Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.5 CVE-2014-7837 mod/wiki/admin.php in Moodle through 2.4.11, 2.5.x before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3 allows remote authenticated users to remo… Moodle after 2.4.11 Fix from $1,6002014-11-24 MEDIUM 5.0 CVE-2014-8000 Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a user… Unified Communications Manager Im And Presence Service Mitigation only Fix from $1,6002014-11-21 MEDIUM 6.4 CVE-2014-7194 TIBCO Managed File Transfer Internet Server before 7.2.4, Managed File Transfer Command Center before 7.2.4, Slingshot before 1.9.3, and Vault before… Managed File Transfer Internet Server after 7.2.3 Fix from $1,6002014-11-21 HIGH 7.5 CVE-2014-9024 The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path. Protected Pages Patch available Fix from $1,9502014-11-20 MEDIUM 5.5 CVE-2014-9023 The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authent… Twilio Mitigation only Fix from $1,6002014-11-20 MEDIUM 6.4 CVE-2014-9022 The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" rest… Web Component Roles Patch available Fix from $1,6002014-11-20 MEDIUM 5.0 CVE-2014-8493EPSS 8% ZTE ZXHN H108L with firmware 4.0.0d_ZRQ_GR4 allows remote attackers to modify the CWMP configuration via a crafted request to Forms/access_cwmp_1. Zxhn H108l Firmware No fix yet Fix from $1,6002014-11-20 HIGH 10.0 CVE-2014-9002EPSS 5% Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in … Xprintserver Mitigation only Fix from $1,9502014-11-20 MEDIUM 6.5 CVE-2014-9000EPSS 9% Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to… Mule Enterprise Management Console No fix yet Fix from $1,6002014-11-20 HIGH 7.5 CVE-2014-4457 The Sandbox Profiles subsystem in Apple iOS before 8.1.1 does not properly implement the debugserver sandbox, which allows attackers to bypass intend… Iphone Os after 8.1 Fix from $1,9502014-11-18 HIGH 7.2 CVE-2014-4451 Apple iOS before 8.1.1 does not properly enforce the failed-passcode limit, which makes it easier for physically proximate attackers to bypass the lo… Iphone Os after 8.1 Fix from $1,9502014-11-18 MEDIUM 5.0 CVE-2014-2268EPSS 31% views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which allows remote attackers to re-in… Vtiger Crm No fix yet Fix from $1,6002014-11-16 MEDIUM 6.4 CVE-2014-2684 The GenericConsumer class in the Consumer component in ZendOpenId before 2.0.2 and the Zend_OpenId_Consumer class in Zend Framework 1 before 1.12.4 d… Zendopenid after 2.0.1 Fix from $1,6002014-11-16 HIGH 7.1 CVE-2014-7998 Cisco IOS on Aironet access points, when "dot11 aaa authenticator" debugging is enabled, allows remote attackers to cause a denial of service via a m… iOS Mitigation only Fix from $1,9502014-11-15 HIGH 7.5 CVE-2014-5424EPSS 11% Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or p… Connected Components Workbench after 6.01.00 Fix from $1,9502014-11-14 HIGH 7.2 CVE-2014-8359 Untrusted search path vulnerability in Huawei Mobile Partner for Windows 23.009.05.03.1014 allows local users to execute arbitrary code and conduct D… Mobile Partner Firmware No fix yet Fix from $1,9502014-11-13 HIGH 7.5 CVE-2014-3674 Red Hat OpenShift Enterprise before 2.2 does not properly restrict access to gears, which allows remote attackers to access the network resources of … Openshift after 2.1.8 Fix from $1,9502014-11-13 HIGH 7.5 CVE-2014-8442EPSS 5% Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.… Flash Player 11.2.202.418 / 13.0.0.252+ Fix from $1,9502014-11-11 MEDIUM 5.0 CVE-2014-6331EPSS 20% Microsoft Active Directory Federation Services (AD FS) 2.0, 2.1, and 3.0, when a configured SAML Relying Party lacks a sign-out endpoint, does not pr… Active Directory Federation Services Mitigation only Fix from $1,6002014-11-11 MEDIUM 5.1 CVE-2014-4078EPSS 20% The IP Security feature in Microsoft Internet Information Services (IIS) 8.0 and 8.5 does not properly process wildcard allow and deny rules for doma… Internet Information Services Mitigation only Fix from $1,6002014-11-11 MEDIUM 5.0 CVE-2014-8655EPSS 7% The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH allows remote attackers to bypass aut… Firmware No fix yet Fix from $1,6002014-11-06 HIGH 7.2 CVE-2014-5507 iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Tr… Ibackup after 10.0.0.32 Fix from $1,9502014-11-03 MEDIUM 5.0 CVE-2014-7986 install/index.php in EspoCRM before 2.6.0 allows remote attackers to re-install the application via a 1 value in the installProcess parameter. Espocrm after 2.5.2 Fix from $1,6002014-10-31 MEDIUM 6.8 CVE-2014-3684 The tm_adopt function in lib/Libifl/tm.c in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 5.0.x, 4.5.x, 4.2.x, and e… Torque Resource Manager Mitigation only Fix from $1,6002014-10-30 MEDIUM 5.0 CVE-2013-6796EPSS 6% The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous … Deepofix after 3.3 Fix from $1,6002014-10-26 MEDIUM 5.0 CVE-2014-4624 EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which a… 6.0 No fix yet Fix from $1,6002014-10-25 MEDIUM 5.0 CVE-2012-5243 functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request. Banana Dance No fix yet Fix from $1,6002014-10-21 MEDIUM 5.0 CVE-2012-5696 Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 does not properly restrict access to frameworkgui/config, which allows remote attackers… Smartphone Pentest Framework after 0.1.2 Fix from $1,6002014-10-20 MEDIUM 5.0 CVE-2014-3381 The ZIP inspection engine in Cisco AsyncOS 8.5 and earlier on the Cisco Email Security Appliance (ESA) does not properly analyze ZIP archives, which … Asyncos after 8.5 Fix from $1,6002014-10-19 HIGH 7.5 CVE-2014-4427 App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API. Mac Os X after 10.9.5 Fix from $1,9502014-10-18