Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2014-9494 RabbitMQ before 3.4.0 allows remote attackers to bypass the loopback_users restriction via a crafted X-Forwareded-For header. Rabbitmq after 3.3.5 Fix from $1,6002015-01-20 MEDIUM 5.0 CVE-2014-3019 IBM BladeCenter SAS Connectivity Module (aka NSSM) and SAS RAID Module (aka RSSM) before 1.3.3.006 allow remote attackers to obtain blade and storage… Sas Raid Module Firmware after 1.3.3.004 Fix from $1,6002015-01-17 HIGH 8.5 CVE-2014-8143 Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows rem… Samba Patch available Fix from $1,9502015-01-17 MEDIUM 6.5 CVE-2015-1029 The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 through 4.5.x before 4.5.1 for Puppet 2.8.8 and earlier allows remote authenticated users to g… Stdlib Mitigation only Fix from $1,6002015-01-16 MEDIUM 5.0 CVE-2014-9476 MediaWiki 1.2x before 1.22.15, 1.23.x before 1.23.8, and 1.24.x before 1.24.1 allows remote attackers to bypass CORS restrictions in $wgCrossSiteAJAX… Mediawiki after 1.19.22 Fix from $1,6002015-01-16 MEDIUM 6.9 CVE-2014-6384 Juniper Junos 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D25, 12.1X47 before 12.1X47-D15, 12.3 before 12.3R9, 13.1 before 13.1R4-S3, 13.2 bef… Junos Mitigation only Fix from $1,6002015-01-16 HIGH 7.2 CVE-2014-8904 lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variab… Vios No fix yet Fix from $1,9502015-01-15 HIGH 7.1 CVE-2014-8643 Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging acce… Firefox after 34.0.5 Fix from $1,9502015-01-14 MEDIUM 6.1 CVE-2015-0006EPSS 12% The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 S… Windows 7 Mitigation only Fix from $1,6002015-01-13 HIGH 7.2 CVE-2015-0004 The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Wi… Windows 7 No fix yet Fix from $1,9502015-01-13 HIGH 7.2 CVE-2015-0002EPSS 14% The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, … Windows 7 No fix yet Fix from $1,9502015-01-13 HIGH 7.2 CVE-2013-2604 RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for t… Realarcade Installer Mitigation only Fix from $1,9502015-01-12 MEDIUM 6.5 CVE-2014-8027 The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges fo… Secure Access Control System Mitigation only Fix from $1,6002015-01-09 HIGH 10.0 CVE-2014-9583EPSS 80% common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC66U, RT-N66U, and other route… Tm Ac1900 Mitigation only Fix from $1,9502015-01-08 MEDIUM 6.4 CVE-2014-9575 VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin … Vdg Sense after 2.3.14 Fix from $1,6002015-01-08 MEDIUM 5.5 CVE-2014-9493 The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.2.2 and 2014.1.4 allows remote authenticated users to read or delete… Openstack 2014.1.4 / 2014.2.2+ Fix from $1,6002015-01-07 MEDIUM 6.4 CVE-2011-5294 The SaveMessage method in the LEADeMail.LEADSmtp.20 ActiveX control in LTCML14n.dll 14.0.0.34 in Kofax e-Transactions Sender Sendbox 2.5.0.933 allows… Kofax E Transactions Sender Sendbox No fix yet Fix from $1,6002015-01-01 HIGH 7.5 CVE-2011-5292 The EaseWeFtp.FtpLibrary ActiveX control in EaseWeFtp.ocx in Easewe FTP OCX 4.5.0.9 does not restrict access to certain methods, which allows remote … Easewe Ftp Ocx Activex Control No fix yet Fix from $1,9502015-01-01 MEDIUM 6.4 CVE-2011-5291 The SaveData method in the Cygnicon.ViewControl.1 ActiveX control in CyViewer.ocx in Ashampoo 3D CAD Professional 3.x before 3.0.2 allows remote atta… Ashampoo 3d Cad Professional 3 No fix yet Fix from $1,6002015-01-01 MEDIUM 6.4 CVE-2011-5290 The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100_EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attacker… Idrive Online Backup No fix yet Fix from $1,6002015-01-01 MEDIUM 6.4 CVE-2011-5289 The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers t… Atube Catcher No fix yet Fix from $1,6002015-01-01 MEDIUM 5.0 CVE-2014-2209 Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-… Hiphop Virtual Machine after 3.0.1 Fix from $1,6002014-12-28 HIGH 7.7 CVE-2014-7999 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unsp… Meraki Mr Firmware after 2014-09-24 Fix from $1,9502014-12-24 HIGH 7.2 CVE-2014-7995 Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's… Meraki Mx Firmware after 2014-09-24 Fix from $1,9502014-12-24 MEDIUM 5.5 CVE-2014-6122 IBM Security AppScan Enterprise 8.5 before 8.5 IFix 002, 8.6 before 8.6 IFix 004, 8.7 before 8.7 IFix 004, 8.8 before 8.8 iFix 003, 9.0 before 9.0.0.… Security Appscan Mitigation only Fix from $1,6002014-12-23 HIGH 9.0 CVE-2014-9193 Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP conf… Mguard Firmware after 7.6.6 Fix from $1,9502014-12-20 MEDIUM 6.0 CVE-2014-9324 The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access a… Otrs Help Desk Mitigation only Fix from $1,6002014-12-19 MEDIUM 5.1 CVE-2014-8890 IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a s… Websphere Application Server Mitigation only Fix from $1,6002014-12-18 HIGH 10.0 CVE-2014-9387 SAP BusinessObjects Edge 4.1 allows remote attackers to obtain the SI_PLATFORM_SEARCH_SERVER_LOGON_TOKEN token and gain privileges via a crafted CORB… Businessobjects Mitigation only Fix from $1,9502014-12-17 HIGH 9.0 CVE-2014-4626 EMC Documentum Content Server before 6.7 SP1 P29, 6.7 SP2 before P18, 7.0 before P16, and 7.1 before P09 allows remote authenticated users to gain pr… Documentum Content Server after 6.7 Fix from $1,9502014-12-17