.9
CVE-2013-1979

The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which …

Fix: after 3.8.10
Fix from $1,600 2013-05-03
Networker HIGH 7.2
CVE-2013-0940

The nsrpush process in the client in EMC NetWorker before 7.6.5.3 and 8.x before 8.0.1.4 sets weak permissions for unspecified files, which allows lo…

Fix: after 7.6.5.2
Fix from $1,950 2013-05-03
Production Planning And Control MEDIUM 6.5
CVE-2013-3062

The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated …

Mitigation only
Fix from $1,600 2013-05-01
Vcenter Server Appliance HIGH 9.0
CVE-2013-3080

VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently…

Mitigation only
Fix from $1,950 2013-05-01
Erp Central Component MEDIUM 6.5
CVE-2013-3061

The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the S…

Mitigation only
Fix from $1,600 2013-05-01
Lotus Notes MEDIUM 5.8
CVE-2013-0127

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote at…

Mitigation only
Fix from $1,600 2013-05-01
Ruby MEDIUM 5.0
CVE-2012-4464

Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untai…

Mitigation only
Fix from $1,600 2013-04-25
Ruby MEDIUM 5.0
CVE-2012-4466

Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level…

Mitigation only
Fix from $1,600 2013-04-25
Adaptive Security Appliance Software MEDIUM 6.8
CVE-2013-1215

The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via un…

Mitigation only
Fix from $1,600 2013-04-25
Unified Computing System Infrastructure And Unified Computing System Software HIGH 9.3
CVE-2013-1182

The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) all…

Fix: after 1.0
Fix from $1,950 2013-04-25
Markvision HIGH 9.3
CVE-2013-3055

Lexmark Markvision Enterprise before 1.8 provides a diagnostic interface on TCP port 9789, which allows remote attackers to execute arbitrary code, c…

Fix: after 1.5
Fix from $1,950 2013-04-25
Firewall Services Module MEDIUM 5.0
CVE-2013-1195

The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properl…

Mitigation only
Fix from $1,600 2013-04-24
Unified Contact Center Express Editor Software MEDIUM 5.0
CVE-2013-1214

The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows r…

Mitigation only
Fix from $1,600 2013-04-24
Elitepad HIGH 7.2
CVE-2012-5218

HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS…

Mitigation only
Fix from $1,950 2013-04-24
Micom S1 Studio MEDIUM 6.6
CVE-2013-0687

The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify …

Mitigation only
Fix from $1,600 2013-04-18
Chrome Os MEDIUM 5.0
CVE-2013-2834

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker…

Fix: after 26.0.1410.56
Fix from $1,600 2013-04-16