Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Wonderware Information Server HIGH 7.5
CVE-2012-0228

Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended …

Mitigation only
Fix from $1,950 2012-04-02
Esxi HIGH 8.3
CVE-2012-1515

VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain gues…

Mitigation only
Fix from $1,950 2012-04-02
Db2 HIGH 10.0
CVE-2012-1797

IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.

Mitigation only
Fix from $1,950 2012-03-20
Dotclear HIGH 7.5
CVE-2011-5083

Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo…

No fix yet
Fix from $1,950 2012-03-19
Twicca MEDIUM 5.0
CVE-2012-0326

The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to re…

Patch available
Fix from $1,600 2012-03-17
Esx HIGH 7.2
CVE-2012-1508

The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS…

Fix: after 4.6.0
Fix from $1,950 2012-03-16
Pidgin MEDIUM 6.4
CVE-2011-4939

The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer der…

Fix: after 2.10.1
Fix from $1,600 2012-03-15
Documentum Eroom HIGH 7.5
CVE-2012-0398

EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecif…

Fix: after 7.4.3
Fix from $1,950 2012-03-15
Firefox MEDIUM 6.8
CVE-2012-0458

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 1…

Fix: after 10.0
Fix from $1,600 2012-03-14
Firefox HIGH 7.5
CVE-2012-0459

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Th…

Fix: after 2.7
Fix from $1,950 2012-03-14
Firefox MEDIUM 6.4
CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey bef…

Fix: after 2.7
Fix from $1,600 2012-03-14
Iphone Os HIGH 9.3
CVE-2012-0643

The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and exec…

Fix: 5.1+
Fix from $1,950 2012-03-08
Iphone Os MEDIUM 5.0
CVE-2012-0585

The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries…

Fix: 5.1+
Fix from $1,600 2012-03-08
Unity Connection HIGH 9.0
CVE-2012-0366

Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Adminis…

Fix: after 7.1
Fix from $1,950 2012-03-01
Wireless Lan Controller Software HIGH 9.3
CVE-2012-0371

Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote atta…

Mitigation only
Fix from $1,950 2012-03-01
Small Business Srp520 Series Firmware HIGH 7.8
CVE-2012-0364

Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to r…

Fix: after 1.01.24
Fix from $1,950 2012-02-25
Advantech Webaccess HIGH 10.0
CVE-2011-4525

Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client syst…

Fix: after 6.0
Fix from $1,950 2012-02-21
Lenovo Thinkmanagement Console HIGH 7.5
CVE-2012-1195EPSS 68%

Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkM…

Mitigation only
Fix from $1,950 2012-02-18
Sysutils MEDIUM 5.0
CVE-2012-1078

The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors…

Fix: after 1.0.3
Fix from $1,600 2012-02-14
Forward MEDIUM 5.0
CVE-2012-1056

The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) M…

Patch available
Fix from $1,600 2012-02-14
Dream Report HIGH 9.3
CVE-2011-4039

Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assi…

Fix: after 3.43
Fix from $1,950 2012-02-10
M Business Anywhere MEDIUM 6.5
CVE-2011-5078

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentic…

Mitigation only
Fix from $1,600 2012-02-08
Allwebmenus Plugin HIGH 7.5
CVE-2012-1011EPSS 9%

actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitr…

Patch available
Fix from $1,950 2012-02-07
Wincc Flexible HIGH 10.0
CVE-2011-4509

The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panel…

Mitigation only
Fix from $1,950 2012-02-03
Mac Os X MEDIUM 6.8
CVE-2011-3458

QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitra…

Fix: after 10.7.2
Fix from $1,600 2012-02-02
Firefox MEDIUM 5.0
CVE-2012-0445

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation po…

Fix: after 2.7
Fix from $1,600 2012-02-01
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4608

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo…

Mitigation only
Fix from $1,950 2012-01-27
Linux Kernel MEDIUM 6.9
CVE-2012-0056EPSS 11%

The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, …

Fix: 3.0.18 / 3.2.2+
Fix from $1,600 2012-01-27
Pcanywhere MEDIUM 6.8
CVE-2011-3479

Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable per…

Mitigation only
Fix from $1,600 2012-01-25
Voxofon MEDIUM 5.8
CVE-2011-4704

The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS in…

Fix: after 2.4.3
Fix from $1,600 2012-01-25