Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 9.0 CVE-2013-4319 pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access b… Torque Resource Manager after 4.0.2 Fix from $1,9502013-10-11 HIGH 7.9 CVE-2013-3693 The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Rem… Blackberry Enterprise Service Mitigation only Fix from $1,9502013-10-11 HIGH 7.8 CVE-2013-2581 cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P… Tl Sc3130 after 1.6.18p12_sign5 Fix from $1,9502013-10-11 HIGH 10.0 CVE-2013-3686EPSS 28% cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list … Airlive Wl2600cam Mitigation only Fix from $1,9502013-10-11 MEDIUM 5.2 CVE-2013-0577 The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass inte… Infosphere Optim Data Growth For Oracle E Business Suite Mitigation only Fix from $1,6002013-10-10 MEDIUM 5.0 CVE-2013-2241 modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive i… Gallery after 3.0.8 Fix from $1,6002013-10-10 HIGH 7.6 CVE-2013-4342EPSS 6% xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it e… Enterprise Linux Patch available Fix from $1,9502013-10-10 MEDIUM 5.4 CVE-2013-4356 Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows l… Xen Mitigation only Fix from $1,6002013-10-09 MEDIUM 6.4 CVE-2013-4379 The Make Meeting Scheduler module 6.x-1.x before 6.x-1.3 for Drupal allows remote attackers to bypass intended access restrictions for a poll via a d… Make Meeting Scheduler Module Patch available Fix from $1,6002013-10-09 MEDIUM 6.8 CVE-2013-3895EPSS 30% Microsoft SharePoint Server 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to conduct clickjacking attacks via a crafted web page, aka "Parame… Office Web Apps Mitigation only Fix from $1,6002013-10-09 MEDIUM 6.2 CVE-2012-4141 Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the… Nx Os Mitigation only Fix from $1,6002013-10-05 HIGH 8.8 CVE-2013-3543 The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwr… Media Control Activex Control No fix yet Fix from $1,9502013-10-04 HIGH 7.8 CVE-2013-3689 Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not … 100ap Device Firmware after 3.0.6.16c1 Fix from $1,9502013-10-04 HIGH 7.2 CVE-2013-5701 Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) … Server Center after 11.7.4 Fix from $1,9502013-10-03 HIGH 10.0 CVE-2013-0692 The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and RO… Ose after 3.50 Fix from $1,9502013-10-03 MEDIUM 6.8 CVE-2012-4136 The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service… Unified Computing System Mitigation only Fix from $1,6002013-10-03 MEDIUM 5.8 CVE-2013-4067 IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or condu… Infosphere Information Server Mitigation only Fix from $1,6002013-10-02 HIGH 7.1 CVE-2013-3688 The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not prop… Tl Sc3130 after 1.6.18p12_sign5 Fix from $1,9502013-10-01 MEDIUM 5.0 CVE-2013-2269 The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows … Clearpass Mitigation only Fix from $1,6002013-10-01 MEDIUM 6.5 CVE-2013-4027 IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended acce… Maximo Asset Management Mitigation only Fix from $1,6002013-10-01 MEDIUM 6.8 CVE-2012-3323 IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified … Maximo Asset Management No fix yet Fix from $1,6002013-10-01 MEDIUM 5.0 CVE-2013-5725 The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite ar… Byword No fix yet Fix from $1,6002013-10-01 HIGH 7.2 CVE-2013-4362 WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) … Davfs2 Patch available Fix from $1,9502013-09-30 MEDIUM 6.9 CVE-2013-4291 The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly … Libvirt Patch available Fix from $1,6002013-09-30 MEDIUM 5.8 CVE-2013-4310EPSS 8% Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass access controls via a crafted action: prefix. Struts Patch available Fix from $1,6002013-09-30 MEDIUM 5.0 CVE-2013-5965 The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remot… Node View Permissions after 7.x-1.1 Fix from $1,6002013-09-30 MEDIUM 6.5 CVE-2012-1313 The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macs… Unified Computing System Mitigation only Fix from $1,6002013-09-27 HIGH 7.2 CVE-2013-4300 The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows lo… Linux Kernel 3.9+ Fix from $1,9502013-09-25 MEDIUM 6.9 CVE-2013-4777 A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that… Android No fix yet Fix from $1,6002013-09-25 MEDIUM 6.9 CVE-2013-5373 The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script,… Rational Clearcase Mitigation only Fix from $1,6002013-09-25