Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2015-7371 Revive Adserver before 3.2.2 does not restrict access to run-mpe.php, which allows remote attackers to run the Maintenance Priority Engine and possib… Revive Adserver after 3.2.1 Fix from $1,6002015-10-14 HIGH 7.2 CVE-2015-2554 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows local users to gain p… Windows 10 Patch available Fix from $1,9502015-10-14 HIGH 7.2 CVE-2015-2553 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2… Windows 10 Patch available Fix from $1,9502015-10-14 HIGH 7.2 CVE-2015-2550 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2… Windows 10 Patch available Fix from $1,9502015-10-14 HIGH 7.2 CVE-2015-6315 Cisco Aironet 1850 access points with software 8.1(112.4) allow local users to gain privileges via crafted CLI commands, aka Bug ID CSCuv79694. Aironet Access Point Software Mitigation only Fix from $1,9502015-10-13 MEDIUM 6.6 CVE-2015-6322 The IPC channel in Cisco AnyConnect Secure Mobility Client 2.0.0343 through 4.1(8) allows local users to bypass intended access restrictions and move… Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002015-10-12 MEDIUM 6.9 CVE-2015-4325 The process-management implementation in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges … Telepresence Video Communication Server Software Mitigation only Fix from $1,6002015-10-12 HIGH 7.2 CVE-2015-4548 EMC RSA Web Threat Detection before 5.1 SP1 allows local users to obtain root privileges by leveraging access to a service account and writing comman… Web Threat Detection after 5.1 Fix from $1,9502015-10-12 HIGH 9.0 CVE-2015-7766EPSS 81% PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL query restrictions via a comme… Manageengine Opmanager after 11.5 Fix from $1,9502015-10-09 HIGH 7.2 CVE-2015-5889EPSS 5% rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving environment variables. Mac Os X after 10.10.5 Fix from $1,9502015-10-09 HIGH 7.2 CVE-2015-5888 The Install Framework Legacy component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors involving a privileged exe… Mac Os X after 10.10.5 Fix from $1,9502015-10-09 MEDIUM 6.8 CVE-2015-5849 The filtering implementation in AppleEvents in Apple OS X before 10.11 mishandles attempts to send events to a different user, which allows attackers… Mac Os X after 10.10.5 Fix from $1,6002015-10-09 HIGH 9.3 CVE-2015-7717 mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal … Android after 5.1 Fix from $1,9502015-10-06 HIGH 7.2 CVE-2015-7600 Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrar… Vpn Client No fix yet Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-6606 The Secure Element Evaluation Kit (aka SEEK or SmartCard API) plugin in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted… Android after 5.1 Fix from $1,9502015-10-06 MEDIUM 6.8 CVE-2015-6607 SQLite before 3.8.9, as used in Android before 5.1.1 LMY48T, allows attackers to gain privileges via a crafted application, aka internal bug 20099586. SQLite after 3.8.8.3 Fix from $1,6002015-10-06 HIGH 9.3 CVE-2015-6596 mediaserver in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bugs 20731946 and 20719651, a … Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-3879 Media Player Framework in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, aka internal bug 23223325. Android after 5.1 Fix from $1,9502015-10-06 HIGH 9.3 CVE-2015-3865 The Runtime subsystem in Android before 5.1.1 LMY48T allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Sign… Android after 5.1 Fix from $1,9502015-10-06 MEDIUM 6.4 CVE-2015-3847 Bluetooth in Android before 5.1.1 LMY48T allows attackers to remove stored SMS messages via a crafted application, aka internal bug 22343270. Android after 5.1 Fix from $1,6002015-10-06 MEDIUM 6.5 CVE-2015-5645 ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors. Matchasns after 1.3.6 Fix from $1,6002015-10-06 MEDIUM 6.5 CVE-2015-5640 baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request. Basercms after 3.0.7 Fix from $1,6002015-10-06 MEDIUM 6.0 CVE-2015-4964 IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allow… Urbancode Deploy Patch available Fix from $1,6002015-10-06 HIGH 10.0 CVE-2015-7709EPSS 79% The arkeiad daemon in the Arkeia Backup Agent in Western Digital Arkeia 11.0.12 and earlier allows remote attackers to bypass authentication and exec… Western Digital Arkeia after 11.0.12 Fix from $1,9502015-10-05 MEDIUM 6.5 CVE-2015-7707EPSS 6% Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter to user-edit-form.jsp. Openfire No fix yet Fix from $1,6002015-10-05 HIGH 9.3 CVE-2015-3858 The checkDestination function in internal/telephony/SMSDispatcher.java in Android before 5.1.1 LMY48M relies on an obsolete permission name for an au… Android after 5.1 Fix from $1,9502015-10-01 HIGH 9.3 CVE-2015-3849 The Region_createFromParcel function in core/jni/android/graphics/Region.cpp in Region in Android before 5.1.1 LMY48M does not check the return value… Android after 5.1 Fix from $1,9502015-10-01 MEDIUM 6.8 CVE-2015-3845 The Parcel::appendFrom function in libs/binder/Parcel.cpp in Binder in Android before 5.1.1 LMY48M does not consider parcel boundaries during identif… Android after 5.1 Fix from $1,6002015-10-01 MEDIUM 6.8 CVE-2015-3844 The getProcessRecordLocked method in services/core/java/com/android/server/am/ActivityManagerService.java in ActivityManager in Android before 5.1.1 … Android after 5.1 Fix from $1,6002015-10-01 HIGH 9.3 CVE-2015-3843 The SIM Toolkit (STK) framework in Android before 5.1.1 LMY48I allows attackers to (1) intercept or (2) emulate unspecified Telephony STK SIM command… Android after 5.1 Fix from $1,9502015-10-01