Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.5 CVE-2014-4844 The import/export functionality in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5 allows re… Business Process Manager Mitigation only Fix from $1,6002014-12-17 HIGH 10.0 CVE-2014-9357EPSS 6% Docker 1.3.2 allows remote attackers to execute arbitrary code with root privileges via a crafted (1) image or (2) build in a Dockerfile in an LZMA (… Docker Mitigation only Fix from $1,9502014-12-16 HIGH 7.5 CVE-2014-9249 The default configuration of Zenoss Core before 5 allows remote attackers to read or modify database information by connecting to unspecified open po… Zenoss Core after 4.2.5 Fix from $1,9502014-12-15 HIGH 7.2 CVE-2014-8609 The addAccount method in src/com/android/settings/accounts/AddAccountSettings.java in the Settings application in Android before 5.0.0 does not prope… Android after 4.4.4 Fix from $1,9502014-12-15 HIGH 7.2 CVE-2014-7911EPSS 25% luni/src/main/java/java/io/ObjectInputStream.java in the java.io.ObjectInputStream implementation in Android before 5.0.0 does not verify that deseri… Android after 4.4.4 Fix from $1,9502014-12-15 MEDIUM 5.0 CVE-2014-6257 Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions by using a web-endpoint URL to invoke an object helper me… Zenoss Core after 5.0.0 Fix from $1,6002014-12-15 HIGH 7.5 CVE-2014-6256 Zenoss Core through 5 Beta 3 allows remote attackers to bypass intended access restrictions and place files in a directory with public (1) read or (2… Zenoss Core after 5.0.0 Fix from $1,9502014-12-15 MEDIUM 5.0 CVE-2014-6408 Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applyin… Docker Mitigation only Fix from $1,6002014-12-12 MEDIUM 5.0 CVE-2014-8270EPSS 20% BMC Track-It! 11.3 allows remote attackers to gain privileges and execute arbitrary code by creating an account whose name matches that of a local sy… Track It\! Mitigation only Fix from $1,6002014-12-12 HIGH 9.0 CVE-2014-8373 The VMware Remote Console (VMRC) function in VMware vCloud Automation Center (vCAC) 6.0.1 through 6.1.1 allows remote authenticated users to gain pri… Vcloud Automation Center No fix yet Fix from $1,9502014-12-11 MEDIUM 5.0 CVE-2014-8453EPSS 13% Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow remote attackers to bypass the Same Origin Policy via … Acrobat Mitigation only Fix from $1,6002014-12-10 HIGH 7.5 CVE-2014-9304EPSS 8% Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrati… Media Server after 0.9.9.2 Fix from $1,9502014-12-07 HIGH 7.8 CVE-2014-8868EPSS 7% EntryPass N5200 Active Network Control Panel does not properly restrict access, which allows remote attackers to obtain the administrator username an… N5200 Active Network Control Panel No fix yet Fix from $1,9502014-12-07 HIGH 7.2 CVE-2014-8651 The KDE Clock KCM policykit helper in kde-workspace before 4.11.14 and plasma-desktop before 5.1.1 allows local users to gain privileges via a crafte… Plasma Desktop after 5.1 Fix from $1,9502014-12-06 HIGH 9.0 CVE-2014-4629 EMC Documentum Content Server 7.0, 7.1 before 7.1 P10, and 6.7 before SP2 P19 allows remote authenticated users to read or delete arbitrary files via… Documentum Content Server No fix yet Fix from $1,9502014-12-06 HIGH 7.2 CVE-2014-2273 The hx170dec device driver in Huawei P2-6011 before V100R001C00B043 allows local users to read and write to arbitrary memory locations via unspecifie… P2 6011 Firmware No fix yet Fix from $1,9502014-12-05 HIGH 7.2 CVE-2014-9141 The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute ar… Fixed Assets Cs after 13.1.4 Fix from $1,9502014-12-03 HIGH 7.2 CVE-2014-9113 CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the… Prosystem Fx Engagement after 7.1 Fix from $1,9502014-12-02 HIGH 7.2 CVE-2014-5284 host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modi… Ossec after 2.8.0 Fix from $1,9502014-12-02 MEDIUM 5.0 CVE-2014-3703 OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration … Packstack Mitigation only Fix from $1,6002014-12-02 MEDIUM 5.8 CVE-2014-5268 The Fasttoggle module 7.x-1.3 and 7.x-1.4 for Drupal allows remote attackers to block or unblock an account via a crafted user status link. Fasttoggle Patch available Fix from $1,6002014-12-01 HIGH 7.2 CVE-2014-8419 Wibu-Systems CodeMeter Runtime before 5.20 uses weak permissions (read and write access for all users) for codemeter.exe, which allows local users to… Codemeter Runtime after 5.10c Fix from $1,9502014-11-26 MEDIUM 6.5 CVE-2014-8558 JExperts Channel Platform 5.0.33_CCB allows remote authenticated users to bypass access restrictions via crafted action and key parameters. Channel Platform No fix yet Fix from $1,6002014-11-25 HIGH 9.0 CVE-2014-8368 The web interface in Aruba Networks AirWave before 7.7.14 and 8.x before 8.0.5 allows remote authenticated users to gain privileges and execute arbit… Airwave 7.7.14 / 8.0.5+ Fix from $1,9502014-11-25 MEDIUM 6.8 CVE-2014-9015 Drupal 6.x before 6.34 and 7.x before 7.34 allows remote attackers to hijack sessions via a crafted request, as demonstrated by a crafted request to … Drupal 6.34 / 7.34+ Fix from $1,6002014-11-24 HIGH 9.0 CVE-2014-8418 The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified … Certified Asterisk 11.14.1 / 12.7.1+ Fix from $1,9502014-11-24 MEDIUM 6.5 CVE-2014-8417 ConfBridge in Asterisk 11.x before 11.14.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 11.6 before 11.6-cert8 allows remote au… Asterisk 11.14.1 / 12.7.1+ Fix from $1,6002014-11-24 HIGH 7.5 CVE-2014-8413 The res_pjsip_acl module in Asterisk Open Source 12.x before 12.7.1 and 13.x before 13.0.1 does not properly create and load ACLs defined in pjsip.co… Asterisk 12.7.1 / 13.0.1+ Fix from $1,9502014-11-24 MEDIUM 5.0 CVE-2014-8412 The (1) VoIP channel drivers, (2) DUNDi, and (3) Asterisk Manager Interface (AMI) in Asterisk Open Source 1.8.x before 1.8.32.1, 11.x before 11.14.1,… Certified Asterisk 1.8.32.1 / 11.14.1+ Fix from $1,6002014-11-24 MEDIUM 6.4 CVE-2014-1424 apparmor_parser in the apparmor package before 2.8.95~2430-0ubuntu5.1 in Ubuntu 14.04 allows attackers to bypass AppArmor policies via unspecified ve… Apparmor after 2.8.94-0ubuntu1.4 Fix from $1,6002014-11-24