Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Plone MEDIUM 5.9
CVE-2015-7315

Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to…

Patch available
Fix from $1,600 2017-09-25
Fedora HIGH 7.5
CVE-2015-1854

389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn ca…

Fix: after 1.3.3.9
Fix from $1,950 2017-09-19
Business Process Manager MEDIUM 6.5
CVE-2015-0110

IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to byp…

Mitigation only
Fix from $1,600 2017-09-15
Soplanning MEDIUM 5.3
CVE-2014-8677

The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databa…

Fix: after 1.32
Fix from $1,600 2017-08-31
Atlas HIGH 7.5
CVE-2016-8752

Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI…

Mitigation only
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3653

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files wi…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3654

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-3657

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Adm…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Clearpass HIGH 7.2
CVE-2015-4649

Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un…

Fix: after 6.4.6
Fix from $1,950 2017-08-29
Satellite MEDIUM 6.1
CVE-2014-8168

Red Hat Satellite 6 allows local users to access mongod and delete pulp_database.

Mitigation only
Fix from $1,600 2017-08-28
Xbindkeys Config CRITICAL 9.8
CVE-2014-9513

Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2017-08-28
Enterprise Virtualization Manager MEDIUM 5.9
CVE-2015-5293

Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m…

Fix: after 3.6.0
Fix from $1,600 2017-08-24
Android CRITICAL 9.8
CVE-2015-9064

In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request be…

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2016-10382

In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient.

Mitigation only
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9040

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API.

No fix yet
Fix from $2,300 2017-08-18
Android CRITICAL 9.8
CVE-2015-9047

In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup.

No fix yet
Fix from $2,300 2017-08-18
Xhq Server MEDIUM 6.5
CVE-2017-6866

A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileg…

Fix: after 5.0.0.1
Fix from $1,600 2017-08-07
Imagemagick HIGH 8.8
CVE-2014-9827

coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.

Fix: 6.9.4-0+
Fix from $1,950 2017-08-07
Imagemagick HIGH 8.8
CVE-2014-9828

coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.

Fix: 6.9.4-0+
Fix from $1,950 2017-08-07
Imagemagick HIGH 8.8
CVE-2014-9830

coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.

Fix: 6.9.4-0+
Fix from $1,950 2017-08-07
Imagemagick HIGH 8.8
CVE-2014-9831

coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.

Fix: 6.9.4-0+
Fix from $1,950 2017-08-07
Snapcenter Server HIGH 8.1
CVE-2015-7887

NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.

Patch available
Fix from $1,950 2017-08-07
Sel 3620 Firmware CRITICAL 10.0
CVE-2017-7928

An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and…

Mitigation only
Fix from $2,300 2017-08-07
Swisscom Internet Box Firmware HIGH 7.5
CVE-2016-10042

Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguratio…

Mitigation only
Fix from $1,950 2017-06-29
Android MEDIUM 5.5
CVE-2015-3840

The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS a…

Fix: after 5.1.1
Fix from $1,600 2017-06-27
Samsung Mobile MEDIUM 5.5
CVE-2015-7895

Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Samsung Mobile MEDIUM 5.5
CVE-2015-7898

Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).

No fix yet
Fix from $1,600 2017-06-27
Stalin MEDIUM 5.5
CVE-2015-8697

stalin 0.11-5 allows local users to write to arbitrary files.

No fix yet
Fix from $1,600 2017-06-27
Helion Openstack Glance HIGH 8.4
CVE-2016-4383

The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated user…

Mitigation only
Fix from $1,950 2017-06-27
Freeipa HIGH 7.5
CVE-2016-5414

FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services.

Patch available
Fix from $1,950 2017-06-27