Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 10.0 CVE-2014-0512 Adobe Reader 11.0.06 allows attackers to bypass a PDF sandbox protection mechanism via unspecified vectors, as demonstrated by VUPEN during a Pwn2Own… Acrobat Reader Mitigation only Fix from $1,9502014-03-27 MEDIUM 5.8 CVE-2014-0125 repository/alfresco/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 places a session key in a URL, w… Moodle after 2.3.11 Fix from $1,6002014-03-24 MEDIUM 5.0 CVE-2014-2276 The FileUploadController servlet in EMC Connectrix Manager Converged Network Edition (CMCNE) before 12.1.5 does not properly restrict additions to th… Connectrix Manager after 12.1.2 Fix from $1,6002014-03-21 HIGH 7.5 CVE-2014-0002EPSS 33% The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other uns… Camel after 2.11.3 Fix from $1,9502014-03-21 HIGH 7.5 CVE-2014-0003EPSS 7% The XSLT component in Apache Camel 2.11.x before 2.11.4, 2.12.x before 2.12.3, and possibly earlier versions allows remote attackers to execute arbit… Camel after 2.11.3 Fix from $1,9502014-03-21 HIGH 7.5 CVE-2011-5275 The install script in Domain Technologie Control (DTC) before 0.34.1 gives sudo permissions for chrootuid to the dtc user, which makes it easier for … Domain Technologie Control after 0.32.11 Fix from $1,9502014-03-21 HIGH 8.5 CVE-2014-2119 The End User Safelist/Blocklist (aka SLBL) service in Cisco AsyncOS Software for Email Security Appliance (ESA) before 7.6.3-023 and 8.x before 8.0.1… Ironport Asyncos after 7.9.1-039 Fix from $1,9502014-03-21 MEDIUM 5.8 CVE-2014-1501 Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving… Firefox after 27.0.1 Fix from $1,6002014-03-19 HIGH 7.2 CVE-2014-2533 /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a comm… Qnx Neutrino Rtos No fix yet Fix from $1,9502014-03-18 MEDIUM 6.5 CVE-2013-2048 ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified … Owncloud after 5.0.5 Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2014-2049 The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified v… Owncloud Server after 5.0.14 Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2014-1276 IOKit HID Event in Apple iOS before 7.1 allows attackers to conduct user-action monitoring attacks against arbitrary apps via a crafted app that acce… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 5.8 CVE-2014-1282 The Profiles component in Apple iOS before 7.1 and Apple TV before 6.1 allows attackers to bypass intended configuration-profile visibility requireme… Tvos after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 5.8 CVE-2014-1285 Springboard in Apple iOS before 7.1 allows physically proximate attackers to bypass intended access restrictions and read the home screen by leveragi… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2014-2265 Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omittin… Contact Form 7 after 3.7.1 Fix from $1,6002014-03-14 HIGH 8.8 CVE-2013-5133 Backup in Apple iOS before 7.1 does not properly restrict symlinks, which allows remote attackers to overwrite files during a restore operation via c… Iphone Os after 7.0.6 Fix from $1,9502014-03-14 MEDIUM 5.8 CVE-2013-6442 The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgr… Samba Mitigation only Fix from $1,6002014-03-14 MEDIUM 5.0 CVE-2013-6835EPSS 7% TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remot… Iphone Os after 7.0.6 Fix from $1,6002014-03-14 HIGH 7.2 CVE-2014-0300 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2… Windows 7 Patch available Fix from $1,9502014-03-12 MEDIUM 5.8 CVE-2013-4191 zip.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce access restrictions when including content in… Plone Patch available Fix from $1,6002014-03-11 MEDIUM 5.0 CVE-2013-4196 The object manager implementation (objectmanager.py) in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly restric… Plone Patch available Fix from $1,6002014-03-11 HIGH 10.0 CVE-2014-2321EPSS 59% web_shell_cmd.gch on ZTE F460 and F660 cable modems allows remote attackers to obtain administrative access via sendcmd requests, as demonstrated by … F460 Mitigation only Fix from $1,9502014-03-11 MEDIUM 6.5 CVE-2014-0899 ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated … Aix Mitigation only Fix from $1,6002014-03-11 MEDIUM 5.0 CVE-2013-4971 Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive … Puppet Enterprise after 3.1.1 Fix from $1,6002014-03-09 MEDIUM 5.8 CVE-2014-1959 lib/x509/verify.c in GnuTLS before 3.1.21 and 3.2.x before 3.2.11 treats version 1 X.509 certificates as intermediate CAs, which allows remote attack… Gnutls after 3.1.20 Fix from $1,6002014-03-07 MEDIUM 5.8 CVE-2009-5138 GnuTLS before 2.7.6, when the GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT flag is not enabled, treats version 1 X.509 certificates as intermediate CAs, which … Gnutls after 2.7.5 Fix from $1,6002014-03-07 HIGH 8.5 CVE-2014-0629 EMC Documentum TaskSpace (TSP) 6.7SP1 before P25 and 6.7SP2 before P11 does not properly handle the interaction between the dm_world group and the dm… Documentum Taskspace Mitigation only Fix from $1,9502014-03-06 MEDIUM 5.8 CVE-2013-6666 The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not veri… Chrome after 33.0.1750.144 Fix from $1,6002014-03-05 MEDIUM 6.8 CVE-2012-6636EPSS 41% The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote attackers to execute arbitrary me… Android Api after 16.0 Fix from $1,6002014-03-03 HIGH 7.5 CVE-2014-1881EPSS 11% Apache Cordova 3.3.0 and earlier and Adobe PhoneGap 2.9.0 and earlier allow remote attackers to bypass intended device-resource restrictions of an ev… Cordova after 3.3.0 Fix from $1,9502014-03-03