Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome Os MEDIUM 5.0
CVE-2013-2835

Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker…

Fix: after 26.0.1410.56
Fix from $1,600 2013-04-16
Sleipnir Mobile MEDIUM 5.8
CVE-2013-2304

The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers …

Fix: after 2.8.0
Fix from $1,600 2013-04-16
Trendlink HIGH 8.5
CVE-2012-3022

The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict th…

Fix: after 9.0.2.27051
Fix from $1,950 2013-04-16
Jboss Enterprise Portal Platform MEDIUM 5.0
CVE-2013-0315

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern…

Mitigation only
Fix from $1,600 2013-04-12
Cognos Disclosure Management HIGH 9.3
CVE-2013-0501

The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)…

Mitigation only
Fix from $1,950 2013-04-12
Unified Meetingplace Web Conferencing Server HIGH 9.3
CVE-2013-1169

Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Reme…

Mitigation only
Fix from $1,950 2013-04-11
Crack HIGH 7.5
CVE-2013-1800

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-inje…

Fix: after 0.3.1
Fix from $1,950 2013-04-09
Httparty HIGH 7.5
CVE-2013-1801

The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-i…

Fix: after 0.9.0
Fix from $1,950 2013-04-09
Extlib HIGH 7.5
CVE-2013-1802

The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-in…

Fix: after 0.9.15
Fix from $1,950 2013-04-09
Linux Kernel HIGH 7.2
CVE-2013-1858

The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags,…

Fix: after 3.8.2
Fix from $1,950 2013-04-05
PostgreSQL HIGH 10.0
CVE-2013-1903

PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t…

Mitigation only
Fix from $1,950 2013-04-04
Firefox HIGH 10.0
CVE-2013-0795

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird E…

Fix: after 19.0.2
Fix from $1,950 2013-04-03
Mcafee Virtual Technician HIGH 8.2
CVE-2012-5879EPSS 5%

An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cr…

Fix: after 6.5.0.2101
Fix from $1,950 2013-03-28
Chrome MEDIUM 6.8
CVE-2013-0918

Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome MEDIUM 6.8
CVE-2013-0921

The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for re…

Fix: after 26.0.1410.42
Fix from $1,600 2013-03-28
Chrome HIGH 7.5
CVE-2013-0922

Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, wh…

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Chrome HIGH 7.5
CVE-2013-0924

The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions,…

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Chrome HIGH 7.5
CVE-2013-0925

Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this …

Fix: after 26.0.1410.42
Fix from $1,950 2013-03-28
Node Parameter Control MEDIUM 6.4
CVE-2013-1859

The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to…

No fix yet
Fix from $1,600 2013-03-27
Payment MEDIUM 5.0
CVE-2013-0182

The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary p…

Patch available
Fix from $1,600 2013-03-27
Email2image MEDIUM 5.0
CVE-2013-0257

The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of use…

Patch available
Fix from $1,600 2013-03-27
Banckle Chat HIGH 10.0
CVE-2013-0318

The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions…

Mitigation only
Fix from $1,950 2013-03-27
Simeji MEDIUM 5.0
CVE-2013-0718

The Simeji application 4.8.1 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive informat…

Fix: after 4.8.1
Fix from $1,600 2013-03-27
Artime Japanese Input MEDIUM 5.0
CVE-2013-0719

The ArtIME Japanese Input application 1.1.2 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sen…

Fix: after 1.1.2
Fix from $1,600 2013-03-27
Cobime MEDIUM 5.0
CVE-2013-0720

The COBIME application before 0.9.4 for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information v…

Fix: after 0.9.3
Fix from $1,600 2013-03-27
Flickwnn MEDIUM 5.0
CVE-2013-2300

The FlickWnn (aka OpenWnn/Flick support) application 2.02 and earlier for Android uses weak permissions for unspecified files, which allows attackers…

Fix: after 2.02
Fix from $1,600 2013-03-27
Moodle MEDIUM 6.5
CVE-2013-1836

Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories…

Mitigation only
Fix from $1,600 2013-03-25
Fedora MEDIUM 5.0
CVE-2013-1830

user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles set…

Patch available
Fix from $1,600 2013-03-25
Ubuntu Linux HIGH 7.6
CVE-2013-0335

OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu…

Mitigation only
Fix from $1,950 2013-03-22
Wp Mailup MEDIUM 5.0
CVE-2013-2640

ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remo…

Fix: after 1.3.1
Fix from $1,600 2013-03-22