Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.5 CVE-2015-8621 t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally. T Coffee after 11.00.8cbe486-1 Fix from $1,6002017-08-07 MEDIUM 6.5 CVE-2017-7916 A Permissions, Privileges, and Access Controls issue was discovered in ABB VSN300 WiFi Logger Card versions 1.8.15 and prior, and VSN300 WiFi Logger … Vsn300 Firmware after 1.8.15 Fix from $1,6002017-08-07 CRITICAL 9.8 CVE-2015-2560EPSS 15% Manage Engine Desktop Central 9 before build 90135 allows remote attackers to change passwords of users with the Administrator role via an addOrModif… Manageengine Desktop Central No fix yet Fix from $2,3002017-08-02 MEDIUM 6.5 CVE-2016-7845 GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized … Gigacc Office Mitigation only Fix from $1,6002017-08-02 MEDIUM 6.2 CVE-2016-10398 Android 6.0 has an authentication bypass for attackers with root and physical access. Cryptographic authentication tokens (AuthTokens) used by the Tr… Android Mitigation only Fix from $1,6002017-07-17 CRITICAL 9.8 CVE-2017-6713 A vulnerability in the Play Framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to gain full access … Elastic Services Controller Mitigation only Fix from $2,3002017-07-06 HIGH 8.1 CVE-2016-3998 NetApp AltaVault 4.1 and earlier allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service vi… Altavault after 4.1 Fix from $1,9502017-07-03 HIGH 7.1 CVE-2004-2778 Ebuild in Gentoo may change directory and file permissions depending on the order of installed packages, which allows local users to read or write to… Portage Mitigation only Fix from $1,9502017-06-27 HIGH 7.8 CVE-2015-1591 The kamailio build in kamailio before 4.2.0-2 process allows local users to gain privileges. Kamailio after 4.2.0-1.1 Fix from $1,9502017-06-27 HIGH 7.8 CVE-2015-1795 Red Hat Gluster Storage RPM Package 3.2 allows local users to gain privileges and execute arbitrary code as root. Gluster Storage Mitigation only Fix from $1,9502017-06-27 MEDIUM 5.9 CVE-2016-9972 IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport … Qradar Security Information And Event Manager Patch available Fix from $1,6002017-06-27 HIGH 8.8 CVE-2016-8493 In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability. Forticlient Mitigation only Fix from $1,9502017-06-26 MEDIUM 6.5 CVE-2016-10364 With X-Pack installed, Kibana versions 5.0.0 and 5.0.1 were not properly authenticating requests to advanced settings and the short URL service, any … Kibana Mitigation only Fix from $1,6002017-06-16 HIGH 7.8 CVE-2016-10341 In all Android releases from CAF using the Linux kernel, 3rd party TEEs have more privilege than intended. Android No fix yet Fix from $1,9502017-06-13 HIGH 8.8 CVE-2016-9984 IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM… Maximo Asset Management Mitigation only Fix from $1,9502017-06-13 HIGH 7.8 CVE-2015-4596 Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges. Mouse Suite after 6.72 Fix from $1,9502017-06-13 HIGH 7.8 CVE-2016-7818 Untrusted search path vulnerability in Installers for Specification check program (social insurance) Ver. 9.00 and earlier, TODOKESHO print program V… Device Data Encryption Program Patch available Fix from $1,9502017-06-09 HIGH 8.8 CVE-2016-4471 ManageIQ in CloudForms before 4.1 allows remote authenticated users to execute arbitrary code. Cloudforms after 4.0 Fix from $1,9502017-06-08 HIGH 7.8 CVE-2017-6638 A vulnerability in how DLL files are loaded with Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to … Anyconnect Secure Mobility Client after 4.4.00243 Fix from $1,9502017-06-08 CRITICAL 9.8 CVE-2017-6640EPSS 11% A vulnerability in Cisco Prime Data Center Network Manager (DCNM) Software could allow an unauthenticated, remote attacker to log in to the administr… Prime Data Center Network Manager Mitigation only Fix from $2,3002017-06-08 HIGH 7.8 CVE-2016-8228 In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges. Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 HIGH 8.1 CVE-2016-3084 The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server… Cloud Foundry Uaa Bosh after 236 Fix from $1,9502017-05-25 CRITICAL 9.0 CVE-2016-4435 An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read… Bosh Stemcell after 3232.4 Fix from $2,3002017-05-25 HIGH 7.5 CVE-2016-5007 Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for m… Spring Framework Mitigation only Fix from $1,9502017-05-25 HIGH 7.8 CVE-2015-8089 The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows loc… P7 L09 Firmware Mitigation only Fix from $1,9502017-05-23 HIGH 7.8 CVE-2016-1876 The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors. Solution Center after 3.3.0001 Fix from $1,9502017-05-23 MEDIUM 6.7 CVE-2015-4045 The sudoers file in the asset discovery scanner in AlienVault OSSIM before 5.0.1 allows local users to gain privileges via a crafted nmap script. Open Source Security Information Management after 5.0 Fix from $1,6002017-05-23 HIGH 7.5 CVE-2015-5682 upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targe… Powerplay Gallery No fix yet Fix from $1,9502017-05-23 HIGH 8.8 CVE-2016-6112 IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain admi… Marketing Platform Mitigation only Fix from $1,9502017-05-22 MEDIUM 6.5 CVE-2017-6635EPSS 10% A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 12.1) could allow an authenticated, remote … Prime Collaboration Provisioning Mitigation only Fix from $1,6002017-05-22