Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.8 CVE-2016-7583 An issue was discovered in certain Apple products. iCloud before 6.0.1 is affected. The issue involves the setup subsystem in the "iCloud" component.… Icloud after 6.0.0 Fix from $1,9502017-02-20 HIGH 8.8 CVE-2016-4617 An issue was discovered in certain Apple products. macOS before 10.12 is affected. The issue involves a sandbox escape related to launchctl process s… Mac Os X after 10.11.6 Fix from $1,9502017-02-20 HIGH 7.8 CVE-2016-4675 An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS before 10.0.1 is affected. wat… Iphone Os 3.1 / 10.0.1+ Fix from $1,9502017-02-20 HIGH 7.5 CVE-2016-9637 The (1) ioport_read and (2) ioport_write functions in Xen, when qemu is used as a device model within Xen, might allow local x86 HVM guest OS adminis… Xenserver Mitigation only Fix from $1,9502017-02-17 HIGH 8.8 CVE-2017-3801 A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary work… Unified Computing System Director Mitigation only Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-8972 IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: I… Aix Patch available Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-6079 IBM AIX 5.3, 6.1, 7.1, and 7.2 contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privileges. I… Aix Patch available Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-10089 Nagios 4.3.2 and earlier allows local users to gain root privileges via a hard link attack on the Nagios init script file, related to CVE-2016-8641. Nagios after 4.2.4 Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-1880 The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain … FreeBSD Mitigation only Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-1881 The kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to cause a denial of service (crash) or potentially gain privilege via a crafted Linux c… FreeBSD Mitigation only Fix from $1,9502017-02-15 HIGH 7.8 CVE-2016-1883 The issetugid system call in the Linux compatibility layer in FreeBSD 9.3, 10.1, and 10.2 allows local users to gain privilege via unspecified vector… FreeBSD Mitigation only Fix from $1,9502017-02-15 CRITICAL 9.8 CVE-2016-9366 An issue was discovered in Moxa NPort 5110 versions prior to 2.6, NPort 5130/5150 Series versions prior to 3.6, NPort 5200 Series versions prior to 2… Nport 5100 Series Firmware after 3.10 Fix from $2,3002017-02-13 CRITICAL 10.0 CVE-2016-8363 An issue was discovered in Moxa OnCell OnCellG3470A-LTE, AWK-1131A/3131A/4131A Series, AWK-3191 Series, AWK-5232/6232 Series, AWK-1121/1127 Series, W… Oncellg3470a Lte Firmware after 10-31-2016 Fix from $2,3002017-02-13 MEDIUM 6.8 CVE-2016-9345 An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow… Deltav Mitigation only Fix from $1,6002017-02-13 HIGH 7.8 CVE-2016-9353 An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The admin password is stored in the system and is encrypted with a stat… Susiaccess after 3.0 Fix from $1,9502017-02-13 MEDIUM 6.4 CVE-2016-8353 An issue was discovered in OSIsoft PI Web API 2015 R2 (Version 1.5.1). There is a weakness in this product that may allow an attacker to access the P… Pi Web Api 2015 R2 No fix yet Fix from $1,6002017-02-13 HIGH 7.1 CVE-2016-8357 An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and… Jenesys Bas Bridge after 1.1.8 Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2015-8768 click/install.py in click does not require files in package filesystem tarballs to start with ./ (dot slash), which allows remote attackers to instal… Ubuntu Linux Patch available Fix from $2,3002017-02-13 HIGH 7.0 CVE-2016-8659 Bubblewrap before 0.1.3 sets the PR_SET_DUMPABLE flag, which might allow local users to gain privileges by attaching to the process, as demonstrated … Bubblewrap after 0.1.1 Fix from $1,9502017-02-13 HIGH 7.8 CVE-2017-3813 A vulnerability in the Start Before Logon (SBL) module of Cisco AnyConnect Secure Mobility Client Software for Windows could allow an unauthenticated… Anyconnect Secure Mobility Client No fix yet Fix from $1,9502017-02-09 HIGH 7.2 CVE-2016-8494 Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a … Connect Mitigation only Fix from $1,9502017-02-09 HIGH 7.3 CVE-2016-5934 IBM Tivoli Storage Manager FastBack installer could allow a remote attacker to execute arbitrary code on the system. By placing a specially-crafted D… Tivoli Storage Manager Fastback Mitigation only Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8419 An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the … Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8420 An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the … Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8421 An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the … Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8476 An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the … Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8480 An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application t… Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.0 CVE-2016-8481 An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the … Linux Kernel after 7.1.1 Fix from $1,9502017-02-08 HIGH 7.8 CVE-2016-2779 runuser in util-linux allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's … Util Linux Mitigation only Fix from $1,9502017-02-07 HIGH 7.8 CVE-2016-10044 The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which makes it easier for local users … Linux Kernel 3.16.43 / 4.4.24+ Fix from $1,9502017-02-07