Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2013-5356 Sharetronix 3.1.1.3, 3.1.1, and earlier does not properly restrict access to unspecified AJAX functionality, which allows remote attackers to bypass … Sharetronix after 3.1.1 Fix from $1,9502014-06-13 MEDIUM 5.8 CVE-2013-2182EPSS 6% The Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a crafted URI, as … Monkey after 1.4.0 Fix from $1,6002014-06-13 HIGH 7.5 CVE-2014-0534EPSS 6% Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Ad… Flash Player after 13.0.0.214 Fix from $1,9502014-06-11 HIGH 7.5 CVE-2014-0535EPSS 10% Adobe Flash Player before 13.0.0.223 and 14.x before 14.0.0.125 on Windows and OS X and before 11.2.202.378 on Linux, Adobe AIR before 14.0.0.110, Ad… Adobe Air Sdk after 13.0.0.111 Fix from $1,9502014-06-11 HIGH 7.2 CVE-2013-6825 (1) movescu.cc and (2) storescp.cc in dcmnet/apps/, (3) dcmnet/libsrc/scp.cc, (4) dcmwlm/libsrc/wlmactmg.cc, (5) dcmprscp.cc and (6) dcmpsrcv.cc in d… Dcmtk after 3.6.1 Fix from $1,9502014-06-10 HIGH 7.5 CVE-2014-4003 The System Landscape Directory (SLD) in SAP NetWeaver allows remote attackers to modify information via vectors related to adding a system. Netweaver No fix yet Fix from $1,9502014-06-09 MEDIUM 5.0 CVE-2014-3278 The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack… Unified Communications Domain Manager Mitigation only Fix from $1,6002014-06-08 MEDIUM 5.0 CVE-2014-3281 The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attack… Unified Communications Domain Manager Mitigation only Fix from $1,6002014-06-08 MEDIUM 5.0 CVE-2014-3286 The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows remote attackers to obtain sen… Webex Meetings Server Mitigation only Fix from $1,6002014-06-08 HIGH 8.5 CVE-2014-2506 EMC Documentum Content Server before 6.7 SP1 P28, 6.7 SP2 before P14, 7.0 before P15, and 7.1 before P05 allows remote authenticated users to obtain … Documentum Content Server after 6.7 Fix from $1,9502014-06-08 HIGH 10.0 CVE-2012-5390 The standard universe shadow (condor_shadow.std) component in Condor 7.7.3 through 7.7.6, 7.8.0 before 7.8.5, and 7.9.0 does no properly check privil… Condor Mitigation only Fix from $1,9502014-06-06 HIGH 7.4 CVE-2014-3969 Xen 4.4.x, when running on an ARM system, does not properly check write permissions on virtual addresses, which allows local guest administrators to … Xen Patch available Fix from $1,9502014-06-05 HIGH 8.3 CVE-2013-4860 Radio Thermostat CT80 And CT50 with firmware 1.4.64 and earlier does not restrict access to the API, which allows remote attackers to change the oper… Ct50 Firmware after 1.4.64 Fix from $1,9502014-06-05 HIGH 7.5 CVE-2014-3834 ownCloud Server before 6.0.3 does not properly check permissions, which allows remote authenticated users to (1) access the contacts of other users v… Owncloud after 6.0.2 Fix from $1,9502014-06-04 MEDIUM 5.5 CVE-2014-3835 ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated … Owncloud Server after 5.0.15 Fix from $1,6002014-06-04 MEDIUM 5.8 CVE-2013-4596 The Node Access Keys module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permissions, which allows remote attackers to bypass access res… Nodeaccesskeys Patch available Fix from $1,6002014-06-02 HIGH 7.6 CVE-2013-6433 The default configuration in the Red Hat openstack-neutron package before 2013.2.3-7 does not properly set a configuration file for rootwrap, which a… Ubuntu Linux after 2013.2.3 Fix from $1,9502014-06-02 HIGH 9.0 CVE-2014-3790 Ruby vSphere Console (RVC) in VMware vCenter Server Appliance allows remote authenticated users to execute arbitrary commands as root by escaping fro… Vcenter Server Appliance Mitigation only Fix from $1,9502014-06-01 HIGH 8.5 CVE-2013-6744 The Stored Procedure infrastructure in IBM DB2 9.5, 9.7 before FP9a, 10.1 before FP3a, and 10.5 before FP3a on Windows allows remote authenticated us… Db2 Mitigation only Fix from $1,9502014-05-30 MEDIUM 5.0 CVE-2014-3279 The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implem… Unified Communications Domain Manager after 9.0 Fix from $1,6002014-05-29 MEDIUM 6.5 CVE-2014-3416 uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by lever… Uportal after 4.0.13 Fix from $1,6002014-05-29 MEDIUM 6.5 CVE-2014-3417 uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging th… Uportal after 4.0.13 Fix from $1,6002014-05-29 MEDIUM 5.0 CVE-2013-4177 The Google Authenticator login module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.4 for Drupal does not properly identify user account names, whi… Ga Login Patch available Fix from $1,6002014-05-29 MEDIUM 5.0 CVE-2013-0199 The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes,… Freeipa Patch available Fix from $1,6002014-05-29 MEDIUM 6.2 CVE-2014-0240 The mod_wsgi module before 3.5 for Apache, when daemon mode is enabled, does not properly handle error codes returned by setuid when run on certain L… Mod Wsgi after 3.4 Fix from $1,6002014-05-27 MEDIUM 5.0 CVE-2013-4598 The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which allows remote attackers to ac… Gcc Patch available Fix from $1,6002014-05-27 MEDIUM 5.0 CVE-2014-0216 The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2… Moodle after 2.3.11 Fix from $1,6002014-05-27 MEDIUM 6.0 CVE-2014-0849 IBM Maximo Asset Management 7.x before 7.5.0.3 IFIX027 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allow remote authent… Maximo Asset Management Mitigation only Fix from $1,6002014-05-26 MEDIUM 6.0 CVE-2013-5464 IBM Maximo Asset Management 7.5.x before 7.5.0.3 IFIX027, 7.5.0.4 before IFIX011, and 7.5.0.5 before IFIX006 and SmartCloud Control Desk 7.x before 7… Maximo Asset Management Mitigation only Fix from $1,6002014-05-26 MEDIUM 6.5 CVE-2013-5465 IBM Maximo Asset Management 7.x before 7.1.1.7 LAFIX.20140319-0837, 7.1.1.11 before IFIX.20140323-0749, 7.1.1.12 before IFIX.20140321-1336, 7.5.x bef… Maximo Asset Management Mitigation only Fix from $1,6002014-05-26