Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.0 CVE-2014-0686 Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file… Unified Communications Manager after 9.1 Fix from $1,6002014-02-04 MEDIUM 5.0 CVE-2013-7301 Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading th… Cantata after 1.2.1 Fix from $1,6002014-02-02 MEDIUM 5.5 CVE-2014-0833 The OAC component in IBM Financial Transaction Manager (FTM) 2.0 before 2.0.0.3 does not properly enforce operator-intervention requirements, which a… Financial Transaction Manager Mitigation only Fix from $1,6002014-02-01 MEDIUM 5.0 CVE-2013-6727 The Connect client in IBM Sametime 8.5.2 through 8.5.2.1 and 9.0 before HF1 does not properly restrict unsigned Java plugins, which allows remote att… Sametime Mitigation only Fix from $1,6002014-01-31 MEDIUM 6.5 CVE-2013-2747 The password reset feature in Courion Access Risk Management Suite Version 8 Update 9 allows remote authenticated users to bypass intended Internet E… Access Risk Management Suite Mitigation only Fix from $1,6002014-01-29 HIGH 7.5 CVE-2013-2974 The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass aut… Tivoli Application Dependency Discovery Manager Mitigation only Fix from $1,9502014-01-29 HIGH 7.2 CVE-2013-7135 The Proc::Daemon module 0.14 for Perl uses world-writable permissions for a file that stores a process ID, which allows local users to have an unspec… Proc\ Mitigation only Fix from $1,9502014-01-28 HIGH 8.3 CVE-2014-1666 The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix … Xen Patch available Fix from $1,9502014-01-26 MEDIUM 5.0 CVE-2014-1626 XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other pro… Marc Xml after 1.0.1 Fix from $1,6002014-01-26 MEDIUM 5.0 CVE-2013-7247 cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover… Ts 550 Evo Firmware No fix yet Fix from $1,6002014-01-26 MEDIUM 5.5 CVE-2014-0678 The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack… Secure Access Control System Mitigation only Fix from $1,6002014-01-25 MEDIUM 5.2 CVE-2013-6457 The libxlDomainGetNumaParameters function in the libxl driver (libxl/libxl_driver.c) in libvirt before 1.2.1 does not properly initialize the nodemap… Libvirt after 1.2.0 Fix from $1,6002014-01-24 MEDIUM 6.8 CVE-2013-7315EPSS 5% The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactor… Spring Framework after 3.2.3 Fix from $1,6002014-01-23 MEDIUM 6.8 CVE-2013-4152EPSS 26% The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allow… Spring Framework after 3.2.3 Fix from $1,6002014-01-23 MEDIUM 5.0 CVE-2013-6448 The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote … Jboss Seam 2 Framework after 2.3.1 Fix from $1,6002014-01-23 MEDIUM 6.8 CVE-2014-0676 Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367. Nx Os Mitigation only Fix from $1,6002014-01-22 MEDIUM 5.0 CVE-2014-0669 The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attacker… Asr 5000 Series Software Mitigation only Fix from $1,6002014-01-22 MEDIUM 6.8 CVE-2013-0339 libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExt… Ubuntu Linux after 2.9.1 Fix from $1,6002014-01-21 MEDIUM 5.5 CVE-2013-2104 python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authen… Python Keystoneclient after 0.2.3 Fix from $1,6002014-01-21 MEDIUM 5.8 CVE-2013-4200 The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs star… Plone Patch available Fix from $1,6002014-01-21 MEDIUM 5.8 CVE-2010-5293 wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers… WordPress after 3.0.1 Fix from $1,6002014-01-21 MEDIUM 6.4 CVE-2012-6634 wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restr… WordPress after 3.3.2 Fix from $1,6002014-01-21 MEDIUM 5.5 CVE-2014-0009 course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the… Moodle after 2.2.11 Fix from $1,6002014-01-20 HIGH 10.0 CVE-2014-0648EPSS 6% The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements,… Secure Access Control System after 5.4.0.46.6 Fix from $1,9502014-01-16 HIGH 9.0 CVE-2014-0649 The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remot… Secure Access Control System after 5.4.0.46.6 Fix from $1,9502014-01-16 MEDIUM 6.3 CVE-2014-0667 The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated… Secure Access Control System Mitigation only Fix from $1,6002014-01-16 HIGH 10.0 CVE-2014-0492EPSS 6% Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef… Flash Player 4.0.0.1390 / 11.2.202.335+ Fix from $1,9502014-01-15 HIGH 10.0 CVE-2014-0491EPSS 7% Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR bef… Flash Player 4.0.0.1390 / 11.2.202.335+ Fix from $1,9502014-01-15 MEDIUM 6.4 CVE-2013-2826 WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console ra… Kingalarm\&event after 3.1 Fix from $1,6002014-01-15 HIGH 7.2 CVE-2014-0615 Juniper Junos 10.4 before 10.4R16, 11.4 before 11.4R10, 12.1R before 12.1R8-S2, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, 12.1X46 befor… Junos Mitigation only Fix from $1,9502014-01-15