Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2013-2835 Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attacker… Chrome Os after 26.0.1410.56 Fix from $1,6002013-04-16 MEDIUM 5.8 CVE-2013-2304 The Sleipnir Mobile application 2.8.0 and earlier and Sleipnir Mobile Black Edition application 2.8.0 and earlier for Android allow remote attackers … Sleipnir Mobile after 2.8.0 Fix from $1,6002013-04-16 HIGH 8.5 CVE-2012-3022 The SaveToFile method in a certain ActiveX control in TrendDisplay.dll in Canary Labs TrendLink 9.0.2.27051 and earlier does not properly restrict th… Trendlink after 9.0.2.27051 Fix from $1,9502013-04-16 MEDIUM 5.0 CVE-2013-0315 The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted extern… Jboss Enterprise Portal Platform Mitigation only Fix from $1,6002013-04-12 HIGH 9.3 CVE-2013-0501 The EdrawSoft EDOFFICE.EDOfficeCtrl.1 ActiveX control, as used in Edraw Office Viewer Component, the client in IBM Cognos Disclosure Management (CDM)… Cognos Disclosure Management Mitigation only Fix from $1,9502013-04-12 HIGH 9.3 CVE-2013-1169 Cisco Unified MeetingPlace Web Conferencing Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 2, and 8.5 before 8.5MR3 Patch 1, when the Reme… Unified Meetingplace Web Conferencing Server Mitigation only Fix from $1,9502013-04-11 HIGH 7.5 CVE-2013-1800 The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-inje… Crack after 0.3.1 Fix from $1,9502013-04-09 HIGH 7.5 CVE-2013-1801 The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-i… Httparty after 0.9.0 Fix from $1,9502013-04-09 HIGH 7.5 CVE-2013-1802 The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-in… Extlib after 0.9.15 Fix from $1,9502013-04-09 HIGH 7.2 CVE-2013-1858 The clone system-call implementation in the Linux kernel before 3.8.3 does not properly handle a combination of the CLONE_NEWUSER and CLONE_FS flags,… Linux Kernel after 3.8.2 Fix from $1,9502013-04-05 HIGH 10.0 CVE-2013-1903 PostgreSQL, possibly 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, 8.4.x before 8.4.17, and 8.3.x before 8.3.23 incorrectly provides t… PostgreSQL Mitigation only Fix from $1,9502013-04-04 HIGH 10.0 CVE-2013-0795 The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird E… Firefox after 19.0.2 Fix from $1,9502013-04-03 HIGH 8.2 CVE-2012-5879EPSS 5% An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or cr… Mcafee Virtual Technician after 6.5.0.2101 Fix from $1,9502013-03-28 MEDIUM 6.8 CVE-2013-0918 Google Chrome before 26.0.1410.43 does not prevent navigation to developer tools in response to a drag-and-drop operation, which allows user-assisted… Chrome after 26.0.1410.42 Fix from $1,6002013-03-28 MEDIUM 6.8 CVE-2013-0921 The Isolated Sites feature in Google Chrome before 26.0.1410.43 does not properly enforce the use of separate processes, which makes it easier for re… Chrome after 26.0.1410.42 Fix from $1,6002013-03-28 HIGH 7.5 CVE-2013-0922 Google Chrome before 26.0.1410.43 does not properly restrict brute-force access attempts against web sites that require HTTP Basic Authentication, wh… Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 HIGH 7.5 CVE-2013-0924 The extension functionality in Google Chrome before 26.0.1410.43 does not verify that use of the permissions API is consistent with file permissions,… Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 HIGH 7.5 CVE-2013-0925 Google Chrome before 26.0.1410.43 does not ensure that an extension has the tabs (aka APIPermission::kTab) permission before providing a URL to this … Chrome after 26.0.1410.42 Fix from $1,9502013-03-28 MEDIUM 6.4 CVE-2013-1859 The Node Parameter Control module 6.x-1.x for Drupal does not properly restrict access to the configuration options, which allows remote attackers to… Node Parameter Control No fix yet Fix from $1,6002013-03-27 MEDIUM 5.0 CVE-2013-0182 The Payment module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to payments, which allows remote attackers to read arbitrary p… Payment Patch available Fix from $1,6002013-03-27 MEDIUM 5.0 CVE-2013-0257 The email2image module 6.x-1.x and 6.x-2.x for Drupal does not properly restrict access to nodes, which allows remote attackers to read images of use… Email2image Patch available Fix from $1,6002013-03-27 HIGH 10.0 CVE-2013-0318 The admin page in the Banckle Chat module for Drupal does not properly restrict access, which allows remote attackers to bypass intended restrictions… Banckle Chat Mitigation only Fix from $1,9502013-03-27 MEDIUM 5.0 CVE-2013-0718 The Simeji application 4.8.1 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive informat… Simeji after 4.8.1 Fix from $1,6002013-03-27 MEDIUM 5.0 CVE-2013-0719 The ArtIME Japanese Input application 1.1.2 and earlier for Android uses weak permissions for unspecified files, which allows attackers to obtain sen… Artime Japanese Input after 1.1.2 Fix from $1,6002013-03-27 MEDIUM 5.0 CVE-2013-0720 The COBIME application before 0.9.4 for Android uses weak permissions for unspecified files, which allows attackers to obtain sensitive information v… Cobime after 0.9.3 Fix from $1,6002013-03-27 MEDIUM 5.0 CVE-2013-2300 The FlickWnn (aka OpenWnn/Flick support) application 2.02 and earlier for Android uses weak permissions for unspecified files, which allows attackers… Flickwnn after 2.02 Fix from $1,6002013-03-27 MEDIUM 6.5 CVE-2013-1836 Moodle 2.x through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not properly manage privileges for WebDAV repositories… Moodle Mitigation only Fix from $1,6002013-03-25 MEDIUM 5.0 CVE-2013-1830 user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles set… Fedora Patch available Fix from $1,6002013-03-25 HIGH 7.6 CVE-2013-0335 OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circu… Ubuntu Linux Mitigation only Fix from $1,9502013-03-22 MEDIUM 5.0 CVE-2013-2640 ajax.functions.php in the MailUp plugin before 1.3.2 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remo… Wp Mailup after 1.3.1 Fix from $1,6002013-03-22