Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2014-4437 LaunchServices in Apple OS X before 10.10 allows attackers to bypass intended sandbox restrictions via an application that specifies a crafted handle… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.8 CVE-2014-4441 NetFS Client Framework in Apple OS X before 10.10 does not ensure that the disabling of File Sharing is always possible, which allows remote attacker… Mac Os X after 10.9.5 Fix from $1,6002014-10-18 MEDIUM 6.5 CVE-2014-6283 SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, whi… Adaptive Server Enterprise No fix yet Fix from $1,6002014-10-17 MEDIUM 6.5 CVE-2014-2058 BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary job… Jenkins after 1.550 Fix from $1,6002014-10-17 MEDIUM 6.0 CVE-2014-3663 Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and c… Jenkins after 3.1 Fix from $1,6002014-10-16 MEDIUM 6.8 CVE-2014-7237EPSS 20% lib/TWiki/Sandbox.pm in TWiki 6.0.0 and earlier, when running on Windows, allows remote attackers to bypass intended access restrictions and upload f… Twiki after 6.0.0 Fix from $1,6002014-10-16 HIGH 10.0 CVE-2014-4073EPSS 23% Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, and 4.5.2 processes unverified data during interaction with the ClickOnce installer, whi… .net Framework Mitigation only Fix from $1,9502014-10-15 HIGH 7.5 CVE-2014-1575EPSS 5% Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 33.0 allow remote attackers to cause a denial of service (memory… Firefox after 32.0 Fix from $1,9502014-10-15 MEDIUM 5.0 CVE-2014-1572 The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before … Fedora Patch available Fix from $1,6002014-10-13 MEDIUM 6.8 CVE-2014-4867 Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging acces… Cryoserver Security Appliance Mitigation only Fix from $1,6002014-10-10 MEDIUM 5.0 CVE-2014-5298 FileUploadsFilter.php in X2Engine 4.1.7 and earlier, when running on case-insensitive file systems, allows remote attackers to bypass the upload blac… X2engine after 4.1.7 Fix from $1,6002014-10-10 HIGH 7.2 CVE-2014-2646 Unspecified vulnerability in HP Network Automation 9.10 and 9.20 allows local users to bypass intended access restrictions via unknown vectors. Network Automation Mitigation only Fix from $1,9502014-10-10 HIGH 7.5 CVE-2014-7984 Joomla! CMS 2.5.x before 2.5.19 and 3.x before 3.2.3 allows remote attackers to authenticate and bypass intended restrictions via vectors involving G… Joomla\! Mitigation only Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-3189 The chrome_pdf::CopyImage function in pdf/draw_utils.cc in the PDFium component in Google Chrome before 38.0.2125.101 does not properly validate imag… Chrome after 38.0.2125.7 Fix from $1,9502014-10-08 HIGH 7.5 CVE-2014-3196 base/memory/shared_memory_win.cc in Google Chrome before 38.0.2125.101 on Windows does not properly implement read-only restrictions on shared memory… Chrome after 38.0.2125.7 Fix from $1,9502014-10-08 MEDIUM 5.0 CVE-2014-3197 The NavigationScheduler::schedulePageBlock function in core/loader/NavigationScheduler.cpp in Blink, as used in Google Chrome before 38.0.2125.101, d… Chrome after 38.0.2125.7 Fix from $1,6002014-10-08 HIGH 7.6 CVE-2014-3632 The default configuration in a sudoers file in the Red Hat openstack-neutron package before 2014.1.2-4, as used in Red Hat Enterprise Linux Open Stac… Neutron after 2014.1.2 Fix from $1,9502014-10-07 MEDIUM 5.0 CVE-2014-4869 The Brocade Vyatta 5400 vRouter 6.4R(x), 6.6R(x), and 6.7R1 allows attackers to obtain sensitive encrypted-password information by leveraging members… Vyatta 5400 Vrouter Software Mitigation only Fix from $1,6002014-10-07 MEDIUM 6.5 CVE-2014-3642 vmdb/app/controllers/application_controller/performance.rb in Red Hat CloudForms 3.1 Management Engine (CFME) before 5.3 allows remote authenticated … Cloudforms 3.0.1 Management Engine after 5.2.5 Fix from $1,6002014-10-06 MEDIUM 5.5 CVE-2014-3521 The component in (1) /luci/homebase and (2) /luci/cluster menu in Red Hat Conga 0.12.2 allows remote authenticated users to bypass intended access re… Conga Mitigation only Fix from $1,6002014-10-06 HIGH 7.5 CVE-2014-3396 Cisco IOS XR on ASR 9000 devices does not properly use compression for port-range and address-range encoding, which allows remote attackers to bypass… Ios Xr Mitigation only Fix from $1,9502014-10-05 HIGH 7.5 CVE-2014-6288 The powermail extension 2.x before 2.0.11 for TYPO3 allows remote attackers to bypass the CAPTCHA protection mechanism via unspecified vectors. Powermail Mitigation only Fix from $1,9502014-10-03 HIGH 7.5 CVE-2014-6289 The Ajax dispatcher for Extbase in the Yet Another Gallery (yag) extension before 3.0.1 and Tools for Extbase development (pt_extbase) extension befo… Yet Another Gallery after 3.0.0 Fix from $1,9502014-10-03 MEDIUM 5.8 CVE-2014-7155 The x86_emulate function in arch/x86/x86_emulate/x86_emulate.c in Xen 4.4.x and earlier does not properly check supervisor mode permissions, which al… Debian Linux after 4.4.0 Fix from $1,6002014-10-02 MEDIUM 6.5 CVE-2014-4793 IBM WebSphere MQ 8.x before 8.0.0.1 does not properly enforce CHLAUTH rules for blocking client connections in certain circumstances related to the C… Websphere Mq Patch available Fix from $1,6002014-10-02 MEDIUM 5.0 CVE-2014-3558 ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 … Hibernate Validator 4.3.2 / 5.1.2+ Fix from $1,6002014-09-30 MEDIUM 6.8 CVE-2014-5267 modules/openid/xrds.inc in Drupal 6.x before 6.33 and 7.x before 7.31 allows remote attackers to have unspecified impact via a crafted DOCTYPE declar… Drupal Patch available Fix from $1,6002014-09-30 MEDIUM 6.5 CVE-2012-5489 The App.Undo.UndoSupport.get_request_var_or_attr function in Zope before 2.12.21 and 3.13.x before 2.13.11, as used in Plone before 4.2.3 and 4.3 bef… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5498 queryCatalog.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to bypass caching and cause a denial of service via a crafted req… Plone after 4.2.2 Fix from $1,6002014-09-30 MEDIUM 5.0 CVE-2012-5501 at_download.py in Plone before 4.2.3 and 4.3 before beta 1 allows remote attackers to read arbitrary BLOBs (Files and Images) stored on custom conten… Plone after 4.2.2 Fix from $1,6002014-09-30