Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2014-7822 The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a si… Linux Kernel after 3.15.8 Fix from $1,9502015-03-16 HIGH 7.5 CVE-2015-0981 The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbi… Bacnet Opc Server after 2.1.359.22 Fix from $1,9502015-03-14 HIGH 7.2 CVE-2015-2151 The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local gu… Fedora Patch available Fix from $1,9502015-03-12 HIGH 7.2 CVE-2015-0078 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not prop… Windows 8 Patch available Fix from $1,9502015-03-11 HIGH 7.2 CVE-2015-0075 The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain… Windows 2003 Server Mitigation only Fix from $1,9502015-03-11 HIGH 7.2 CVE-2015-0073 The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows … Windows 7 Patch available Fix from $1,9502015-03-11 MEDIUM 5.0 CVE-2015-1226 The DebuggerFunction::InitAgentHost function in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 41.0.2272.76 does not properl… Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2014-9689 content/renderer/device_sensors/device_orientation_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate … Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 MEDIUM 5.0 CVE-2011-5319 content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accel… Chrome after 40.0.2214.115 Fix from $1,6002015-03-09 HIGH 7.2 CVE-2015-1170 The NVIDIA Display Driver R304 before 309.08, R340 before 341.44, R343 before 345.20, and R346 before 347.52 does not properly validate local client … Gpu Driver R304 after 347.51 Fix from $1,9502015-03-06 MEDIUM 6.5 CVE-2014-2130 Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authentic… Secure Access Control System Mitigation only Fix from $1,6002015-03-06 MEDIUM 5.0 CVE-2015-2075 SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011… Businessobjects Edge No fix yet Fix from $1,6002015-02-27 MEDIUM 6.8 CVE-2015-0821 Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges… Firefox after 35.0.1 Fix from $1,6002015-02-25 MEDIUM 6.5 CVE-2014-8115 The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended ac… Kie Workbench Patch available Fix from $1,6002015-02-20 MEDIUM 6.8 CVE-2014-8114 The UberFire Framework 0.3.x does not properly restrict paths, which allows remote attackers to (1) execute arbitrary code by uploading crafted conte… Uberfire Patch available Fix from $1,6002015-02-20 HIGH 7.2 CVE-2015-1515 The dwall.sys driver in SoftSphere DefenseWall Personal Firewall 3.24 allows local users to write data to arbitrary memory locations, and consequentl… Defensewall Personal Firewall No fix yet Fix from $1,9502015-02-19 MEDIUM 6.4 CVE-2014-5286 The ActiveMatrix Policy Manager Authentication module in TIBCO ActiveMatrix Policy Agent 3.x before 3.1.2, ActiveMatrix Policy Manager 3.x before 3.1… Activematrix Management Agent Mitigation only Fix from $1,6002015-02-19 HIGH 8.5 CVE-2015-1499 The ActiveMQ Broker in Samsung Security Manager (SSM) before 1.31 allows remote attackers to delete arbitrary files, and consequently cause a denial … Samsung Security Manager after 1.30 Fix from $1,9502015-02-16 HIGH 10.0 CVE-2015-1498 Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user … Radia Client Automation Mitigation only Fix from $1,9502015-02-16 HIGH 7.2 CVE-2015-1496 Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local … Motorola Scanner Sdk Mitigation only Fix from $1,9502015-02-16 HIGH 9.0 CVE-2015-0518 The Properties service in the D2FS web-service component in EMC Documentum D2 3.1 through SP1, 4.0 and 4.1 before 4.1 P22, and 4.2 before P11 allows … Documentum D2 Mitigation only Fix from $1,9502015-02-14 HIGH 7.2 CVE-2014-6185 dsmtca in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.2.3, 6.4 before 6.4.2.2, and 7.1 before 7.1.1.3 does not properly restrict sh… Tivoli Storage Manager Patch available Fix from $1,9502015-02-13 MEDIUM 5.0 CVE-2015-0227EPSS 8% Apache WSS4J before 1.6.17 and 2.x before 2.0.2 allows remote attackers to bypass the requireSignedEncryptedDataElements configuration via a vectors … Wss4j after 1.6.16 Fix from $1,6002015-02-12 MEDIUM 6.5 CVE-2015-0611 The administrative web-management portal in Cisco IX 8 (.0.1) and earlier on Cisco TelePresence IX5000 devices does not properly restrict the device-… Telepresence System Software Ix Mitigation only Fix from $1,6002015-02-12 HIGH 7.2 CVE-2015-0062 Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local… Windows 7 Patch available Fix from $1,9502015-02-11 MEDIUM 6.9 CVE-2015-0059EPSS 11% win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2… Windows 7 Patch available Fix from $1,6002015-02-11 HIGH 7.2 CVE-2015-0057EPSS 13% win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… Windows 7 Patch available Fix from $1,9502015-02-11 MEDIUM 6.9 CVE-2015-0012 Microsoft System Center Virtual Machine Manager (VMM) 2012 R2 Update Rollup 4 does not properly validate the roles of users, which allows local users… Virtual Machine Manager Patch available Fix from $1,6002015-02-11 MEDIUM 5.0 CVE-2014-9675 bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers… Ubuntu Linux No fix yet Fix from $1,6002015-02-08 MEDIUM 6.9 CVE-2015-1305 McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privilege… Data Loss Prevention Endpoint after 9.3.300 Fix from $1,6002015-02-06