Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2015-7809 The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute arbitrary … Twig after 1.19.0 Fix from $1,6002015-11-06 HIGH 9.0 CVE-2015-7394 The datastor kernel module in F5 BIG-IP Analytics, APM, ASM, Link Controller, and LTM 11.1.0 before 12.0.0, BIG-IP AAM 11.4.0 before 12.0.0, BIG-IP A… Big Iq Device Mitigation only Fix from $1,9502015-11-06 MEDIUM 6.9 CVE-2015-4282 Cisco Mobility Services Engine (MSE) through 8.0.120.7 uses weak permissions for unspecified binary files, which allows local users to obtain root pr… Mobility Services Engine Mitigation only Fix from $1,6002015-11-06 MEDIUM 5.0 CVE-2015-7197 Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 improperly control the ability of a web worker to create a WebSocket object, which allow… Firefox after 41.0.2 Fix from $1,6002015-11-05 HIGH 7.2 CVE-2015-6030 HP ArcSight Logger 6.0.0.7307.1, ArcSight Command Center 6.8.0.1896.0, and ArcSight Connector Appliance 6.4.0.6881.3 use the root account to execute … Arcsight Connector Appliance after 7.1.3 Fix from $1,9502015-11-04 MEDIUM 5.5 CVE-2015-5021 IBM InfoSphere Information Server 11.3 and 11.5 allows remote authenticated DataStage users to bypass intended job-execution restrictions or obtain s… Infosphere Information Server Patch available Fix from $1,6002015-11-04 HIGH 7.2 CVE-2015-4927 The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses… Tivoli Storage Manager Mitigation only Fix from $1,9502015-11-04 MEDIUM 5.8 CVE-2015-6614 Telephony in Android 5.x before 5.1.1 LMY48X allows attackers to gain privileges, and consequently bypass intended network-interface restrictions, pe… Android Mitigation only Fix from $1,6002015-11-03 HIGH 9.3 CVE-2015-6612 libmedia in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to gain privileges via a crafted application, aka internal bug 235… Android 5.1.1+ Fix from $1,9502015-11-03 MEDIUM 6.5 CVE-2015-3270 Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibl… Ambari Mitigation only Fix from $1,6002015-11-02 HIGH 7.2 CVE-2015-7835 The mod_l2_entry function in arch/x86/mm.c in Xen 3.4 through 4.6.x does not properly validate level 2 page table entries, which allows local PV gues… Xen Mitigation only Fix from $1,9502015-10-30 MEDIUM 5.0 CVE-2015-5671 Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to bypass intended access restrictions and read arbitrary uploaded files via unsp… Enisys Gw after 1.4.0 Fix from $1,6002015-10-29 MEDIUM 6.8 CVE-2015-4997 IBM WebSphere Portal 8.5.0 before CF08 allows remote attackers to bypass intended access restrictions via a crafted request. Websphere Portal Patch available Fix from $1,6002015-10-29 MEDIUM 6.9 CVE-2015-6034 EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a Trojan ho… Network Utility Patch available Fix from $1,6002015-10-28 MEDIUM 6.8 CVE-2015-5286 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage q… Image Registry And Delivery Service \(glance\) after 2014.2.3 Fix from $1,6002015-10-26 MEDIUM 5.5 CVE-2015-5251 OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of … Image Registry And Delivery Service \(glance\) after 2014.2.3 Fix from $1,6002015-10-26 MEDIUM 5.0 CVE-2015-6341 The Web Management GUI on Cisco Wireless LAN Controller (WLC) devices with software 7.4(140.0) and 8.0(120.0) allows remote attackers to cause a deni… Wireless Lan Controller Software Mitigation only Fix from $1,6002015-10-25 HIGH 9.0 CVE-2015-6335 The policy implementation in Cisco FireSIGHT Management Center 5.3.1.7, 5.4.0.4, and 6.0.0 for VMware allows remote authenticated administrators to b… Firesight System Software Mitigation only Fix from $1,9502015-10-25 HIGH 7.6 CVE-2015-7016 The MCX Application Restrictions component in Apple OS X before 10.11.1, when Managed Configuration is enabled, mishandles provisioning profiles, whi… Mac Os X after 10.11.0 Fix from $1,9502015-10-23 MEDIUM 6.8 CVE-2015-7003 coreaudiod in Audio in Apple OS X before 10.11.1 does not initialize an unspecified data structure, which allows attackers to execute arbitrary code … Mac Os X after 10.11.0 Fix from $1,6002015-10-23 HIGH 7.2 CVE-2015-5945 The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters. Mac Os X after 10.11.0 Fix from $1,9502015-10-23 MEDIUM 5.0 CVE-2015-7031 The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass … Mac Os X Server after 5.0.14 Fix from $1,6002015-10-23 MEDIUM 5.0 CVE-2015-7862 Persistent Accelerite Radia Client Automation (formerly HP Client Automation) 7.9 through 9.1 before 2015-02-19 improperly implements the Role Based … Radia Client Automation Mitigation only Fix from $1,6002015-10-19 HIGH 10.0 CVE-2015-7861EPSS 5% Persistent Accelerite Radia Client Automation (formerly HP Client Automation), possibly before 9.1, allows remote attackers to execute arbitrary code… Radia Client Automation Mitigation only Fix from $1,9502015-10-19 MEDIUM 6.9 CVE-2015-7751 Juniper Junos OS before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, 12.3 before 12.3R9, 12.3X48 before 12.3X48-D15, 13.2 bef… Junos after 12.1x44 Fix from $1,6002015-10-19 HIGH 7.5 CVE-2015-1814 The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token chang… Jenkins after 3.1 Fix from $1,9502015-10-16 MEDIUM 6.5 CVE-2015-1806 The combination filter Groovy script in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with job configuration permissi… Jenkins after 3.1 Fix from $1,6002015-10-16 MEDIUM 6.9 CVE-2015-4948 netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vect… Vios Mitigation only Fix from $1,6002015-10-16 HIGH 7.5 CVE-2015-7840 The command line management console (CMC) in SolarWinds Log and Event Manager (LEM) before 6.2.0 allows remote attackers to execute arbitrary code vi… Log And Event Manager after 6.1 Fix from $1,9502015-10-15 HIGH 7.5 CVE-2015-6755 The ContainerNode::parserInsertBefore function in core/dom/ContainerNode.cpp in Blink, as used in Google Chrome before 46.0.2490.71, proceeds with a … Chrome after 45.0.2454.101 Fix from $1,9502015-10-15