Vulnerability index

Browse CVEs

3,016 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Privilege ManagementCWE-269 × clear
CRITICAL 9.8 CVE-2017-4992 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions pr… Cf Release after 260 Fix from $2,3002017-06-13 HIGH 8.8 CVE-2017-9324 In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable o… Debian Linux after 5.0.19 Fix from $1,9502017-06-12 CRITICAL 9.8 CVE-2017-7312 An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, anyone can add a vendor account or read exi… Personify360 Mitigation only Fix from $2,3002017-06-07 MEDIUM 6.5 CVE-2016-0767 PostgreSQL PL/Java before 1.5.0 allows remote authenticated users with USAGE permission on the public schema to alter the public schema classpath. Pl\/java after 1.4.3 Fix from $1,6002017-06-06 MEDIUM 6.5 CVE-2016-2192 PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own. Pl\/java after 1.4.3 Fix from $1,6002017-06-06 HIGH 8.8 CVE-2017-8438 Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into … X Pack Patch available Fix from $1,9502017-06-05 HIGH 8.8 CVE-2017-7505 Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so… Foreman Patch available Fix from $1,9502017-05-26 HIGH 7.8 CVE-2017-6623 A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an… Policy Suite Mitigation only Fix from $1,9502017-05-18 MEDIUM 6.3 CVE-2017-7489 In Moodle 2.x and 3.x, remote authenticated users can take ownership of arbitrary blogs by editing an external blog link. Moodle Patch available Fix from $1,6002017-05-15 CRITICAL 9.8 CVE-2017-4982 EMC Mainframe Enablers ResourcePak Base versions 7.6.0, 8.0.0, and 8.1.0 contains a fix for a privilege management vulnerability that could potential… Mainframe Enablers Resourcepak Base No fix yet Fix from $2,3002017-05-08 CRITICAL 9.8 CVE-2017-5689 KEVEPSS 92% An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and I… Proliant Ml10 Gen9 Server Firmware 6.2.61.3535 / 9.1.41.3024+ Fix from $2,3002017-05-02 HIGH 8.8 CVE-2017-8114 Roundcube Webmail allows arbitrary password resets by authenticated users. This affects versions before 1.0.11, 1.1.x before 1.1.9, and 1.2.x before … Webmail 1.0.11 / 1.1.9+ Fix from $1,9502017-04-29 HIGH 7.5 CVE-2017-8308 In Avast Antivirus before v17, an unprivileged user (and thus malware or a virus) can mark an arbitrary process as Trusted from the perspective of th… Antivirus after 12.3.2279 Fix from $1,9502017-04-27 MEDIUM 6.5 CVE-2017-6339 Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation,… Interscan Web Security Virtual Appliance after 6.5 Fix from $1,6002017-04-05 MEDIUM 5.3 CVE-2017-0360 file_open in Tryton 3.x and 4.x through 4.2.2 allows remote authenticated users with certain permissions to read arbitrary files via a "same root nam… Tryton Mitigation only Fix from $1,6002017-04-04 HIGH 8.8 CVE-2017-5671 Honeywell Intermec PM23, PM42, PM43, PC23, PC43, PD43, and PC42 industrial printers before 10.11.013310 and 10.12.x before 10.12.013309 have /usr/bin… Intermec Pc23 Firmware after 10.10.011406 Fix from $1,9502017-03-29 MEDIUM 5.9 CVE-2017-6507 An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or syste… Ubuntu Core after 2.11 Fix from $1,6002017-03-24 HIGH 7.8 CVE-2017-5207 Firejail before 0.9.44.4, when running a bandwidth command, allows local users to gain root privileges via the --shell argument. Firejail 0.9.44.4+ Fix from $1,9502017-03-23 MEDIUM 6.6 CVE-2017-5623 An issue was discovered in OxygenOS before 4.1.0 on OnePlus 3 and 3T devices. The attacker can change the bootmode of the device by issuing the 'fast… Oxygenos after 4.0.3 Fix from $1,6002017-03-19 CRITICAL 9.8 CVE-2017-5624 An issue was discovered in OxygenOS before 4.0.3 for OnePlus 3 and 3T. The attacker can persistently make the (locked) bootloader start the platform … Oxygenos after 4.0.2 Fix from $2,3002017-03-12 HIGH 7.8 CVE-2017-6401 An issue was discovered in Veritas NetBackup before 8.0 and NetBackup Appliance before 3.0. Local arbitrary command execution can occur when using bp… Netbackup after 8.0 Fix from $1,9502017-03-02 CRITICAL 9.8 CVE-2017-6342EPSS 13% An issue was discovered on Dahua DHI-HCVR7216A-S3 devices with NVR Firmware 3.210.0001.10 2016-06-06, Camera Firmware 2.400.0000.28.R 2016-03-29, and… Camera Firmware Mitigation only Fix from $2,3002017-02-27 MEDIUM 6.5 CVE-2017-0310 All versions of NVIDIA GPU Display Driver contain a vulnerability in the kernel mode layer handler where improper access controls allowing unprivileg… Gpu Driver Mitigation only Fix from $1,6002017-02-15 CRITICAL 9.1 CVE-2017-5142 An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user wit… Xl Web Ii Controller Mitigation only Fix from $2,3002017-02-13 HIGH 8.8 CVE-2017-5940 Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing… Firejail after 0.9.44.6 Fix from $1,9502017-02-09 MEDIUM 6.5 CVE-2017-5572 An issue was discovered in Linux Foundation xapi in Citrix XenServer through 7.0. An authenticated read-only administrator can corrupt the host datab… Xenserver Mitigation only Fix from $1,6002017-01-30 MEDIUM 6.5 CVE-2017-3257 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB). Supported versions that are affected are 5.6.34 and earli… MySQL 10.0.29 / 10.1.21+ Fix from $1,6002017-01-27 HIGH 7.0 CVE-2016-10010 sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which might allow local users to ga… Openssh after 7.3 Fix from $1,9502017-01-05 HIGH 7.8 CVE-2016-3376EPSS 13% The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and … Windows 10 Patch available Fix from $1,9502016-10-14 HIGH 7.8 CVE-2016-2067 drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android con… Linux Kernel after 6.0.1 Fix from $1,9502016-07-11