Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 8.5 CVE-2012-5487 The sandbox whitelisting function (allowmodule.py) in Plone before 4.2.3 and 4.3 before beta 1 allows remote authenticated users with certain privile… Plone after 4.2.2 Fix from $1,9502014-09-30 HIGH 7.1 CVE-2013-3066 Linksys EA6500 with firmware 1.1.28.147876 does not properly restrict access, which allows remote attackers to obtain sensitive information (clients … Ea6500 Firmware No fix yet Fix from $1,9502014-09-29 HIGH 8.8 CVE-2013-3632EPSS 57% The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary command… Openmediavault No fix yet Fix from $1,9502014-09-29 HIGH 7.2 CVE-2014-3811 Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via uns… Juniper Installer Service Client after 4.0 Fix from $1,9502014-09-29 MEDIUM 5.8 CVE-2014-5318 The jigbrowser+ application 1.8.1 and earlier for iOS allows remote attackers to bypass the Same Origin Policy via crafted JavaScript code. Jigbrowser\+ after 1.8.1 Fix from $1,6002014-09-26 HIGH 7.2 CVE-2014-0484 The Debian acpi-support package before 0.140-5+deb7u3 allows local users to gain privileges via vectors related to the "user's environment." Acpi Support No fix yet Fix from $1,9502014-09-22 MEDIUM 6.6 CVE-2014-6602 Microsoft Asha OS on the Microsoft Mobile Nokia Asha 501 phone 14.0.4 allows physically proximate attackers to bypass the lock-screen protection mech… Nokia Asha 501 Software No fix yet Fix from $1,6002014-09-22 MEDIUM 5.0 CVE-2014-5412 Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access… Clearscada Mitigation only Fix from $1,6002014-09-18 MEDIUM 6.9 CVE-2014-4368 The Accessibility subsystem in Apple iOS before 8 allows attackers to interfere with screen locking via vectors related to AssistiveTouch events. Iphone Os after 7.1.2 Fix from $1,6002014-09-18 MEDIUM 6.8 CVE-2014-2886 GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrar… Gksu No fix yet Fix from $1,6002014-09-18 MEDIUM 5.8 CVE-2014-4354 Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions vi… Iphone Os after 7.1.2 Fix from $1,6002014-09-18 HIGH 8.5 CVE-2014-4621 EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subtypes of protected… Documentum Content Server after 6.7 Fix from $1,9502014-09-17 HIGH 7.1 CVE-2014-4622 EMC Documentum Content Server before 6.7 SP2 P17, 7.0 through P15, and 7.1 before P08 does not properly check authorization for subgroups of privileg… Documentum Content Server after 6.7 Fix from $1,9502014-09-17 HIGH 9.0 CVE-2014-2375 Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to read or write to arbitrary files, … Integraxor after 4.1.4392 Fix from $1,9502014-09-15 MEDIUM 6.5 CVE-2014-6043EPSS 13% ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote … Manageengine Eventlog Analyzer No fix yet Fix from $1,6002014-09-11 HIGH 7.2 CVE-2014-4074 The Task Scheduler in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privi… Windows 8 Patch available Fix from $1,9502014-09-10 HIGH 10.0 CVE-2014-0557EPSS 5% Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.… Flash Player after 14.0.0.179 Fix from $1,9502014-09-10 HIGH 7.5 CVE-2014-0548 Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.… Adobe Air after 14.0.0.179 Fix from $1,9502014-09-10 MEDIUM 5.0 CVE-2014-0877 IBM Cognos TM1 10.2.0.2 before IF1 and 10.2.2.0 before IF1 allows remote attackers to bypass intended access restrictions by visiting the Rights page… Cognos Tm1 Patch available Fix from $1,6002014-09-05 MEDIUM 5.0 CVE-2014-5269 Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of genera… Plack after 1.0030 Fix from $1,6002014-09-04 MEDIUM 5.8 CVE-2014-6041EPSS 18% The Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a \u0000 charac… Android Browser No fix yet Fix from $1,6002014-09-02 HIGH 7.2 CVE-2013-2595 The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) And… Android Msm Mitigation only Fix from $1,9502014-08-31 MEDIUM 5.0 CVE-2014-5337EPSS 17% The WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows remote attack… Wordpress Mobile Pack after 2.0.1 Fix from $1,6002014-08-29 HIGH 9.0 CVE-2014-2593 The management console in Aruba Networks ClearPass Policy Manager 6.3.0.60730 allows local users to execute arbitrary commands via shell metacharacte… Clearpass Policy Manager Mitigation only Fix from $1,9502014-08-29 HIGH 7.2 CVE-2013-5467 Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shar… Monitoring Agent For Unix Logs Mitigation only Fix from $1,9502014-08-29 MEDIUM 5.0 CVE-2014-3345 The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check … Transport Gateway Installation Software Mitigation only Fix from $1,6002014-08-28 MEDIUM 6.4 CVE-2014-3170 extensions/common/url_pattern.cc in Google Chrome before 37.0.2062.94 does not prevent use of a '\0' character in a host name, which allows remote at… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 MEDIUM 6.4 CVE-2014-3172 The Debugger extension API in browser/extensions/api/debugger/debugger_api.cc in Google Chrome before 37.0.2062.94 does not validate a tab's URL befo… Chrome after 37.0.2062.93 Fix from $1,6002014-08-27 HIGH 7.2 CVE-2014-5453 Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game … Uplay Pc after 4.6.3208 Fix from $1,9502014-08-25 HIGH 10.0 CVE-2014-5246EPSS 12% The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator acces… A5s Firmware Mitigation only Fix from $1,9502014-08-22