Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.0 CVE-2014-2227 The default Flash cross-domain policy (crossdomain.xml) in Ubiquiti Networks UniFi Video (formerly AirVision aka AirVision Controller) before 3.0.1 d… Unifi Video after 2.1.3 Fix from $1,6002014-07-25 MEDIUM 5.0 CVE-2014-5015 bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote att… Bozohttpd after 20140201 Fix from $1,6002014-07-24 MEDIUM 6.0 CVE-2014-4684 The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via… Simatic Pcs7 after 8.0 Fix from $1,6002014-07-24 MEDIUM 5.8 CVE-2014-1552 Mozilla Firefox before 31.0 and Thunderbird before 31.0 do not properly implement the sandbox attribute of the IFRAME element, which allows remote at… Firefox after 30.0 Fix from $1,6002014-07-23 MEDIUM 5.8 CVE-2014-1561 Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to al… Firefox after 30.0 Fix from $1,6002014-07-23 MEDIUM 6.8 CVE-2014-3160 The ResourceFetcher::canRequest function in core/fetch/ResourceFetcher.cpp in Blink, as used in Google Chrome before 36.0.1985.125, does not properly… Debian Linux Mitigation only Fix from $1,6002014-07-20 HIGH 7.5 CVE-2014-3161 The WebMediaPlayerAndroid::load function in content/renderer/media/android/webmediaplayer_android.cc in Google Chrome before 36.0.1985.122 on Android… Chrome after 36.0.1985.106 Fix from $1,9502014-07-20 HIGH 7.5 CVE-2014-1996 Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial o… Garoon Mitigation only Fix from $1,9502014-07-20 MEDIUM 5.0 CVE-2013-7391 The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restrict… Entity Api after 7.x-1.1 Fix from $1,6002014-07-19 MEDIUM 6.5 CVE-2014-3043 IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.3.3 allows remote authenticated users to gain privileges by leveraging access to the service ac… Storwize Unified V7000 Software Mitigation only Fix from $1,6002014-07-19 MEDIUM 5.5 CVE-2014-4976 Dell SonicWall Scrutinizer 11.0.1 allows remote authenticated users to change user passwords via the user ID in the savePrefs parameter in a change p… Scrutinizer No fix yet Fix from $1,6002014-07-16 MEDIUM 5.0 CVE-2014-4154EPSS 7% ZTE ZXV10 W300 router with firmware W300V1.0.0a_ZRD_LK stores sensitive information under the web root with insufficient access control, which allows… Zxv10 W300 Firmware No fix yet Fix from $1,6002014-07-16 HIGH 9.0 CVE-2014-3816 Juniper Junos 11.4 before 11.4R12, 12.1 before 12.1R11, 12.1X44 before 12.1X44-D35, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D20, 12.1X47 b… Junos Mitigation only Fix from $1,9502014-07-11 HIGH 7.2 CVE-2014-3499 Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified… Docker Mitigation only Fix from $1,9502014-07-11 MEDIUM 5.0 CVE-2014-3309 The NTP implementation in Cisco IOS and IOS XE does not properly support use of the access-group command for a "deny all" configuration, which allows… iOS Mitigation only Fix from $1,6002014-07-09 HIGH 7.5 CVE-2014-0537 Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on … Adobe Air Sdk after 14.0.0.110 Fix from $1,9502014-07-09 HIGH 7.5 CVE-2014-0539 Adobe Flash Player before 13.0.0.231 and 14.x before 14.0.0.145 on Windows and OS X and before 11.2.202.394 on Linux, Adobe AIR before 14.0.0.137 on … Adobe Air after 14.0.0.110 Fix from $1,9502014-07-09 HIGH 7.6 CVE-2014-2781EPSS 6% Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows … Windows 7 Patch available Fix from $1,9502014-07-08 HIGH 9.3 CVE-2014-2956 ScriptHelperApi in the AVG ScriptHelper ActiveX control in ScriptHelper.exe in AVG Secure Search toolbar before 18.1.7.598 and AVG Safeguard before 1… Safeguard after 18.1.7 Fix from $1,9502014-07-08 HIGH 7.5 CVE-2014-3300EPSS 22% The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not p… Unified Cdm Application Software after 8.1.4 Fix from $1,9502014-07-07 HIGH 9.0 CVE-2014-2197 The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 doe… Unified Cdm Application Software after 8.1 Fix from $1,9502014-07-07 HIGH 7.2 CVE-2014-3074 The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, b… Vios No fix yet Fix from $1,9502014-07-02 MEDIUM 5.5 CVE-2014-3088 stconf.nsf in IBM Sametime Meeting Server 8.5.1 relies on the client to validate the file format used in wAttach?OpenForm multipart/form-data POST re… Sametime Meeting Server No fix yet Fix from $1,6002014-07-01 HIGH 10.0 CVE-2014-1373 Intel Graphics Driver in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenGL API call, which allows attackers to execute arbitr… Mac Os X after 10.9.3 Fix from $1,9502014-07-01 HIGH 10.0 CVE-2014-1376 Intel Compute in Apple OS X before 10.9.4 does not properly restrict an unspecified OpenCL API call, which allows attackers to execute arbitrary code… Mac Os X after 10.9.3 Fix from $1,9502014-07-01 HIGH 10.0 CVE-2014-1381 Thunderbolt in Apple OS X before 10.9.4 does not properly restrict IOThunderBoltController API calls, which allows attackers to execute arbitrary cod… Mac Os X Mitigation only Fix from $1,9502014-07-01 MEDIUM 5.5 CVE-2014-1383 Apple TV before 6.1.2 allows remote authenticated users to bypass an intended password requirement for iTunes Store purchase transactions via unspeci… Tvos after 6.1.1 Fix from $1,6002014-07-01 MEDIUM 6.4 CVE-2011-1381 Unspecified vulnerability in IBM OpenPages GRC Platform 6.1.0.1 before IF4 allows remote attackers to bypass intended access restrictions via unknown… Openpages Grc Platform Mitigation only Fix from $1,6002014-06-27 MEDIUM 6.2 CVE-2014-4014 The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows… Linux Kernel 3.14.8+ Fix from $1,6002014-06-23 MEDIUM 6.6 CVE-2014-0960 IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictio… Pureapplication System Mitigation only Fix from $1,6002014-06-14