Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2014-0685 Cisco Nexus 1000V InterCloud 5.2(1)IC1(1.2) and earlier for VMware allows remote attackers to bypass ACL deny statements via crafted (1) IGMPv2 or (2… Cisco Nexus 1000v Intercloud after 5.2 Fix from $1,6002014-05-07 MEDIUM 6.9 CVE-2014-2905 fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal vari… Fish Mitigation only Fix from $1,6002014-05-02 MEDIUM 5.8 CVE-2014-3001 The device file system (aka devfs) in FreeBSD 10.0 before p2 does not load default rulesets when booting, which allows context-dependent attackers to… FreeBSD Mitigation only Fix from $1,6002014-05-02 MEDIUM 6.8 CVE-2014-3006 Sitepark Information Enterprise Server (IES) 2.9 before 2.9.6, when upgraded from an earlier version, does not properly restrict access, which allows… Information Enterprise Server Mitigation only Fix from $1,6002014-05-02 MEDIUM 6.2 CVE-2014-3125 Xen 4.4.x, when running on an ARM system, does not properly context switch the CNTKCTL_EL1 register, which allows local guest users to modify the har… Xen Patch available Fix from $1,6002014-05-02 MEDIUM 5.5 CVE-2013-7061 Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via … Plone Mitigation only Fix from $1,6002014-05-02 HIGH 7.2 CVE-2014-2173 Cisco TelePresence TC Software 4.x and 5.x and TE Software 4.x and 6.0 do not properly restrict access to the serial port, which allows local users t… Telepresence Te Software Mitigation only Fix from $1,9502014-05-02 MEDIUM 6.0 CVE-2014-1989 Cybozu Garoon 3.0 through 3.7 SP3 allows remote authenticated users to bypass intended access restrictions and delete schedule information via unspec… Garoon Mitigation only Fix from $1,6002014-05-02 MEDIUM 5.0 CVE-2013-1807EPSS 8% PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow … Php Fusion after 7.02.05 Fix from $1,6002014-04-30 MEDIUM 5.0 CVE-2014-3133 SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered o… Netweaver Java Application Server Mitigation only Fix from $1,6002014-04-30 HIGH 7.2 CVE-2014-0470 super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges v… Super Mitigation only Fix from $1,9502014-04-30 MEDIUM 6.5 CVE-2014-1957 FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors. Fortiweb after 5.0.2 Fix from $1,6002014-04-30 HIGH 9.0 CVE-2013-6990 FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface. Fortiauthenticator after 2.2 Fix from $1,9502014-04-30 MEDIUM 5.0 CVE-2013-7063 The Invitation module 7.x-2.x for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via unspe… Invitation Mitigation only Fix from $1,6002014-04-29 MEDIUM 5.8 CVE-2013-7065 The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote attackers to bypass access restrictions and post to arbitrary groups v… Organic Groups Patch available Fix from $1,6002014-04-29 HIGH 7.5 CVE-2014-0112EPSS 98% ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which allows remote attackers to "mani… Struts 2.3.16.2+ Fix from $1,9502014-04-29 HIGH 7.5 CVE-2014-0113EPSS 78% CookieInterceptor in Apache Struts before 2.3.20, when a wildcard cookiesName value is used, does not properly restrict access to the getClass method… Struts 2.3.16.2+ Fix from $1,9502014-04-29 HIGH 9.0 CVE-2014-0187 The openvswitch-agent process in OpenStack Neutron 2013.1 before 2013.2.4 and 2014.1 before 2014.1.1 allows remote authenticated users to bypass secu… Ubuntu Linux Mitigation only Fix from $1,9502014-04-28 HIGH 7.5 CVE-2014-1217 Livetecs Timelive before 6.2.8 does not properly restrict access to systemsetting.aspx, which allows remote attackers to change configurations and ob… Timeline Mitigation only Fix from $1,9502014-04-28 MEDIUM 5.5 CVE-2014-2915 Xen 4.4.x, when running on ARM systems, does not properly restrict access to hardware features, which allows local guest users to cause a denial of s… Xen Mitigation only Fix from $1,6002014-04-24 MEDIUM 5.0 CVE-2012-3946 Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an u… iOS after 15.3 Fix from $1,6002014-04-24 MEDIUM 5.0 CVE-2014-0473 The caching framework in Django before 1.4.11, 1.5.x before 1.5.6, 1.6.x before 1.6.3, and 1.7.x before 1.7 beta 2 reuses a cached CSRF token for all… Django after 1.4.10 Fix from $1,6002014-04-23 HIGH 10.0 CVE-2014-1314 WindowServer in Apple OS X through 10.9.2 does not prevent session creation by a sandboxed application, which allows attackers to bypass the sandbox … Mac Os X after 10.9.2 Fix from $1,9502014-04-23 MEDIUM 5.8 CVE-2014-0173 The Jetpack plugin before 1.9 before 1.9.4, 2.0.x before 2.0.9, 2.1.x before 2.1.4, 2.2.x before 2.2.7, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x… Jetpack Mitigation only Fix from $1,6002014-04-22 MEDIUM 5.5 CVE-2013-7195 PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specif… Phpfox Mitigation only Fix from $1,6002014-04-18 MEDIUM 5.5 CVE-2013-7196 static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a privat… Phpfox Mitigation only Fix from $1,6002014-04-18 MEDIUM 6.4 CVE-2014-0071 PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass int… Openstack Mitigation only Fix from $1,6002014-04-17 MEDIUM 5.0 CVE-2014-0053 The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 before 2.3.6 does not properly restrict access to files… Grails Resources Mitigation only Fix from $1,6002014-04-15 MEDIUM 5.0 CVE-2014-2857 The default configuration of the Resources plugin 1.0.0 before 1.2.6 for Pivotal Grails 2.0.0 through 2.3.6 does not properly restrict access to file… Grails Resources Mitigation only Fix from $1,6002014-04-15 HIGH 7.5 CVE-2014-2859 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request. Commonspot Content Server after 7.0.1 Fix from $1,9502014-04-15