Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Wp Mailup MEDIUM 5.0
CVE-2013-0731

ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remo…

Fix: after 1.3.2
Fix from $1,600 2013-03-22
Acselerator Quickset MEDIUM 6.2
CVE-2013-0665

Schweitzer Engineering Laboratories (SEL) AcSELerator QuickSet before 5.12.0.1 uses weak permissions for its Program Files directory, which allows lo…

Fix: after 5.12.0
Fix from $1,600 2013-03-21
Infosphere Information Server HIGH 7.2
CVE-2012-5938

The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for …

No fix yet
Fix from $1,950 2013-03-20
Samba MEDIUM 6.0
CVE-2013-1863

Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which a…

Patch available
Fix from $1,600 2013-03-19
Keyboard Shortcut Utility MEDIUM 6.0
CVE-2013-0226

The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticat…

Mitigation only
Fix from $1,600 2013-03-19
Access Gateway MEDIUM 5.0
CVE-2013-2263

Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via…

No fix yet
Fix from $1,600 2013-03-19
Spotfire Web Player MEDIUM 6.4
CVE-2013-2373

The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implemen…

Mitigation only
Fix from $1,600 2013-03-15
Sharepoint Foundation HIGH 7.5
CVE-2013-0080EPSS 19%

Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and …

Mitigation only
Fix from $1,950 2013-03-13
Jboss Enterprise Application Platform HIGH 7.5
CVE-2012-5629

The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.…

Mitigation only
Fix from $1,950 2013-03-12
Automatic Bug Reporting Tool MEDIUM 6.9
CVE-2012-5660

abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit…

Fix: after 2.0.9
Fix from $1,600 2013-03-12
Aeolus Conductor MEDIUM 5.5
CVE-2012-6118

The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan…

No fix yet
Fix from $1,600 2013-03-12
Gnome Screensaver HIGH 7.2
CVE-2013-1050

The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prev…

Mitigation only
Fix from $1,950 2013-03-08
Essex HIGH 8.8
CVE-2013-0261

A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This …

Mitigation only
Fix from $1,950 2013-03-08
Sudo MEDIUM 6.9
CVE-2013-1775

sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions …

Fix: after 10.10.4
Fix from $1,600 2013-03-05
Gdb MEDIUM 6.9
CVE-2011-4355

GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, whic…

Fix: after 7.4.1
Fix from $1,600 2013-03-05
Universal Raid Utility HIGH 9.0
CVE-2013-0706

NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which a…

Fix: after 2.31
Fix from $1,950 2013-02-22
Maximo Asset Management MEDIUM 6.5
CVE-2012-6355

IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6356

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Maximo Asset Management MEDIUM 6.5
CVE-2012-6357

IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri…

Mitigation only
Fix from $1,600 2013-02-20
Smartcloud Control Desk MEDIUM 6.5
CVE-2012-3321

IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

Mitigation only
Fix from $1,600 2013-02-20
Linux Kernel MEDIUM 6.2
CVE-2013-0268

The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by exec…

Fix: after 3.7.5
Fix from $1,600 2013-02-18
Ata 187 Analog Telephone Adaptor Firmware HIGH 9.0
CVE-2013-1111

The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allo…

Mitigation only
Fix from $1,950 2013-02-13
Ubuntu Linux MEDIUM 6.5
CVE-2013-0208

The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from ot…

Patch available
Fix from $1,600 2013-02-13
.net Framework HIGH 10.0
CVE-2013-0073EPSS 30%

The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a…

Mitigation only
Fix from $1,950 2013-02-13
Rsa Archer Smartsuite HIGH 7.5
CVE-2012-2292

The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the A…

Mitigation only
Fix from $1,950 2013-02-06
Jboss Enterprise Application Platform MEDIUM 5.8
CVE-2012-3370

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf…

Fix: after 5.3.0
Fix from $1,600 2013-02-05
Infosphere Information Server MEDIUM 6.5
CVE-2012-0205

InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use …

Mitigation only
Fix from $1,600 2013-01-31
Infosphere Datastage MEDIUM 6.5
CVE-2012-0701

The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8…

Mitigation only
Fix from $1,600 2013-01-31
Moodle MEDIUM 5.5
CVE-2012-6106

calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot…

Mitigation only
Fix from $1,600 2013-01-27
Moodle MEDIUM 5.0
CVE-2012-6112

classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.…

Patch available
Fix from $1,600 2013-01-27