Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2013-3981 The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users v… Sametime Mitigation only Fix from $1,6002014-05-26 HIGH 7.1 CVE-2013-1191 Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga… Nx Os Mitigation only Fix from $1,9502014-05-26 HIGH 7.1 CVE-2014-2200 Cisco NX-OS 5.0 before 5.0(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to ga… Nx Os Mitigation only Fix from $1,9502014-05-26 HIGH 9.0 CVE-2014-2504 EMC Documentum D2 3.1 before P20, 3.1 SP1 before P02, 4.0 before P10, 4.1 before P13, and 4.2 before P01 allows remote authenticated users to bypass … Documentum D2 Mitigation only Fix from $1,9502014-05-26 MEDIUM 5.0 CVE-2014-3848EPSS 9% The iMember360 plugin before 3.9.001 for WordPress does not properly restrict access, which allows remote attackers to obtain database credentials vi… Imember360 after 3.9.000 Fix from $1,6002014-05-23 MEDIUM 5.0 CVE-2013-4223 The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP aut… Nullmailer Mitigation only Fix from $1,6002014-05-23 HIGH 7.5 CVE-2013-2757 Citrix CloudPlatform (formerly Citrix CloudStack) 3.0.x before 3.0.6 Patch C does not properly restrict access to VNC ports on the management network… Cloudplatform Patch available Fix from $1,9502014-05-23 MEDIUM 5.0 CVE-2014-3844 The TinyMCE Color Picker plugin before 1.2 for WordPress does not properly check permissions, which allows remote attackers to modify plugin settings… Color Picker after 1.1 Fix from $1,6002014-05-22 MEDIUM 5.5 CVE-2013-4320 The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenti… TYPO3 Mitigation only Fix from $1,6002014-05-20 HIGH 9.0 CVE-2013-7383 x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vect… X2go Server after 4.0.0.7 Fix from $1,9502014-05-20 MEDIUM 5.5 CVE-2013-4431 Mahara before 1.5.12, 1.6.x before 1.6.7, and 1.7.x before 1.7.3 does not properly prevent access to blocks, which allows remote authenticated users … Mahara after 1.5.11 Fix from $1,6002014-05-19 MEDIUM 5.0 CVE-2013-4406 The Quick Tabs module 6.x-2.x before 6.x-2.2, 6.x-3.x before 6.x-3.2, and 7.x-3.x before 7.x-3.6 for Drupal does not properly check block permissions… Quicktabs Patch available Fix from $1,6002014-05-19 HIGH 8.5 CVE-2014-2084 Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin in… Skybox View Appliance Iso No fix yet Fix from $1,9502014-05-17 HIGH 7.9 CVE-2014-1649EPSS 42% The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLR… Workspace Streaming after 7.5.0 Fix from $1,9502014-05-16 HIGH 7.2 CVE-2014-1807 The ShellExecute API in Windows Shell in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Win… Windows 7 Patch available Fix from $1,9502014-05-14 MEDIUM 6.8 CVE-2014-1809EPSS 10% The MSCOMCTL library in Microsoft Office 2007 SP3, 2010 SP1 and SP2, and 2013 Gold, SP1, RT, and RT SP1 makes it easier for remote attackers to bypas… Office Mitigation only Fix from $1,6002014-05-14 HIGH 7.5 CVE-2014-0520 Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi… Flash Player 11.2.202.359 / 13.0.0.111+ Fix from $1,9502014-05-14 HIGH 10.0 CVE-2014-0525EPSS 6% The API in Adobe Reader and Acrobat 10.x before 10.1.10 and 11.x before 11.0.07 on Windows and OS X does not prevent access to unmapped memory, which… Acrobat Reader Mitigation only Fix from $1,9502014-05-14 HIGH 7.5 CVE-2014-0516 Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi… Flash Player 11.2.202.359 / 13.0.0.111+ Fix from $1,9502014-05-14 HIGH 7.5 CVE-2014-0517 Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi… Flash Player 11.2.202.359 / 13.0.0.111+ Fix from $1,9502014-05-14 HIGH 7.5 CVE-2014-0518 Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi… Flash Player 11.2.202.359 / 13.0.0.111+ Fix from $1,9502014-05-14 HIGH 7.5 CVE-2014-0519 Adobe Flash Player before 13.0.0.214 on Windows and OS X and before 11.2.202.359 on Linux, Adobe AIR SDK before 13.0.0.111, and Adobe AIR SDK & Compi… Flash Player 11.2.202.359 / 13.0.0.111+ Fix from $1,9502014-05-14 MEDIUM 6.8 CVE-2011-2514 The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and bef… Icedtea Web after 1.8.8 Fix from $1,6002014-05-14 MEDIUM 5.0 CVE-2013-4501 The default views in the Quiz module 6.x-4.x before 6.x-4.5 for Drupal allows remote attackers to obtain sensitive quiz results via unspecified vecto… Quiz Patch available Fix from $1,6002014-05-13 MEDIUM 5.0 CVE-2014-0192 Foreman 1.4.0 before 1.5.0 does not properly restrict access to provisioning template previews, which allows remote attackers to obtain sensitive inf… Foreman Patch available Fix from $1,6002014-05-08 MEDIUM 6.5 CVE-2013-0187 Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request. Foreman after 1.0 Fix from $1,6002014-05-08 MEDIUM 6.9 CVE-2014-3215 seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the s… Policycoreutils Mitigation only Fix from $1,6002014-05-08 HIGH 7.6 CVE-2013-5016 Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to b… Symantec Critical System Protection after 5.2.8 Fix from $1,9502014-05-08 MEDIUM 5.8 CVE-2014-0116EPSS 7% CookieInterceptor in Apache Struts 2.x before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass me… Struts Mitigation only Fix from $1,6002014-05-08 MEDIUM 6.7 CVE-2014-3124 The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or poss… Xen Patch available Fix from $1,6002014-05-07