Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.9 CVE-2015-1117 The (1) setreuid and (2) setregid system-call implementations in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7… Iphone Os after 10.10.2 Fix from $1,6002015-04-10 MEDIUM 5.5 CVE-2015-3028 McAfee Advanced Threat Defense (MATD) before 3.4.4.63 allows remote authenticated users to bypass intended restrictions and change or update configur… Advanced Threat Defense after 3.4.4.14 Fix from $1,6002015-04-08 MEDIUM 5.0 CVE-2015-0798 The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which… Firefox after 37.0 Fix from $1,6002015-04-08 HIGH 9.0 CVE-2015-2828 CA Spectrum 9.2.x and 9.3.x before 9.3 H02 does not properly validate serialized Java objects, which allows remote authenticated users to obtain admi… Spectrum No fix yet Fix from $1,9502015-04-08 MEDIUM 6.8 CVE-2015-1893 The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack the sessions of arbitrary users, and consequently obt… Websphere Datapower Xc10 Appliance Firmware Patch available Fix from $1,6002015-04-06 HIGH 7.2 CVE-2015-0179 Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege… Domino Patch available Fix from $1,9502015-04-06 MEDIUM 6.5 CVE-2015-0951 X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modified (1) update or (2) remove r… X Cart after 5.1.10 Fix from $1,6002015-04-05 HIGH 10.0 CVE-2015-0932EPSS 6% The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGate 3.01 G, and InnGate 3.10 G … Inngate Ig 3.00 E Patch available Fix from $1,9502015-04-05 MEDIUM 6.5 CVE-2015-0682 Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka B… Unified Communications Domain Manager Mitigation only Fix from $1,6002015-04-03 MEDIUM 6.5 CVE-2015-2821 TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other edit… Neos Patch available Fix from $1,6002015-04-01 MEDIUM 6.4 CVE-2015-2814 SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which… Clinical Task Tracker Mitigation only Fix from $1,6002015-04-01 MEDIUM 5.0 CVE-2015-0816EPSS 67% Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier… Firefox after 36.0.4 Fix from $1,6002015-04-01 HIGH 7.5 CVE-2015-0804 The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation… Firefox after 36.0.4 Fix from $1,9502015-04-01 HIGH 7.5 CVE-2015-0803 The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value duri… Ubuntu Linux after 36.0.4 Fix from $1,9502015-04-01 MEDIUM 5.0 CVE-2015-0802EPSS 67% Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might a… Ubuntu Linux after 36.0.4 Fix from $1,6002015-04-01 HIGH 7.5 CVE-2015-0801 Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and ex… Firefox after 36.0.4 Fix from $1,9502015-04-01 MEDIUM 6.4 CVE-2015-2791EPSS 13% The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts, pages, and menus via a craf… Wpml after 3.1.8 Fix from $1,6002015-03-30 MEDIUM 5.0 CVE-2015-2348EPSS 9% The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a… Enterprise Linux Desktop after 10.10.5 Fix from $1,6002015-03-30 HIGH 7.2 CVE-2015-0528 The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local… Isilon Onefs after 7.0.2.12 Fix from $1,9502015-03-29 MEDIUM 6.5 CVE-2015-2758 The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain… Data Loss Prevention Endpoint after 9.3.400 Fix from $1,6002015-03-27 HIGH 7.5 CVE-2015-2683EPSS 5% Citrix Command Center before 5.1 Build 35.4 and 5.2 before Build 42.7 does not properly restrict access to the Advent Java Management Extensions (JMX… Command Center No fix yet Fix from $1,9502015-03-26 HIGH 10.0 CVE-2015-2284EPSS 73% userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary cod… Firewall Security Manager after 6.6.5 Fix from $1,9502015-03-24 HIGH 7.2 CVE-2015-0197 IBM General Parallel File System (GPFS) 3.4 before 3.4.0.32, 3.5 before 3.5.0.24, and 4.1 before 4.1.0.7 allows local users to obtain root privileges… General Parallel File System Patch available Fix from $1,9502015-03-24 HIGH 7.5 CVE-2015-0818 Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy an… Firefox after 36.0.3 Fix from $1,9502015-03-24 MEDIUM 5.5 CVE-2015-0149 The developer portal in IBM API Management 3.0 before 3.0.4.1 does not properly restrict access to the public and private APIs, which allows remote a… Api Management Patch available Fix from $1,6002015-03-18 MEDIUM 5.5 CVE-2014-6129 IBM Rational Jazz Team Server (JTS), as used in Rational Collaborative Lifecycle Management 3.x and 4.x before 4.0.7 iFix4 and 5.x before 5.0.2 iFix2… Rational Quality Manager Patch available Fix from $1,6002015-03-18 MEDIUM 6.6 CVE-2015-0663 Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement access control for IPC messages, which allows local users… Anyconnect Secure Mobility Client after 4.0 Fix from $1,6002015-03-17 HIGH 7.2 CVE-2015-0662 Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier allows local users to gain privileges via crafted IPC messages that trigger use of ro… Anyconnect Secure Mobility Client after 4.0 Fix from $1,9502015-03-17 MEDIUM 5.0 CVE-2015-1593 The stack randomization feature in the Linux kernel before 3.19.1 on 64-bit platforms uses incorrect data types for the results of bitwise left-shift… Linux Kernel after 3.18.9 Fix from $1,6002015-03-16 MEDIUM 6.9 CVE-2014-8159 The InfiniBand (IB) implementation in the Linux kernel package before 2.6.32-504.12.2 on Red Hat Enterprise Linux (RHEL) 6 does not properly restrict… Linux Kernel 3.2.69 / 3.4.108+ Fix from $1,6002015-03-16