Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.8 CVE-2016-8585EPSS 7% admin_sys_time.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as th… Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-8586EPSS 6% detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary … Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-8589EPSS 6% log_query_dae.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the… Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-8590EPSS 6% log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the… Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-8591EPSS 6% log_query.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the roo… Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 HIGH 8.8 CVE-2016-8592EPSS 6% log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as … Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28 CRITICAL 9.9 CVE-2016-6902EPSS 5% lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. Lshell Patch available Fix from $2,3002017-04-24 CRITICAL 9.9 CVE-2016-6903 lshell 0.9.16 allows remote authenticated users to break out of a limited shell and execute arbitrary commands. Lshell Patch available Fix from $2,3002017-04-24 MEDIUM 6.5 CVE-2016-3114 Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access. Kallithea Mitigation only Fix from $1,6002017-04-24 HIGH 7.8 CVE-2015-8110 Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to… Lenovo System Update after 5.07.0013 Fix from $1,9502017-04-24 CRITICAL 9.8 CVE-2016-3067 Cygwin before 2.5.0 does not properly handle updating permissions when changing users, which allows attackers to gain privileges. Cygwin after 2.4.1-1 Fix from $2,3002017-04-21 HIGH 7.8 CVE-2016-10345 In Phusion Passenger before 5.1.0, a known /tmp filename was used during passenger-install-nginx-module execution, which could allow local attackers … Passenger after 5.0.30 Fix from $1,9502017-04-18 CRITICAL 9.8 CVE-2016-6727 The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code. Android after 7.1.1 Fix from $2,3002017-04-17 HIGH 8.8 CVE-2016-4889 ZOHO ManageEngine ServiceDesk Plus before 9.0 allows remote authenticated guest users to have unspecified impact by leveraging failure to restrict ac… Servicedesk Plus after 8.2 Fix from $1,9502017-04-14 HIGH 7.8 CVE-2016-6299 The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file. Fedora Patch available Fix from $1,9502017-04-14 CRITICAL 9.8 CVE-2014-7920 mediaserver in Android 2.2 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7921. Android Mitigation only Fix from $2,3002017-04-13 CRITICAL 9.8 CVE-2014-7921 mediaserver in Android 4.0.3 through 5.x before 5.1 allows attackers to gain privileges. NOTE: This is a different vulnerability than CVE-2014-7920. Android Mitigation only Fix from $2,3002017-04-13 HIGH 7.8 CVE-2016-10117 Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc. Firejail Mitigation only Fix from $1,9502017-04-13 HIGH 7.8 CVE-2016-10119 Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges. Firejail Mitigation only Fix from $1,9502017-04-13 HIGH 7.8 CVE-2016-10120 Firejail uses 0777 permissions when mounting (1) /dev, (2) /dev/shm, (3) /var/tmp, or (4) /var/lock, which allows local users to gain privileges. Firejail Mitigation only Fix from $1,9502017-04-13 HIGH 7.8 CVE-2016-10121 Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges. Firejail Mitigation only Fix from $1,9502017-04-13 HIGH 7.8 CVE-2016-10122 Firejail does not properly clean environment variables, which allows local users to gain privileges. Firejail No fix yet Fix from $1,9502017-04-13 HIGH 7.8 CVE-2016-10123 Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges. Firejail No fix yet Fix from $1,9502017-04-13 MEDIUM 6.5 CVE-2016-4896 SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecifie… Setucocms Mitigation only Fix from $1,6002017-04-12 HIGH 7.0 CVE-2016-5856 Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerabili… Linux Kernel after 6.0.1 Fix from $1,9502017-04-12 HIGH 8.8 CVE-2016-6811 In Apache Hadoop 2.x before 2.7.4, a user who can escalate to yarn user can possibly run arbitrary commands as root user. Hadoop after 2.7.3 Fix from $1,9502017-04-11 HIGH 7.8 CVE-2016-8235 Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with … Customer Care Software Development Kit after 2.0.16 Fix from $1,9502017-04-10 HIGH 8.1 CVE-2016-8237 Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code. Updates Mitigation only Fix from $1,9502017-04-10 HIGH 7.8 CVE-2016-10323 Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" co… Photo Station 6.3-2958+ Fix from $1,9502017-04-10 HIGH 8.8 CVE-2016-5071 Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 execute the management web application as root. Aleos Firmware No fix yet Fix from $1,9502017-04-10