Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2013-2065 (1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native function… Ruby Patch available Fix from $1,6002013-11-02 HIGH 8.5 CVE-2013-4401 The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permi… Libvirt Patch available Fix from $1,9502013-11-02 HIGH 8.3 CVE-2013-5598 PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remo… Firefox after 24.0 Fix from $1,9502013-10-30 HIGH 7.5 CVE-2013-0337 The default configuration of nginx, possibly 1.3.13 and earlier, uses world-readable permissions for the (1) access.log and (2) error.log files, whic… Nginx after 1.3.13 Fix from $1,9502013-10-27 MEDIUM 5.0 CVE-2013-4302 (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php… Mediawiki Patch available Fix from $1,6002013-10-27 MEDIUM 6.8 CVE-2013-5424 IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by… Flex System Manager Mitigation only Fix from $1,6002013-10-25 MEDIUM 5.8 CVE-2013-6128 The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveT… Kingview after 6.52 Fix from $1,6002013-10-25 HIGH 7.5 CVE-2013-3280 EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to by… Rsa Authentication Agent Mitigation only Fix from $1,9502013-10-25 MEDIUM 5.0 CVE-2013-5521 Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service … Identity Services Engine Software Mitigation only Fix from $1,6002013-10-25 MEDIUM 6.8 CVE-2013-5522 Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service M… iOS Mitigation only Fix from $1,6002013-10-25 MEDIUM 6.0 CVE-2013-4299 Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive i… Linux Kernel after 3.11.6 Fix from $1,6002013-10-24 HIGH 7.2 CVE-2013-5148 Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows … Keynote after 5.3 Fix from $1,9502013-10-24 MEDIUM 5.0 CVE-2013-5178 LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to … Mac Os X after 10.8.5 Fix from $1,6002013-10-24 HIGH 7.5 CVE-2013-5179 App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices int… Mac Os X after 10.8.5 Fix from $1,9502013-10-24 MEDIUM 5.8 CVE-2013-5189 Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-depend… Mac Os X after 10.8.5 Fix from $1,6002013-10-24 MEDIUM 5.0 CVE-2013-6246EPSS 6% The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's ful… Quest One Password Manager No fix yet Fix from $1,6002013-10-24 MEDIUM 6.4 CVE-2013-5165 socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers… Mac Os X after 10.8.5 Fix from $1,6002013-10-24 HIGH 7.1 CVE-2013-5428 IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a … Websphere Datapower Xc10 Appliance Mitigation only Fix from $1,9502013-10-22 MEDIUM 6.8 CVE-2013-5971 Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web se… Vcenter Server after 5.0 Fix from $1,6002013-10-21 HIGH 7.5 CVE-2013-6129EPSS 52% The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password… Vbulletin No fix yet Fix from $1,9502013-10-19 HIGH 10.0 CVE-2013-6026EPSS 8% The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-… Di 524up Mitigation only Fix from $1,9502013-10-19 MEDIUM 6.8 CVE-2012-4112 The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary command… Unified Computing System Mitigation only Fix from $1,6002013-10-19 MEDIUM 5.0 CVE-2013-5538 The Sponsor Portal in Cisco Identity Services Engine (ISE) uses weak permissions for uploaded files, which allows remote attackers to read arbitrary … Identity Services Engine Software Mitigation only Fix from $1,6002013-10-16 HIGH 7.2 CVE-2013-5030 Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain conf… Zoneflex 2942 Firmware Mitigation only Fix from $1,9502013-10-16 MEDIUM 6.8 CVE-2012-4121 Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, … Nx Os Mitigation only Fix from $1,6002013-10-14 MEDIUM 6.8 CVE-2012-4077 Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via the sed e option, aka Bug IDs CSCtf25457 and CSCtf27651. Nx Os Mitigation only Fix from $1,6002013-10-14 HIGH 7.5 CVE-2013-4825 Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers t… Imc Service Operation Management Software Module Mitigation only Fix from $1,9502013-10-13 MEDIUM 6.6 CVE-2013-5506 The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context… Firewall Services Module Software Mitigation only Fix from $1,6002013-10-13 HIGH 10.0 CVE-2013-5509 The SSL implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0 before 9.0(2.6) and 9.1 before 9.1(2) allows remote attackers to bypas… Adaptive Security Appliance Software Mitigation only Fix from $1,9502013-10-13 MEDIUM 6.8 CVE-2012-4106 The fabric-interconnect component in Cisco Unified Computing System (UCS) uses the same privilege level for execution of every script, which allows l… Unified Computing System Mitigation only Fix from $1,6002013-10-13