Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2012-6562 engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbit… Elgg after 1.8.4 Fix from $1,6002013-05-23 HIGH 7.2 CVE-2013-3496 Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNe… Vipnet Client after 4.1 Fix from $1,9502013-05-22 MEDIUM 6.9 CVE-2013-2007 The qemu guest agent in Qemu 1.4.1 and earlier, as used by Xen, when started in daemon mode, uses weak permissions for certain files, which allows lo… Qemu Mitigation only Fix from $1,6002013-05-21 MEDIUM 6.9 CVE-2013-1964 Xen 4.0.x and 4.1.x incorrectly releases a grant reference when releasing a non-v1, non-transitive grant, which allows local guest administrators to … Xen Mitigation only Fix from $1,6002013-05-21 MEDIUM 6.8 CVE-2013-3270 EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, w… Vnx Control Station after 7.1.70.1 Fix from $1,6002013-05-20 MEDIUM 6.9 CVE-2013-1672 The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x b… Firefox after 20.0.1 Fix from $1,6002013-05-16 MEDIUM 6.9 CVE-2013-1673 The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situ… Firefox after 20.0.1 Fix from $1,6002013-05-16 MEDIUM 6.8 CVE-2013-0096EPSS 16% Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL p… Windows Essentials Mitigation only Fix from $1,6002013-05-15 HIGH 7.8 CVE-2013-1225 Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP… Unified Customer Voice Portal after 9.0 Fix from $1,9502013-05-09 HIGH 9.3 CVE-2013-0685 Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which all… Wonderware Information Server Mitigation only Fix from $1,9502013-05-09 MEDIUM 6.5 CVE-2013-3509 html/System-NeDi.php in the NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands via… Groundwork Monitor Mitigation only Fix from $1,6002013-05-08 HIGH 7.5 CVE-2013-3499 GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administ… Groundwork Monitor Mitigation only Fix from $1,9502013-05-08 HIGH 7.5 CVE-2013-3500 The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/… Groundwork Monitor Mitigation only Fix from $1,9502013-05-08 HIGH 7.5 CVE-2013-3506 cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which a… Groundwork Monitor Mitigation only Fix from $1,9502013-05-08 MEDIUM 6.9 CVE-2013-1979 The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which … Linux Kernel after 3.8.10 Fix from $1,6002013-05-03 HIGH 7.2 CVE-2013-0940 The nsrpush process in the client in EMC NetWorker before 7.6.5.3 and 8.x before 8.0.1.4 sets weak permissions for unspecified files, which allows lo… Networker after 7.6.5.2 Fix from $1,9502013-05-03 MEDIUM 6.5 CVE-2013-3062 The CP_RC_TRANSACTION_CALL_BY_SET function in the Engineering Workbench component in SAP Production Planning and Control allows remote authenticated … Production Planning And Control Mitigation only Fix from $1,6002013-05-01 HIGH 9.0 CVE-2013-3080 VMware vCenter Server Appliance (vCSA) 5.1 before Update 1 allows remote authenticated users to create or overwrite arbitrary files, and consequently… Vcenter Server Appliance Mitigation only Fix from $1,9502013-05-01 MEDIUM 6.5 CVE-2013-3061 The ISHMED-PATRED_TRANSACT_RFCCALL function in the IS-H Industry-Specific Component Hospital subsystem in SAP Healthcare Industry Solution, and the S… Erp Central Component Mitigation only Fix from $1,6002013-05-01 MEDIUM 5.8 CVE-2013-0127 IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote at… Lotus Notes Mitigation only Fix from $1,6002013-05-01 MEDIUM 5.0 CVE-2012-4464 Ruby 1.9.3 before patchlevel 286 and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level restrictions and modify untai… Ruby Mitigation only Fix from $1,6002013-04-25 MEDIUM 5.0 CVE-2012-4466 Ruby 1.8.7 before patchlevel 371, 1.9.3 before patchlevel 286, and 2.0 before revision r37068 allows context-dependent attackers to bypass safe-level… Ruby Mitigation only Fix from $1,6002013-04-25 MEDIUM 6.8 CVE-2013-1215 The vpnclient program in the Easy VPN component on Cisco Adaptive Security Appliances (ASA) 5505 devices allows local users to gain privileges via un… Adaptive Security Appliance Software Mitigation only Fix from $1,6002013-04-25 HIGH 9.3 CVE-2013-1182 The login page in the Web Console in the Manager component in Cisco Unified Computing System (UCS) before 1.0(2h), 1.1 before 1.1(1j), and 1.3(x) all… Unified Computing System Infrastructure And Unified Computing System Software after 1.0 Fix from $1,9502013-04-25 HIGH 9.3 CVE-2013-3055 Lexmark Markvision Enterprise before 1.8 provides a diagnostic interface on TCP port 9789, which allows remote attackers to execute arbitrary code, c… Markvision after 1.5 Fix from $1,9502013-04-25 MEDIUM 5.0 CVE-2013-1195 The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properl… Firewall Services Module Mitigation only Fix from $1,6002013-04-24 MEDIUM 5.0 CVE-2013-1214 The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows r… Unified Contact Center Express Editor Software Mitigation only Fix from $1,6002013-04-24 HIGH 7.2 CVE-2012-5218 HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS… Elitepad Mitigation only Fix from $1,9502013-04-24 MEDIUM 6.6 CVE-2013-0687 The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify … Micom S1 Studio Mitigation only Fix from $1,6002013-04-18 MEDIUM 5.0 CVE-2013-2834 Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker… Chrome Os after 26.0.1410.56 Fix from $1,6002013-04-16