Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2013-4294 The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the … Keystone Patch available Fix from $1,6002013-09-23 MEDIUM 5.0 CVE-2013-5502 The web interface in Cisco MediaSense does not properly protect the client-server communication channel, which allows remote attackers to obtain sens… Mediasense Mitigation only Fix from $1,6002013-09-23 MEDIUM 6.9 CVE-2013-5691 The (1) IPv6 and (2) ATM ioctl request handlers in the kernel in FreeBSD 8.3 through 9.2-STABLE do not validate SIOCSIFADDR, SIOCSIFBRDADDR, SIOCSIFD… FreeBSD Patch available Fix from $1,6002013-09-23 MEDIUM 6.9 CVE-2013-4325 The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communicatio… Linux Imaging And Printing Project Mitigation only Fix from $1,6002013-09-23 MEDIUM 6.8 CVE-2013-1130 Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a … Anyconnect Secure Mobility Client Mitigation only Fix from $1,6002013-09-20 MEDIUM 6.3 CVE-2013-4706 The SSH implementation on the D-Link Japan DWL-2100AP with firmware before R252JP-RC572 allows remote authenticated users to cause a denial of servic… Dwl 2100ap after 2.50 Fix from $1,6002013-09-20 MEDIUM 6.3 CVE-2013-4707 The SSH implementation on D-Link Japan DES-3810 devices with firmware before R2.20.011 allows remote authenticated users to cause a denial of service… Des 3810 Firmware Mitigation only Fix from $1,6002013-09-20 MEDIUM 5.0 CVE-2013-5157 The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post T… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 6.3 CVE-2013-5145 kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) u… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 5.8 CVE-2013-0957 Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Era… Iphone Os after 6.1.4 Fix from $1,6002013-09-19 MEDIUM 6.2 CVE-2013-1726 Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaM… Firefox after 23.0.1 Fix from $1,6002013-09-18 MEDIUM 5.0 CVE-2013-1737 Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 d… Firefox after 23.0.1 Fix from $1,6002013-09-18 HIGH 10.0 CVE-2013-5754 The authorization implementation on Dahua DVR appliances accepts a hash string representing the current date for the role of a master password, which… Dvr0404hd A Mitigation only Fix from $1,9502013-09-17 HIGH 9.3 CVE-2013-3614EPSS 7% Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-forc… Dvr0404hd A No fix yet Fix from $1,9502013-09-17 MEDIUM 5.5 CVE-2013-2296 Walrus in Eucalyptus before 3.2.2 does not verify authorization for the GetBucketLoggingStatus, SetBucketLoggingStatus, and SetBucketVersioningStatus… Eucalyptus after 3.2.1 Fix from $1,6002013-09-17 MEDIUM 6.0 CVE-2013-2256 OpenStack Compute (Nova) before 2013.1.3 and Havana before havana-2 does not properly enforce the os-flavor-access:is_public property, which allows r… Nova 2013.1.3+ Fix from $1,6002013-09-16 HIGH 7.5 CVE-2013-4182 app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to acces… Openstack after 1.2.1 Fix from $1,9502013-09-16 MEDIUM 6.8 CVE-2013-1027 Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which mig… Mac Os X after 10.8.4 Fix from $1,6002013-09-16 MEDIUM 5.5 CVE-2013-1033 Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging… Mac Os X after 10.8.4 Fix from $1,6002013-09-16 MEDIUM 5.0 CVE-2013-5489 The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensit… Socialminer Mitigation only Fix from $1,6002013-09-13 MEDIUM 6.5 CVE-2013-4329 The xenlight library (libxl) in Xen 4.0.x through 4.2.x, when IOMMU is disabled, provides access to a busmastering-capable PCI passthrough device bef… Xen Patch available Fix from $1,6002013-09-12 HIGH 10.0 CVE-2013-2934 Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspeci… Cloudportal Services Manager after 10.0 Fix from $1,9502013-09-12 MEDIUM 6.9 CVE-2013-3859 Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows lo… Office Mitigation only Fix from $1,6002013-09-11 HIGH 7.2 CVE-2013-4984EPSS 8% The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain… Web Appliance after 3.7.9 Fix from $1,9502013-09-10 MEDIUM 6.0 CVE-2013-3601 Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arb… Coursemill Learning Management System Mitigation only Fix from $1,6002013-09-06 MEDIUM 6.0 CVE-2013-3276 EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deact… Rsa Archer Egrc Mitigation only Fix from $1,6002013-09-05 MEDIUM 5.8 CVE-2013-2123 The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content cont… Nodeaccess Userreference Module Patch available Fix from $1,6002013-08-28 HIGH 7.5 CVE-2013-2247 The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the moda… Fast Permission Administration Patch available Fix from $1,9502013-08-28 MEDIUM 5.2 CVE-2013-2077 Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unha… Xen Mitigation only Fix from $1,6002013-08-28 HIGH 7.4 CVE-2013-2211 The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated ser… Xen Mitigation only Fix from $1,9502013-08-28