Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Enterprise Linux Desktop HIGH 8.8
CVE-2013-0643 KEVEPSS 11%

The Firefox sandbox in Adobe Flash Player before 10.3.183.67 and 11.x before 11.6.602.171 on Windows and Mac OS X, and before 10.3.183.67 and 11.x be…

Fix: 10.3.183.67 / 11.2.202.273+
Fix from $1,950 2013-02-27
Chrome CRITICAL 9.6
CVE-2012-5376

The Inter-process Communication (IPC) implementation in Google Chrome before 22.0.1229.94 allows remote attackers to bypass intended sandbox restrict…

Fix: 22.0.1229.94+
Fix from $2,300 2012-10-11
Firefox HIGH 9.3
CVE-2012-3993EPSS 43%

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird E…

Fix: after 15.0.1
Fix from $1,950 2012-10-10
iOS HIGH 7.2
CVE-2012-0384

Cisco IOS 12.2 through 12.4 and 15.0 through 15.2 and IOS XE 2.1.x through 2.6.x and 3.1.xS before 3.1.2S, 3.2.xS through 3.4.xS before 3.4.2S, 3.5.x…

Mitigation only
Fix from $1,950 2012-03-29
Chrome HIGH 7.5
CVE-2011-3898

Google Chrome before 15.0.874.120, when Java Runtime Environment (JRE) 7 is used, does not request user confirmation before applet execution begins, …

Fix: 15.0.874.120+
Fix from $1,950 2011-11-11
Debian Linux MEDIUM 6.5
CVE-2011-1526

ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return valu…

Fix: 1.0.1+
Fix from $1,600 2011-07-11
Linux Kernel MEDIUM 6.2
CVE-2010-4258

The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users…

Fix: 2.6.36.2+
Fix from $1,600 2010-12-30
Linux Kernel MEDIUM 6.9
CVE-2010-4347

The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain pri…

Fix: 2.6.36.2+
Fix from $1,600 2010-12-22
Linux Kernel HIGH 7.2
CVE-2010-3301

The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on the x86_64 platform does not …

Fix: 2.6.36+
Fix from $1,950 2010-09-22
Linux Kernel MEDIUM 5.9
CVE-2009-2848

The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows …

Fix: after 2.6.29.5
Fix from $1,600 2009-08-18
Linux Kernel HIGH 7.8
CVE-2008-2931

The do_change_type function in fs/namespace.c in the Linux kernel before 2.6.22 does not verify that the caller has the CAP_SYS_ADMIN capability, whi…

Fix: 2.6.22+
Fix from $1,950 2008-07-09
Site Documentation MEDIUM 5.0
CVE-2008-2271

The Site Documentation Drupal module 5.x before 5.x-1.8 and 6.x before 6.x-1.1 allows remote authenticated users to gain privileges of other users by…

Fix: 5.x-1.8 / 6.x-1.1+
Fix from $1,600 2008-05-16
Debian Linux HIGH 7.2
CVE-2007-2444

Logic error in the SID/Name translation functionality in smbd in Samba 3.0.23d through 3.0.25pre2 allows local users to gain temporary privileges and…

Patch available
Fix from $1,950 2007-05-14
Windows 2000 HIGH 7.8
CVE-2002-0367 KEV

smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to other programs, which allows loca…

Patch available
Fix from $1,950 2002-06-25
Exchange Server MEDIUM 6.4
CVE-2002-0049EPSS 13%

Microsoft Exchange Server 2000 System Attendant gives "Everyone" group privileges to the WinReg key, which could allow remote attackers to read or mo…

Patch available
Fix from $1,600 2002-03-08
Nfs HIGH 8.4
CVE-1999-0084

Certain NFS servers allow users to use mknod to gain privileges by creating a writable kmem device and setting the UID to 0.

Mitigation only
Fix from $1,950 1990-05-01