Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.8 CVE-2016-2313 auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging … Cacti after 0.8.8f Fix from $1,9502016-04-13 HIGH 7.8 CVE-2016-0148EPSS 14% Microsoft .NET Framework 4.6 and 4.6.1 mishandles library loading, which allows local users to gain privileges via a crafted application, aka ".NET F… .net Framework No fix yet Fix from $1,9502016-04-12 HIGH 7.8 CVE-2016-0143 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R… Windows 10 No fix yet Fix from $1,9502016-04-12 HIGH 8.8 CVE-2016-2405 Huawei Policy Center with software before V100R003C10SPC020 allows remote authenticated users to gain privileges and cause a denial of service (syste… Policy Center Firmware Mitigation only Fix from $1,9502016-04-12 HIGH 7.8 CVE-2016-3157 The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel does not properly context-switch IOPL on 64-bit PV Xen guests, which all… Ubuntu Linux Patch available Fix from $1,9502016-04-12 HIGH 8.1 CVE-2016-3169 The User module in Drupal 6.x before 6.38 and 7.x before 7.43 allows remote attackers to gain privileges by leveraging contributed or custom code tha… Debian Linux Patch available Fix from $1,9502016-04-12 HIGH 8.4 CVE-2016-2557 The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows allows lo… Gpu Driver R340 Mitigation only Fix from $1,9502016-04-12 HIGH 7.8 CVE-2016-2556 The Escape interface in the Kernel Mode Driver layer in the NVIDIA GPU graphics driver R340 before 341.95 and R352 before 354.74 on Windows improperl… Gpu Driver R340 after 431.61 Fix from $1,9502016-04-12 MEDIUM 6.5 CVE-2015-5167 The Policy Admin Tool in Apache Ranger before 0.5.1 allows remote authenticated users to bypass intended access restrictions via the REST API. Ranger after 0.5.0 Fix from $1,6002016-04-12 HIGH 7.3 CVE-2015-5329 The TripleO Heat templates (tripleo-heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 7.0, do not properly use the configured R… Openstack Mitigation only Fix from $1,9502016-04-11 HIGH 8.8 CVE-2016-0735 Apache Ranger 0.5.x before 0.5.2 allows remote authenticated users to bypass intended parent resource-level access restrictions by leveraging mishand… Ranger Mitigation only Fix from $1,9502016-04-11 HIGH 7.1 CVE-2015-0266 The Policy Admin Tool in Apache Ranger before 0.5.0 allows remote authenticated users to bypass intended access restrictions via direct access to mod… Ranger after 0.4.0. Fix from $1,9502016-04-11 CRITICAL 9.1 CVE-2016-3065 The (1) brin_page_type and (2) brin_metapage_info functions in the pageinspect extension in PostgreSQL before 9.5.x before 9.5.2 allows attackers to … PostgreSQL Patch available Fix from $2,3002016-04-11 HIGH 8.8 CVE-2016-1235 The oarsh script in OAR before 2.5.7 allows remote authenticated users of a cluster to obtain sensitive information and possibly gain privileges via … Debian Linux after 2.5.6 Fix from $1,9502016-04-11 HIGH 7.8 CVE-2016-2393 Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows… Fingerprint Manager after 8.01.56 Fix from $1,9502016-04-11 HIGH 7.5 CVE-2016-2171EPSS 43% The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to … Jetspeed after 2.3.0 Fix from $1,9502016-04-11 HIGH 7.3 CVE-2016-3188 The _prepopulate_request_walk function in the Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the (1) actions,… Prepopulate Patch available Fix from $1,9502016-04-08 HIGH 7.3 CVE-2016-3187 The Prepopulate module 7.x-2.x before 7.x-2.1 for Drupal allows remote attackers to modify the REQUEST superglobal array, and consequently have unspe… Prepopulate Patch available Fix from $1,9502016-04-08 HIGH 7.0 CVE-2016-1531EPSS 6% Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument. Exim after 4.86 Fix from $1,9502016-04-07 CRITICAL 9.8 CVE-2016-0788EPSS 12% The remoting module in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to execute arbitrary code by opening a JRMP listener. Jenkins after 1.649 Fix from $2,3002016-04-07 CRITICAL 9.8 CVE-2016-1313 Cisco UCS Invicta C3124SA Appliance 4.3.1 through 5.0.1, UCS Invicta Scaling System and Appliance, and Whiptail Racerunner improperly store a default… Ucs Invicta C3124sa Appliance Mitigation only Fix from $2,3002016-04-06 HIGH 8.1 CVE-2016-1290 The web API in Cisco Prime Infrastructure 1.2.0 through 2.2(2) and Cisco Evolved Programmable Network Manager (EPNM) 1.2 allows remote authenticated … Evolved Programmable Network Manager Mitigation only Fix from $1,9502016-04-06 HIGH 7.8 CVE-2016-2288 Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file. Cogent Datahub after 7.3.9 Fix from $1,9502016-03-29 MEDIUM 6.5 CVE-2016-1366 The SCP and SFTP modules in Cisco IOS XR 5.0.0 through 5.2.5 on Network Convergence System 6000 devices use weak permissions for system files, which … Ios Xr Mitigation only Fix from $1,6002016-03-24 HIGH 7.8 CVE-2016-1751 The kernel in Apple iOS before 9.3, tvOS before 9.2, and watchOS before 2.2 does not properly restrict the execute permission, which allows attackers… Iphone Os 2.2 / 9.2+ Fix from $1,9502016-03-24 MEDIUM 6.8 CVE-2016-1734 AppleUSBNetworking in Apple iOS before 9.3 and OS X before 10.11.4 allows physically proximate attackers to execute arbitrary code in a privileged co… Iphone Os after 10.11.3 Fix from $1,6002016-03-24 HIGH 7.2 CVE-2016-2281 Untrusted search path vulnerability in ABB Panel Builder 800 5.1 allows local users to gain privileges via a Trojan horse DLL in the current working … Panel Builder 800 Mitigation only Fix from $1,9502016-03-18 HIGH 8.8 CVE-2015-8154EPSS 5% The SysPlant.sys driver in the Application and Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 12.1 before RU6-MP4… Endpoint Protection Manager after 12.1 Fix from $1,9502016-03-18 HIGH 8.8 CVE-2014-9768 IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" … Tivoli Netview Access Services Mitigation only Fix from $1,9502016-03-18 HIGH 7.8 CVE-2016-1990 HPE ArcSight ESM 5.x before 5.6, 6.0, 6.5.x before 6.5C SP1 Patch 2, and 6.8c before P1, and ArcSight ESM Express before 6.9.1, allows local users to… Arcsight Enterprise Security Manager after 5.6 Fix from $1,9502016-03-16