Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 9.3 CVE-2015-3704EPSS 9% runner in Install.framework in the Install Framework Legacy subsystem in Apple OS X before 10.10.4 does not properly drop privileges, which allows at… Mac Os X after 10.10.3 Fix from $1,9502015-07-03 HIGH 7.2 CVE-2015-3673EPSS 6% Admin Framework in Apple OS X before 10.10.4 does not properly restrict the location of writeconfig clients, which allows local users to obtain root … Mac Os X after 10.10.3 Fix from $1,9502015-07-03 MEDIUM 6.8 CVE-2015-3659 The SQLite authorizer in the Storage functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7, as used in Apple i… Safari after 10.10.3 Fix from $1,6002015-07-03 HIGH 7.5 CVE-2014-9735EPSS 76% The ThemePunch Slider Revolution (revslider) plugin before 3.0.96 for WordPress and Showbiz Pro plugin 1.7.1 and earlier for Wordpress does not prope… Showbiz Pro after 3.0.95 Fix from $1,9502015-06-30 HIGH 7.2 CVE-2015-1900 IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obta… Infosphere Datastage Patch available Fix from $1,9502015-06-29 MEDIUM 6.5 CVE-2015-1974 The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6… Tivoli Directory Server Patch available Fix from $1,6002015-06-28 HIGH 7.2 CVE-2015-4211 Cisco AnyConnect Secure Mobility Client 3.1(60) on Windows does not properly validate pathnames, which allows local users to gain privileges via a cr… Anyconnect Secure Mobility Client Mitigation only Fix from $1,9502015-06-24 HIGH 10.0 CVE-2015-0546 EMC Unified Infrastructure Manager/Provisioning (UIM/P) 4.1 allows remote attackers to bypass LDAP authentication by providing a valid account name. Unified Infrastructure Manager\/provisioning Mitigation only Fix from $1,9502015-06-17 MEDIUM 5.0 CVE-2015-4394 The Services module 7.x-3.x before 7.x-3.12 for Drupal allows remote attackers to bypass the field_access restriction and obtain sensitive private fi… Services Patch available Fix from $1,6002015-06-15 MEDIUM 5.0 CVE-2015-4344 The Services Basic Authentication module 7.x-1.x through 7.x-1.3 for Drupal allows remote attackers to bypass intended resource restrictions via vect… Services Basic Authentication after 7.x-1.3 Fix from $1,6002015-06-15 MEDIUM 6.4 CVE-2015-2958 Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and modify s… Milkystep Light after 1.82 Fix from $1,6002015-06-13 MEDIUM 5.0 CVE-2015-2953 Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote attackers to bypass intended access restrictions and read fil… Milkystep Light after 1.82 Fix from $1,6002015-06-13 MEDIUM 6.9 CVE-2015-4185 The TCL interpreter in Cisco IOS 15.2 does not properly maintain the vty state, which allows local users to gain privileges by starting a session ver… iOS Mitigation only Fix from $1,6002015-06-13 MEDIUM 5.5 CVE-2015-4182 The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restr… Identity Services Engine Software Mitigation only Fix from $1,6002015-06-12 MEDIUM 6.5 CVE-2015-0768 The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implem… Prime Network Control System Mitigation only Fix from $1,6002015-06-12 MEDIUM 5.5 CVE-2015-0773 Cisco FireSIGHT System Software 5.3.1.3 and 6.0.0 allows remote authenticated users to delete an arbitrary user's dashboard via a modified VPN deleti… Firesight System Software Mitigation only Fix from $1,6002015-06-12 MEDIUM 5.0 CVE-2014-8605EPSS 7% The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under the web root with insufficient… Xcloner No fix yet Fix from $1,6002015-06-10 HIGH 7.2 CVE-2014-7872 Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server. Geekbuddy after 4.18.120 Fix from $1,9502015-06-09 HIGH 7.5 CVE-2015-2993EPSS 55% SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator ac… Sysaid after 15.1 Fix from $1,9502015-06-08 HIGH 7.5 CVE-2014-6284 SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and response mechani… Adaptive Server Enterprise after 15.7 Fix from $1,9502015-06-08 HIGH 7.2 CVE-2015-0767 Cisco Edge 300 software 1.0 and 1.1 on Edge 340 devices allows local users to obtain root privileges via unspecified commands, aka Bug ID CSCur18132. Edge 340 Firmware Mitigation only Fix from $1,9502015-06-07 HIGH 7.2 CVE-2015-0761 Cisco AnyConnect Secure Mobility Client before 3.1(8009) and 4.x before 4.0(2052) on Linux does not properly implement unspecified internal functions… Anyconnect Secure Mobility Client after 3.1 Fix from $1,9502015-06-04 HIGH 7.8 CVE-2015-4104 Xen 3.3.x through 4.5.x does not properly restrict access to PCI MSI mask bits, which allows local x86 HVM guest users to cause a denial of service (… Xen Mitigation only Fix from $1,9502015-06-03 MEDIUM 6.5 CVE-2015-4038EPSS 8% The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_sett… Wpmembership No fix yet Fix from $1,6002015-06-03 HIGH 7.5 CVE-2015-4161 SAP Afaria does not properly restrict access to unspecified functionality, which allows remote attackers to obtain sensitive information, gain privil… Afaria No fix yet Fix from $1,9502015-06-02 MEDIUM 6.8 CVE-2015-2851 client_chown in the sync client in Synology Cloud Station 1.1-2291 through 3.1-3320 on OS X allows local users to change the ownership of arbitrary f… Cloud Station Mitigation only Fix from $1,6002015-05-30 HIGH 10.0 CVE-2015-4032 projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently exec… Netcharts Server Mitigation only Fix from $1,9502015-05-29 MEDIUM 5.8 CVE-2015-2694 The kdcpreauth modules in MIT Kerberos 5 (aka krb5) 1.12.x and 1.13.x before 1.13.2 do not properly track whether a client's request has been validat… Kerberos 5 Patch available Fix from $1,6002015-05-25 HIGH 9.0 CVE-2015-0160 IBM Security SiteProtector System 3.0 before 3.0.0.7, 3.1 before 3.1.0.4, and 3.1.1 before 3.1.1.2 allows remote authenticated users to execute arbit… Security Siteprotector System Mitigation only Fix from $1,9502015-05-25 MEDIUM 5.0 CVE-2015-1895 IBM InfoSphere Optim Workload Replay 2.x before 2.1.0.3 relies on client-side code to verify authorization, which allows remote attackers to bypass i… Optim Workload Replay Patch available Fix from $1,6002015-05-25