Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Moodle MEDIUM 6.4
CVE-2012-6102

lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0651

The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with…

Mitigation only
Fix from $1,600 2013-01-27
Intelligent Platforms Proficy Real Time Information Portal MEDIUM 5.0
CVE-2013-0652

GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote a…

Mitigation only
Fix from $1,600 2013-01-27
Wireless Lan Controller Software HIGH 9.0
CVE-2013-1105

Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote a…

Mitigation only
Fix from $1,950 2013-01-24
Codesys Runtime System CRITICAL 9.8
CVE-2012-6068EPSS 5%

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via …

Mitigation only
Fix from $2,300 2013-01-21
Avamar HIGH 7.2
CVE-2012-2291

EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions fo…

Mitigation only
Fix from $1,950 2013-01-21
Adaptive Security Appliance Software MEDIUM 6.3
CVE-2012-5717

Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authentica…

Mitigation only
Fix from $1,600 2013-01-18
Telepresence Video Communication Servers Software MEDIUM 5.0
CVE-2012-5444

Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create co…

Mitigation only
Fix from $1,600 2013-01-17
Chrome HIGH 7.5
CVE-2013-0838

Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors.

Fix: after 24.0.1312.51
Fix from $1,950 2013-01-15
Chrome MEDIUM 5.0
CVE-2012-5146

Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL.

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome MEDIUM 5.0
CVE-2012-5155

Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote …

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Chrome MEDIUM 6.4
CVE-2013-0829

Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrict…

Fix: after 24.0.1312.51
Fix from $1,600 2013-01-15
Rails MEDIUM 6.4
CVE-2013-0155EPSS 8%

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between …

Fix: 3.0.19 / 3.1.10+
Fix from $1,600 2013-01-13
Firefox MEDIUM 5.8
CVE-2013-0751

Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attack…

Fix: after 17.0.1
Fix from $1,600 2013-01-13
Acrobat HIGH 10.0
CVE-2013-0622EPSS 6%

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unsp…

Mitigation only
Fix from $1,950 2013-01-10
Acrobat HIGH 10.0
CVE-2013-0624

Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unsp…

Patch available
Fix from $1,950 2013-01-10
Jboss Enterprise Application Platform MEDIUM 6.5
CVE-2012-4549

A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter…

Fix: after 6.0.0
Fix from $1,600 2013-01-05
Jboss Enterprise Application Platform MEDIUM 5.3
CVE-2012-4550

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d…

Mitigation only
Fix from $1,600 2013-01-05
Cloudforms MEDIUM 5.5
CVE-2012-5603

proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to rea…

Fix: after 1.0
Fix from $1,600 2013-01-04
Drupal MEDIUM 5.0
CVE-2012-5651

Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information…

Patch available
Fix from $1,600 2013-01-03
Context MEDIUM 5.0
CVE-2012-5655

The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allow…

Patch available
Fix from $1,600 2013-01-03
Opera Browser MEDIUM 5.0
CVE-2012-6462

Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intend…

Fix: after 12.10
Fix from $1,600 2013-01-02
Lemonldap\ HIGH 7.5
CVE-2012-6426

LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended …

Fix: after 1.2.2
Fix from $1,950 2013-01-01
Symfony MEDIUM 6.4
CVE-2012-6431

Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers …

Mitigation only
Fix from $1,600 2012-12-27
Symfony MEDIUM 6.8
CVE-2012-6432

Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access ar…

Mitigation only
Fix from $1,600 2012-12-27
Rational Automation Framework HIGH 7.5
CVE-2012-4816

IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz…

Mitigation only
Fix from $1,950 2012-12-26
Tivoli Netview HIGH 7.2
CVE-2012-5951

Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t…

Mitigation only
Fix from $1,950 2012-12-26
phpMyAdmin HIGH 7.5
CVE-2012-5469EPSS 24%

The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a…

No fix yet
Fix from $1,950 2012-12-20
Symfony MEDIUM 5.0
CVE-2012-5574

lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.

Fix: after 1.4.19
Fix from $1,600 2012-12-18
Mx HIGH 9.3
CVE-2012-6422EPSS 15%

The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses wea…

No fix yet
Fix from $1,950 2012-12-18