Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
Cf Release CRITICAL 9.8
CVE-2017-4992

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions pr…

Fix: after 260
Fix from $2,300 2017-06-13
Debian Linux HIGH 8.8
CVE-2017-9324

In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o…

Fix: after 5.0.19
Fix from $1,950 2017-06-12
Personify360 CRITICAL 9.8
CVE-2017-7312

An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read exi…

Mitigation only
Fix from $2,300 2017-06-07
Pl\/java MEDIUM 6.5
CVE-2016-0767

PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath.

Fix: after 1.4.3
Fix from $1,600 2017-06-06
Pl\/java MEDIUM 6.5
CVE-2016-2192

PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.

Fix: after 1.4.3
Fix from $1,600 2017-06-06
X Pack HIGH 8.8
CVE-2017-8438

Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into …

Patch available
Fix from $1,950 2017-06-05
Foreman HIGH 8.8
CVE-2017-7505

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so…

Patch available
Fix from $1,950 2017-05-26
Policy Suite HIGH 7.8
CVE-2017-6623

A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an…

Mitigation only
Fix from $1,950 2017-05-18
Moodle MEDIUM 6.3
CVE-2017-7489

In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link.

Patch available
Fix from $1,600 2017-05-15
Mainframe Enablers Resourcepak Base CRITICAL 9.8
CVE-2017-4982

EMC Mainframe Enablers ResourcePak Base versions 7.6.0, 8.0.0, and 8.1.0 contains a fix for a privilege management vulnerability that could potential…

No fix yet
Fix from $2,300 2017-05-08
Proliant Ml10 Gen9 Server Firmware CRITICAL 9.8
CVE-2017-5689 KEVEPSS 92%

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and I…

Fix: 6.2.61.3535 / 9.1.41.3024+
Fix from $2,300 2017-05-02
Webmail HIGH 8.8
CVE-2017-8114

Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before …

Fix: 1.0.11 / 1.1.9+
Fix from $1,950 2017-04-29
Antivirus HIGH 7.5
CVE-2017-8308

In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of th…

Fix: after 12.3.2279
Fix from $1,950 2017-04-27
Interscan Web Security Virtual Appliance MEDIUM 6.5
CVE-2017-6339

Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,…

Fix: after 6.5
Fix from $1,600 2017-04-05
Tryton MEDIUM 5.3
CVE-2017-0360

file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root nam…

Mitigation only
Fix from $1,600 2017-04-04
Intermec Pc23 Firmware HIGH 8.8
CVE-2017-5671

Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin…

Fix: after 10.10.011406
Fix from $1,950 2017-03-29
Ubuntu Core MEDIUM 5.9
CVE-2017-6507

An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or syste…

Fix: after 2.11
Fix from $1,600 2017-03-24
Firejail HIGH 7.8
CVE-2017-5207

Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument.

Fix: 0.9.44.4+
Fix from $1,950 2017-03-23
Oxygenos MEDIUM 6.6
CVE-2017-5623

An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fast…

Fix: after 4.0.3
Fix from $1,600 2017-03-19
Oxygenos CRITICAL 9.8
CVE-2017-5624

An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform …

Fix: after 4.0.2
Fix from $2,300 2017-03-12
Netbackup HIGH 7.8
CVE-2017-6401

An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bp…

Fix: after 8.0
Fix from $1,950 2017-03-02
Camera Firmware CRITICAL 9.8
CVE-2017-6342EPSS 13%

An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and…

Mitigation only
Fix from $2,300 2017-02-27
Gpu Driver MEDIUM 6.5
CVE-2017-0310

All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileg…

Mitigation only
Fix from $1,600 2017-02-15
Xl Web Ii Controller CRITICAL 9.1
CVE-2017-5142

An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user wit…

Mitigation only
Fix from $2,300 2017-02-13
Firejail HIGH 8.8
CVE-2017-5940

Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing…

Fix: after 0.9.44.6
Fix from $1,950 2017-02-09
Xenserver MEDIUM 6.5
CVE-2017-5572

An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host datab…

Mitigation only
Fix from $1,600 2017-01-30
MySQL MEDIUM 6.5
CVE-2017-3257

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.34 and earli…

Fix: 10.0.29 / 10.1.21+
Fix from $1,600 2017-01-27
Openssh HIGH 7.0
CVE-2016-10010

sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to ga…

Fix: after 7.3
Fix from $1,950 2017-01-05
Windows 10 HIGH 7.8
CVE-2016-3376EPSS 13%

The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and …

Patch available
Fix from $1,950 2016-10-14
Linux Kernel HIGH 7.8
CVE-2016-2067

drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android con…

Fix: after 6.0.1
Fix from $1,950 2016-07-11