Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2015-5400EPSS 21% Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass in… Fedora after 3.5.2 Fix from $1,6002015-09-28 HIGH 7.2 CVE-2015-6306 Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to o… Anyconnect Secure Mobility Client Patch available Fix from $1,9502015-09-26 MEDIUM 6.5 CVE-2015-4542 EMC RSA Archer GRC 5.x before 5.5.3 allows remote authenticated users to bypass intended access restrictions, and read or modify Discussion Forum Fie… Rsa Archer Grc No fix yet Fix from $1,6002015-09-26 MEDIUM 6.6 CVE-2015-4505 updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a… Firefox after 40.0.3 Fix from $1,6002015-09-24 HIGH 7.9 CVE-2015-5692EPSS 5% admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenti… Web Gateway after 5.2.2 Fix from $1,9502015-09-20 MEDIUM 6.8 CVE-2015-5637 The Newphoria Photon application before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via uns… 1.1 No fix yet Fix from $1,6002015-09-20 MEDIUM 6.8 CVE-2015-5636 The Newphoria Reversi application before 1.0.3 for Android and before 1.2 for iOS allows attackers to bypass a URL whitelist protection mechanism and… Reversi after 1.1 Fix from $1,6002015-09-20 MEDIUM 6.8 CVE-2015-5635 The Newphoria Koritore application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and … Koritore after 1.0 Fix from $1,6002015-09-20 MEDIUM 6.8 CVE-2015-5634 The Newphoria MEGAPHONE MUSIC application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechani… Megaphone Music after 1.0 Fix from $1,6002015-09-20 MEDIUM 6.8 CVE-2015-5633 The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtai… Auction Camera after 1.1 Fix from $1,6002015-09-20 MEDIUM 6.8 CVE-2015-5632 The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml… Applican after 1.12.2 Fix from $1,6002015-09-20 HIGH 9.0 CVE-2015-4307 The web framework in Cisco Prime Collaboration Provisioning before 11.0 allows remote authenticated users to bypass intended access restrictions and … Prime Collaboration Provisioning Mitigation only Fix from $1,9502015-09-20 HIGH 8.5 CVE-2015-4306 The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended login-session rea… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-09-20 HIGH 9.0 CVE-2015-4304 The web framework in Cisco Prime Collaboration Assurance before 10.5.1.53684-1 allows remote authenticated users to bypass intended access restrictio… Prime Collaboration Assurance Mitigation only Fix from $1,9502015-09-20 HIGH 7.2 CVE-2015-6296 Cisco Prime Network Registrar (CPNR) 8.1(3.3), 8.2(3), and 8.3(2) has a default account, which allows local users to obtain root access by leveraging… Prime Network Registrar Mitigation only Fix from $1,9502015-09-18 MEDIUM 5.0 CVE-2015-3801 The document.cookie API implementation in the CFNetwork Cookies subsystem in WebKit in Apple iOS before 9 allows remote attackers to bypass an intend… Safari after 8.4.1 Fix from $1,6002015-09-18 MEDIUM 6.8 CVE-2015-5629 The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.6.0 and earlier for Android and 1.0.2 and earlier for iOS allows attackers to byp… Japan Connected Free Wi Fi after 1.6.0 Fix from $1,6002015-09-11 HIGH 7.2 CVE-2015-2528 Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation le… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-2527EPSS 7% The process-initialization implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and … Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-2525EPSS 33% Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold an… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-2524 Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not properly constrain impersonation le… Windows 10 Patch available Fix from $1,9502015-09-09 MEDIUM 6.9 CVE-2015-2518 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Windows 10 Patch available Fix from $1,6002015-09-09 MEDIUM 6.9 CVE-2015-2517 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012… Windows 10 Patch available Fix from $1,6002015-09-09 HIGH 7.2 CVE-2015-2512 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Ser… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-2508 The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application, aka "Font Driver Elevation of… Windows 10 No fix yet Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-2507 The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Ser… Windows 10 Patch available Fix from $1,9502015-09-09 HIGH 7.2 CVE-2015-5198 libvdpau before 1.1.1, when used in a setuid or setgid application, allows local users to gain privileges via unspecified vectors, related to the VDP… Ubuntu Linux after 1.1.0 Fix from $1,9502015-09-08 HIGH 9.0 CVE-2015-4544 EMC Documentum Content Server before 7.1P20 and 7.2.x before 7.2P04 does not properly verify authorization for dm_job object access, which allows rem… Documentum Content Server No fix yet Fix from $1,9502015-09-04 HIGH 7.5 CVE-2015-1293 The DOM implementation in Blink, as used in Google Chrome before 45.0.2454.85, allows remote attackers to bypass the Same Origin Policy via unspecifi… Chrome after 44.0.2403 Fix from $1,9502015-09-03 MEDIUM 5.0 CVE-2015-1292 The NavigatorServiceWorker::serviceWorker function in modules/serviceworkers/NavigatorServiceWorker.cpp in Blink, as used in Google Chrome before 45.… Chrome after 44.0.2403 Fix from $1,6002015-09-03