Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.5 CVE-2014-2862 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated user… Commonspot Content Server after 7.0.1 Fix from $1,6002014-04-15 HIGH 7.5 CVE-2014-2865 PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a '\0' character, as demons… Commonspot Content Server after 7.0.1 Fix from $1,9502014-04-15 MEDIUM 5.5 CVE-2014-0642 EMC Documentum Content Server before 6.7 SP1 P26, 6.7 SP2 before P13, 7.0 before P13, and 7.1 before P02 allows remote authenticated users to bypass … Documentum Content Server after 6.7 Fix from $1,6002014-04-15 MEDIUM 5.8 CVE-2014-1986 The Content Provider in the KOKUYO CamiApp application 1.21.1 and earlier for Android allows attackers to bypass intended access restrictions and rea… Camiapp after 1.21.1 Fix from $1,6002014-04-15 HIGH 9.3 CVE-2014-0514EPSS 72% The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute ar… Adobe Reader after 11.1.3 Fix from $1,9502014-04-15 HIGH 7.5 CVE-2014-0107EPSS 14% The TransformerFactory in Apache Xalan-Java before 2.7.2 does not properly restrict access to certain properties when FEATURE_SECURE_PROCESSING is en… Xalan Java after 2.7.1 Fix from $1,9502014-04-15 MEDIUM 6.0 CVE-2014-0167 The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce R… Compute Patch available Fix from $1,6002014-04-15 HIGH 8.5 CVE-2014-2849EPSS 60% The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user pass… Web Appliance Firmware after 3.8.1.1 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2746 net/IOService.java in Tigase before 5.2.1 does not properly restrict the processing of compressed XML elements, which allows remote attackers to caus… Tigase after 5.2.0 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2829 Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers … Mongooseim after 1.3.1 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2743 plugins/mod_compression.lua in Lightwitch Metronome through 3.4 does not properly restrict the processing of compressed XML elements, which allows re… Metronome after 3.4 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2745 Prosody before 0.9.4 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service… Prosody after 0.9.3 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2741 nio/XMLLightweightParser.java in Ignite Realtime Openfire before 3.9.2 does not properly restrict the processing of compressed XML elements, which al… Openfire after 3.9.1 Fix from $1,9502014-04-11 HIGH 7.8 CVE-2014-2742 Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of s… M Link Mitigation only Fix from $1,9502014-04-11 MEDIUM 6.0 CVE-2014-0908 The User Attribute implementation in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.2, and 8.5.x through 8.5.0.1 does … Business Process Manager Mitigation only Fix from $1,6002014-04-10 HIGH 7.5 CVE-2013-7364 An unspecified J2EE core service in the J2EE Engine in SAP NetWeaver does not properly restrict access, which allows remote attackers to read and wri… Netweaver Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2013-7367 SAP Enterprise Portal does not properly restrict access to the Federation configuration pages, which allows remote attackers to gain privileges via u… Enterprise Portal Mitigation only Fix from $1,9502014-04-10 HIGH 7.5 CVE-2014-2748 The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes … Enhancement Package Mitigation only Fix from $1,9502014-04-10 HIGH 8.5 CVE-2014-2126 Cisco Adaptive Security Appliance (ASA) Software 8.2 before 8.2(5.47), 8.4 before 8.4(7.5), 8.7 before 8.7(1.11), 9.0 before 9.0(3.10), and 9.1 befor… Adaptive Security Appliance Software Mitigation only Fix from $1,9502014-04-10 MEDIUM 5.0 CVE-2014-0508 Adobe Flash Player before 11.7.700.275 and 11.8.x through 13.0.x before 13.0.0.182 on Windows and OS X and before 11.2.202.350 on Linux, Adobe AIR be… Adobe Air Sdk after 11.2.202.346 Fix from $1,6002014-04-08 MEDIUM 5.0 CVE-2014-2541 The Rendezvous Daemon (rvd), Rendezvous Routing Daemon (rvrd), Rendezvous Secure Daemon (rvsd), and Rendezvous Secure Routing Daemon (rvsrd) in TIBCO… Rendezvous after 8.7.0 Fix from $1,6002014-04-08 HIGH 7.5 CVE-2014-0592 Barclamp (aka barclamp-network) 1.7 for the Crowbar Framework, as used in SUSE Cloud 3, does not enable netfilter on bridges when creating new instan… Barclamp Patch available Fix from $1,9502014-04-04 MEDIUM 5.8 CVE-2014-0093 Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002014-04-03 MEDIUM 5.0 CVE-2014-2237 The memcache token backend in OpenStack Identity (Keystone) 2013.1 through 2.013.1.4, 2013.2 through 2013.2.2, and icehouse before icehouse-3, when i… Keystone Mitigation only Fix from $1,6002014-04-01 HIGH 7.5 CVE-2014-0050EPSS 83% MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to c… Commons Fileupload after 1.3 Fix from $1,9502014-04-01 HIGH 7.6 CVE-2013-6770 The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /sys… Superuser No fix yet Fix from $1,9502014-03-31 HIGH 10.0 CVE-2013-6775 The Chainfire SuperSU package before 1.69 for Android allows attackers to gain privileges via the (1) backtick or (2) $() type of shell metacharacter… Supersu Mitigation only Fix from $1,9502014-03-31 MEDIUM 6.5 CVE-2014-0061 The validator functions for the procedural languages (PLs) in PostgreSQL before 8.4.20, 9.0.x before 9.0.16, 9.1.x before 9.1.12, 9.2.x before 9.2.7,… PostgreSQL after 8.4.19 Fix from $1,6002014-03-31 MEDIUM 6.5 CVE-2014-0344EPSS 6% Properties.do in ZOHO ManageEngine OpStor before build 8500 does not properly check privilege levels, which allows remote authenticated users to obta… Manageengine Opstor after 8.3 Fix from $1,6002014-03-29 MEDIUM 5.0 CVE-2014-1516 The saltProfileName function in base/GeckoProfileDirectories.java in Mozilla Firefox through 28.0.1 on Android relies on Android's weak approach to s… Firefox after 28.0.1 Fix from $1,6002014-03-29