Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2010-5291 Amberdms Billing System (ABS) before 1.4.1 does not properly implement blacklisting after detection of invalid login attempts, which makes it easier … Amberdms Billing System after 1.4.0 Fix from $1,6002014-01-10 MEDIUM 5.0 CVE-2014-0752 The SCADA server in Ecava IntegraXor before 4.1.4369 allows remote attackers to read arbitrary project backup files via a crafted URL. Integraxor after 4.1.4360 Fix from $1,6002014-01-09 HIGH 10.0 CVE-2013-6955EPSS 85% webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remo… Diskstation Manager Mitigation only Fix from $1,9502014-01-09 HIGH 10.0 CVE-2012-0264 op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via un… Monitor after 5.4.2 Fix from $1,9502013-12-31 HIGH 7.2 CVE-2013-6886 RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) vncserver, (2) vncserver-x11, … Realvnc Mitigation only Fix from $1,9502013-12-28 MEDIUM 5.2 CVE-2013-4554 Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which … Xen Mitigation only Fix from $1,6002013-12-24 MEDIUM 6.8 CVE-2013-6403 The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB. Owncloud after 5.0.12 Fix from $1,6002013-12-24 HIGH 7.2 CVE-2013-3709 WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret to… Suse Lifecycle Management Server No fix yet Fix from $1,9502013-12-23 MEDIUM 6.5 CVE-2013-4404 cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restri… Enterprise Mrg Mitigation only Fix from $1,6002013-12-23 MEDIUM 5.0 CVE-2013-6723 IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, whic… Websphere Portal Patch available Fix from $1,6002013-12-22 MEDIUM 5.0 CVE-2013-6735 IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.… Websphere Portal Patch available Fix from $1,6002013-12-22 MEDIUM 5.8 CVE-2013-7067 The OG Features module 6.x-1.x before 6.x-1.4 for Drupal does not properly override pages that have an access callback set to false, which allows rem… Og Features Patch available Fix from $1,6002013-12-19 MEDIUM 6.4 CVE-2013-5227 Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofi… Safari after 6.1 Fix from $1,6002013-12-18 MEDIUM 5.0 CVE-2013-6965 The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows rem… Webex Training Center Mitigation only Fix from $1,6002013-12-14 HIGH 8.8 CVE-2013-6271EPSS 8% Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the up… Android No fix yet Fix from $1,9502013-12-14 MEDIUM 6.8 CVE-2013-6400 Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspeci… Xen Mitigation only Fix from $1,6002013-12-13 MEDIUM 6.9 CVE-2013-6840 Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified ve… Comos No fix yet Fix from $1,6002013-12-10 MEDIUM 5.0 CVE-2013-6708 Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889. Cloud Portal Mitigation only Fix from $1,6002013-12-10 MEDIUM 6.8 CVE-2013-6180 EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI… Rsa Netwitness Nextgen Mitigation only Fix from $1,6002013-12-09 HIGH 7.2 CVE-2013-4400 virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environm… Libvirt Patch available Fix from $1,9502013-12-09 MEDIUM 6.2 CVE-2013-6409 Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOC… Adequate after 0.8 Fix from $1,6002013-12-07 HIGH 7.5 CVE-2013-6410 nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended acces… Debian Linux after 3.4 Fix from $1,9502013-12-07 MEDIUM 6.4 CVE-2013-6417 actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in paramete… Rails after 3.2.15 Fix from $1,6002013-12-07 HIGH 7.2 CVE-2013-1090 The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, … Opensuse Mitigation only Fix from $1,9502013-12-06 MEDIUM 5.5 CVE-2013-2133 The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly … Jboss Enterprise Application Platform after 6.1.0 Fix from $1,6002013-12-06 MEDIUM 6.8 CVE-2013-6004 Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors. Garoon after 3.7 Fix from $1,6002013-12-05 HIGH 7.5 CVE-2013-6945 The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doct… Vista Patch available Fix from $1,9502013-12-04 HIGH 7.9 CVE-2013-3519 lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and… Esxi Mitigation only Fix from $1,9502013-12-04 HIGH 7.2 CVE-2012-0427 yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain pri… Opensuse No fix yet Fix from $1,9502013-12-02 HIGH 10.0 CVE-2012-0434 The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors. Suse Cloud Mitigation only Fix from $1,9502013-12-02