Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2013-0731 ajax.functions.php in the MailUp plugin before 1.3.3 for WordPress does not properly restrict access to unspecified Ajax functions, which allows remo… Wp Mailup after 1.3.2 Fix from $1,6002013-03-22 MEDIUM 6.2 CVE-2013-0665 Schweitzer Engineering Laboratories (SEL) AcSELerator QuickSet before 5.12.0.1 uses weak permissions for its Program Files directory, which allows lo… Acselerator Quickset after 5.12.0 Fix from $1,6002013-03-21 HIGH 7.2 CVE-2012-5938 The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for … Infosphere Information Server No fix yet Fix from $1,9502013-03-20 MEDIUM 6.0 CVE-2013-1863 Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which a… Samba Patch available Fix from $1,6002013-03-19 MEDIUM 6.0 CVE-2013-0226 The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticat… Keyboard Shortcut Utility Mitigation only Fix from $1,6002013-03-19 MEDIUM 5.0 CVE-2013-2263 Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via… Access Gateway No fix yet Fix from $1,6002013-03-19 MEDIUM 6.4 CVE-2013-2373 The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implemen… Spotfire Web Player Mitigation only Fix from $1,6002013-03-15 HIGH 7.5 CVE-2013-0080EPSS 19% Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and … Sharepoint Foundation Mitigation only Fix from $1,9502013-03-13 HIGH 7.5 CVE-2012-5629 The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502013-03-12 MEDIUM 6.9 CVE-2012-5660 abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbit… Automatic Bug Reporting Tool after 2.0.9 Fix from $1,6002013-03-12 MEDIUM 5.5 CVE-2012-6118 The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instan… Aeolus Conductor No fix yet Fix from $1,6002013-03-12 HIGH 7.2 CVE-2013-1050 The default configuration in gnome-screensaver 3.5.4 through 3.6.0 sets the AutostartCondition line to fallback mode in the .desktop file, which prev… Gnome Screensaver Mitigation only Fix from $1,9502013-03-08 HIGH 8.8 CVE-2013-0261 A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This … Essex Mitigation only Fix from $1,9502013-03-08 MEDIUM 6.9 CVE-2013-1775 sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions … Sudo after 10.10.4 Fix from $1,6002013-03-05 MEDIUM 6.9 CVE-2011-4355 GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, whic… Gdb after 7.4.1 Fix from $1,6002013-03-05 HIGH 9.0 CVE-2013-0706 NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which a… Universal Raid Utility after 2.31 Fix from $1,9502013-02-22 MEDIUM 6.5 CVE-2012-6355 IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivo… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-6356 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-6357 IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain pri… Maximo Asset Management Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.5 CVE-2012-3321 IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password. Smartcloud Control Desk Mitigation only Fix from $1,6002013-02-20 MEDIUM 6.2 CVE-2013-0268 The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by exec… Linux Kernel after 3.7.5 Fix from $1,6002013-02-18 HIGH 9.0 CVE-2013-1111 The Cisco ATA 187 Analog Telephone Adaptor with firmware 9.2.1.0 and 9.2.3.1 before ES build 4 does not properly implement access control, which allo… Ata 187 Analog Telephone Adaptor Firmware Mitigation only Fix from $1,9502013-02-13 MEDIUM 6.5 CVE-2013-0208 The boot-from-volume feature in OpenStack Compute (Nova) Folsom and Essex, when using nova-volumes, allows remote authenticated users to boot from ot… Ubuntu Linux Patch available Fix from $1,6002013-02-13 HIGH 10.0 CVE-2013-0073EPSS 30% The Windows Forms (aka WinForms) component in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly restrict the privileges of a… .net Framework Mitigation only Fix from $1,9502013-02-13 HIGH 7.5 CVE-2012-2292 The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the A… Rsa Archer Smartsuite Mitigation only Fix from $1,9502013-02-06 MEDIUM 5.8 CVE-2012-3370 The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platf… Jboss Enterprise Application Platform after 5.3.0 Fix from $1,6002013-02-05 MEDIUM 6.5 CVE-2012-0205 InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use … Infosphere Information Server Mitigation only Fix from $1,6002013-01-31 MEDIUM 6.5 CVE-2012-0701 The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8… Infosphere Datastage Mitigation only Fix from $1,6002013-01-31 MEDIUM 5.5 CVE-2012-6106 calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remot… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2012-6112 classes/GoogleSpell.php in the PHP Spellchecker (aka Google Spellchecker) addon before 2.0.6.1 for TinyMCE, as used in Moodle 2.1.x before 2.1.10, 2.… Moodle Patch available Fix from $1,6002013-01-27