Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2012-6102 lib.php in the Submission comments plugin in the Assignment module in Moodle 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allows remote attackers to rea… Moodle Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2013-0651 The Portal installation process in GE Intelligent Platforms Proficy Real-Time Information Portal stores sensitive information under the web root with… Intelligent Platforms Proficy Real Time Information Portal Mitigation only Fix from $1,6002013-01-27 MEDIUM 5.0 CVE-2013-0652 GE Intelligent Platforms Proficy Real-Time Information Portal does not restrict access to methods of an unspecified Java class, which allows remote a… Intelligent Platforms Proficy Real Time Information Portal Mitigation only Fix from $1,6002013-01-27 HIGH 9.0 CVE-2013-1105 Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote a… Wireless Lan Controller Software Mitigation only Fix from $1,9502013-01-24 CRITICAL 9.8 CVE-2012-6068EPSS 5% The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via … Codesys Runtime System Mitigation only Fix from $2,3002013-01-21 HIGH 7.2 CVE-2012-2291 EMC Avamar Client 4.x, 5.x, and 6.x on HP-UX and Mac OS X, and the EMC Avamar plugin 4.x, 5.x, and 6.x for Oracle, uses world-writable permissions fo… Avamar Mitigation only Fix from $1,9502013-01-21 MEDIUM 6.3 CVE-2012-5717 Cisco Adaptive Security Appliances (ASA) devices with firmware 8.x through 8.4(1) do not properly manage SSH sessions, which allows remote authentica… Adaptive Security Appliance Software Mitigation only Fix from $1,6002013-01-18 MEDIUM 5.0 CVE-2012-5444 Cisco TelePresence Video Communication Server (VCS) X7.0.3 does not properly process certain search rules, which allows remote attackers to create co… Telepresence Video Communication Servers Software Mitigation only Fix from $1,6002013-01-17 HIGH 7.5 CVE-2013-0838 Google Chrome before 24.0.1312.52 on Linux uses weak permissions for shared memory segments, which has unspecified impact and attack vectors. Chrome after 24.0.1312.51 Fix from $1,9502013-01-15 MEDIUM 5.0 CVE-2012-5146 Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL. Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 MEDIUM 5.0 CVE-2012-5155 Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote … Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 MEDIUM 6.4 CVE-2013-0829 Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrict… Chrome after 24.0.1312.51 Fix from $1,6002013-01-15 MEDIUM 6.4 CVE-2013-0155EPSS 8% Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between … Rails 3.0.19 / 3.1.10+ Fix from $1,6002013-01-13 MEDIUM 5.8 CVE-2013-0751 Mozilla Firefox before 18.0 on Android and SeaMonkey before 2.15 do not restrict a touch event to a single IFRAME element, which allows remote attack… Firefox after 17.0.1 Fix from $1,6002013-01-13 HIGH 10.0 CVE-2013-0622EPSS 6% Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unsp… Acrobat Mitigation only Fix from $1,9502013-01-10 HIGH 10.0 CVE-2013-0624 Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allow attackers to bypass intended access restrictions via unsp… Acrobat Patch available Fix from $1,9502013-01-10 MEDIUM 6.5 CVE-2012-4549 A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInter… Jboss Enterprise Application Platform after 6.0.0 Fix from $1,6002013-01-05 MEDIUM 5.3 CVE-2012-4550 A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system d… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002013-01-05 MEDIUM 5.5 CVE-2012-5603 proxies_controller.rb in Katello in Red Hat CloudForms before 1.1 does not properly check permissions, which allows remote authenticated users to rea… Cloudforms after 1.0 Fix from $1,6002013-01-04 MEDIUM 5.0 CVE-2012-5651 Drupal 6.x before 6.27 and 7.x before 7.18 displays information for blocked users, which might allow remote attackers to obtain sensitive information… Drupal Patch available Fix from $1,6002013-01-03 MEDIUM 5.0 CVE-2012-5655 The Context module 6.x-3.x before 6.x-3.1 and 7.x-3.x before 7.x-3.0-beta6 for Drupal does not properly restrict access to block content, which allow… Context Patch available Fix from $1,6002013-01-03 MEDIUM 5.0 CVE-2012-6462 Opera before 12.10 does not properly implement the Cross-Origin Resource Sharing (CORS) specification, which allows remote attackers to bypass intend… Opera Browser after 12.10 Fix from $1,6002013-01-02 HIGH 7.5 CVE-2012-6426 LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended … Lemonldap\ after 1.2.2 Fix from $1,9502013-01-01 MEDIUM 6.4 CVE-2012-6431 Symfony 2.0.x before 2.0.20 does not process URL encoded data consistently within the Routing and Security components, which allows remote attackers … Symfony Mitigation only Fix from $1,6002012-12-27 MEDIUM 6.8 CVE-2012-6432 Symfony 2.0.x before 2.0.20, 2.1.x before 2.1.5, and 2.2-dev, when the internal routes configuration is enabled, allows remote attackers to access ar… Symfony Mitigation only Fix from $1,6002012-12-27 HIGH 7.5 CVE-2012-4816 IBM Rational Automation Framework (RAF) 3.x through 3.0.0.5 allows remote attackers to bypass intended Env Gen Wizard (aka Environment Generation Wiz… Rational Automation Framework Mitigation only Fix from $1,9502012-12-26 HIGH 7.2 CVE-2012-5951 Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to t… Tivoli Netview Mitigation only Fix from $1,9502012-12-26 HIGH 7.5 CVE-2012-5469EPSS 24% The Portable phpMyAdmin plugin before 1.3.1 for WordPress allows remote attackers to bypass authentication and obtain phpMyAdmin console access via a… phpMyAdmin No fix yet Fix from $1,9502012-12-20 MEDIUM 5.0 CVE-2012-5574 lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request. Symfony after 1.4.19 Fix from $1,6002012-12-18 HIGH 9.3 CVE-2012-6422EPSS 15% The kernel in Samsung Galaxy S2, Galaxy Note 2, MEIZU MX, and possibly other Android devices, when running an Exynos 4210 or 4412 processor, uses wea… Mx No fix yet Fix from $1,9502012-12-18