Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Nx Os MEDIUM 6.8
CVE-2011-2569

Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, wh…

Mitigation only
Fix from $1,600 2011-10-27
Puppet MEDIUM 6.2
CVE-2011-3871

Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to ru…

Patch available
Fix from $1,600 2011-10-27
Office MEDIUM 5.5
CVE-2011-2677

Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and a…

Fix: after 7
Fix from $1,600 2011-10-21
Blackberry Enterprise Server MEDIUM 6.5
CVE-2011-0290

The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotu…

No fix yet
Fix from $1,600 2011-10-21
Show And Share HIGH 7.5
CVE-2011-2584

Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Co…

Fix: after 5.2
Fix from $1,950 2011-10-20
Mac Os X MEDIUM 6.5
CVE-2011-3436

Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allo…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 5.0
CVE-2011-3225

The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-…

Mitigation only
Fix from $1,600 2011-10-14
Mac Os X MEDIUM 6.8
CVE-2011-3226

Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypas…

Mitigation only
Fix from $1,600 2011-10-14
Safari MEDIUM 6.8
CVE-2011-3230EPSS 50%

Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via…

Fix: after 5.1
Fix from $1,600 2011-10-14
Mac Os X HIGH 7.6
CVE-2011-3213

The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for a…

Fix: after 10.7.1
Fix from $1,950 2011-10-14
.net Framework HIGH 9.3
CVE-2011-1253EPSS 13%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which a…

Mitigation only
Fix from $1,950 2011-10-12
Cmfeditions HIGH 9.3
CVE-2011-4030

The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publish…

Patch available
Fix from $1,950 2011-10-10
Opensolaris HIGH 8.5
CVE-2008-7300

The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is i…

Mitigation only
Fix from $1,950 2011-10-05
Omnidocs HIGH 7.5
CVE-2011-3645

Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which…

No fix yet
Fix from $1,950 2011-09-27
Chrome HIGH 7.5
CVE-2011-2862

Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remo…

Fix: 14.0.835.163+
Fix from $1,950 2011-09-19
Avamar HIGH 7.7
CVE-2011-1740

EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about produ…

Mitigation only
Fix from $1,950 2011-09-19
Acrobat Reader HIGH 9.3
CVE-2011-2431

Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors…

Patch available
Fix from $1,950 2011-09-15
Windows 2003 Server HIGH 7.2
CVE-2011-1984EPSS 7%

WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over t…

Mitigation only
Fix from $1,950 2011-09-15
Nx Os MEDIUM 5.0
CVE-2011-2581

The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000…

Fix: after 5.0
Fix from $1,600 2011-09-14
Tomcat HIGH 7.5
CVE-2011-3190EPSS 15%

Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other …

No fix yet
Fix from $1,950 2011-08-31
Firefox HIGH 9.3
CVE-2011-2993

The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does n…

Mitigation only
Fix from $1,950 2011-08-18
Web Application Firewall MEDIUM 5.0
CVE-2011-3140

IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle qu…

No fix yet
Fix from $1,600 2011-08-15
Tomcat MEDIUM 5.0
CVE-2011-2729EPSS 7%

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,…

Patch available
Fix from $1,600 2011-08-15
Xen HIGH 7.4
CVE-2011-1898

Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS us…

Patch available
Fix from $1,950 2011-08-12
Flash Player MEDIUM 6.4
CVE-2011-2139EPSS 5%

Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows…

Fix: after 10.3.181.36
Fix from $1,600 2011-08-10
WordPress HIGH 9.3
CVE-2011-3129

The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unkn…

Patch available
Fix from $1,950 2011-08-10
Windows 2003 Server HIGH 7.2
CVE-2011-1967

Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W…

Mitigation only
Fix from $1,950 2011-08-10
Windows 2003 Server HIGH 7.2
CVE-2011-1974EPSS 7%

NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly …

No fix yet
Fix from $1,950 2011-08-10
Saas Endpoint Protection MEDIUM 6.8
CVE-2011-3006

The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyAS…

Fix: after 5.2.1
Fix from $1,600 2011-08-10
Infosphere Datastage HIGH 7.2
CVE-2011-3123

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses wea…

Mitigation only
Fix from $1,950 2011-08-10