Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2012-0228 Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended … Wonderware Information Server Mitigation only Fix from $1,9502012-04-02 HIGH 8.3 CVE-2012-1515 VMware ESXi 3.5, 4.0, and 4.1 and ESX 3.5, 4.0, and 4.1 do not properly implement port-based I/O operations, which allows guest OS users to gain gues… Esxi Mitigation only Fix from $1,9502012-04-02 HIGH 10.0 CVE-2012-1797 IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors. Db2 Mitigation only Fix from $1,9502012-03-20 HIGH 7.5 CVE-2011-5083 Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uplo… Dotclear No fix yet Fix from $1,9502012-03-19 MEDIUM 5.0 CVE-2012-0326 The twicca application 0.7.0 through 0.9.30 for Android does not properly restrict the use of network privileges, which allows remote attackers to re… Twicca Patch available Fix from $1,6002012-03-17 HIGH 7.2 CVE-2012-1508 The XPDM display driver in VMware ESXi 4.0, 4.1, and 5.0; VMware ESX 4.0 and 4.1; and VMware View before 4.6.1 allows guest OS users to gain guest OS… Esx after 4.6.0 Fix from $1,9502012-03-16 MEDIUM 6.4 CVE-2011-4939 The pidgin_conv_chat_rename_user function in gtkconv.c in Pidgin before 2.10.2 allows remote attackers to cause a denial of service (NULL pointer der… Pidgin after 2.10.1 Fix from $1,6002012-03-15 HIGH 7.5 CVE-2012-0398 EMC Documentum eRoom before 7.4.4 does not properly validate session cookies, which allows remote attackers to hijack or replay sessions via unspecif… Documentum Eroom after 7.4.3 Fix from $1,9502012-03-15 MEDIUM 6.8 CVE-2012-0458 Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 1… Firefox after 10.0 Fix from $1,6002012-03-14 HIGH 7.5 CVE-2012-0459 The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Th… Firefox after 2.7 Fix from $1,9502012-03-14 MEDIUM 6.4 CVE-2012-0460 Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey bef… Firefox after 2.7 Fix from $1,6002012-03-14 HIGH 9.3 CVE-2012-0643 The kernel in Apple iOS before 5.1 does not properly handle debug system calls, which allows remote attackers to bypass sandbox restrictions and exec… Iphone Os 5.1+ Fix from $1,9502012-03-08 MEDIUM 5.0 CVE-2012-0585 The Private Browsing feature in Safari in Apple iOS before 5.1 allows remote attackers to bypass intended privacy settings and insert history entries… Iphone Os 5.1+ Fix from $1,6002012-03-08 HIGH 9.0 CVE-2012-0366 Cisco Unity Connection before 7.1.3b(Su2) allows remote authenticated users to change the administrative password by leveraging the Help Desk Adminis… Unity Connection after 7.1 Fix from $1,9502012-03-01 HIGH 9.3 CVE-2012-0371 Cisco Wireless LAN Controller (WLC) devices with software 4.x, 5.x, 6.0, and 7.0 before 7.0.220.4, when CPU-based ACLs are enabled, allow remote atta… Wireless Lan Controller Software Mitigation only Fix from $1,9502012-03-01 HIGH 7.8 CVE-2012-0364 Cisco SRP 520 series devices with firmware before 1.1.26 and SRP 520W-U and 540 series devices with firmware before 1.2.4 allow remote attackers to r… Small Business Srp520 Series Firmware after 1.01.24 Fix from $1,9502012-02-25 HIGH 10.0 CVE-2011-4525 Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client syst… Advantech Webaccess after 6.0 Fix from $1,9502012-02-21 HIGH 7.5 CVE-2012-1195EPSS 68% Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkM… Lenovo Thinkmanagement Console Mitigation only Fix from $1,9502012-02-18 MEDIUM 5.0 CVE-2012-1078 The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors… Sysutils after 1.0.3 Fix from $1,6002012-02-14 MEDIUM 5.0 CVE-2012-1056 The Forward module 6.x-1.x before 6.x-1.21 and 7.x-1.x before 7.x-1.3 for Drupal does not properly enforce permissions for (1) Recent forwards, (2) M… Forward Patch available Fix from $1,6002012-02-14 HIGH 9.3 CVE-2011-4039 Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assi… Dream Report after 3.43 Fix from $1,9502012-02-10 MEDIUM 6.5 CVE-2011-5078 The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentic… M Business Anywhere Mitigation only Fix from $1,6002012-02-08 HIGH 7.5 CVE-2012-1011EPSS 9% actions.php in the AllWebMenus plugin 1.1.8 for WordPress allows remote attackers to bypass intended access restrictions to upload and execute arbitr… Allwebmenus Plugin Patch available Fix from $1,9502012-02-07 HIGH 10.0 CVE-2011-4509 The HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panel… Wincc Flexible Mitigation only Fix from $1,9502012-02-03 MEDIUM 6.8 CVE-2011-3458 QuickTime in Apple Mac OS X before 10.7.3 does not prevent access to uninitialized memory locations, which allows remote attackers to execute arbitra… Mac Os X after 10.7.2 Fix from $1,6002012-02-02 MEDIUM 5.0 CVE-2012-0445 Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to bypass the HTML5 frame-navigation po… Firefox after 2.7 Fix from $1,6002012-02-01 HIGH 7.5 CVE-2011-4608 mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allo… Jboss Enterprise Application Platform Mitigation only Fix from $1,9502012-01-27 MEDIUM 6.9 CVE-2012-0056EPSS 11% The mem_write function in the Linux kernel before 3.2.2, when ASLR is disabled, does not properly check permissions when writing to /proc/<pid>/mem, … Linux Kernel 3.0.18 / 3.2.2+ Fix from $1,6002012-01-27 MEDIUM 6.8 CVE-2011-3479 Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable per… Pcanywhere Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4704 The Voxofon (com.voxofon) application before 2.5.2 for Android does not properly protect data, which allows remote attackers to read or modify SMS in… Voxofon after 2.4.3 Fix from $1,6002012-01-25