Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Fedora HIGH 7.5
CVE-2016-6342

elog 3.1.1 allows remote attackers to post data as any username in the logbook.

Mitigation only
Fix from $1,950 2017-06-27
Epmp 1000 Firmware MEDIUM 6.8
CVE-2017-7918EPSS 7%

An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able …

Mitigation only
Fix from $1,600 2017-06-21
Android MEDIUM 5.5
CVE-2016-10335

In all Android releases from CAF using the Linux kernel, libtomcrypt was updated.

No fix yet
Fix from $1,600 2017-06-13
Android HIGH 7.8
CVE-2014-9961

In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write pr…

Mitigation only
Fix from $1,950 2017-06-13
Android MEDIUM 5.5
CVE-2015-9021

In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled.

Mitigation only
Fix from $1,600 2017-06-13
Android MEDIUM 5.5
CVE-2015-9024

In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications.

Mitigation only
Fix from $1,600 2017-06-13
Android HIGH 7.8
CVE-2015-9029

In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.

Mitigation only
Fix from $1,950 2017-06-13
Android MEDIUM 5.5
CVE-2016-10333

In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS.

No fix yet
Fix from $1,600 2017-06-13
Android MEDIUM 5.5
CVE-2016-10334

In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten.

No fix yet
Fix from $1,600 2017-06-13
Wnc01wh Firmware HIGH 8.8
CVE-2016-7824

Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug opti…

Fix: after 1.0.0.8
Fix from $1,950 2017-06-09
Dezie HIGH 7.5
CVE-2016-7833

Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file v…

Mitigation only
Fix from $1,950 2017-06-09
Wfs Sr01 Firmware HIGH 7.5
CVE-2016-7807

I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inse…

Fix: after 1.10
Fix from $1,950 2017-06-09
Cg Wlr300nx Firmware HIGH 8.8
CVE-2016-7811

Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary op…

Fix: after 1.20
Fix from $1,950 2017-06-09
Adblock CRITICAL 10.0
CVE-2015-2692

AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.

Fix: after 2.20.1
Fix from $2,300 2017-06-08
Security Key Lifecycle Manager HIGH 8.1
CVE-2016-6098

IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be …

Patch available
Fix from $1,950 2017-06-08
Pulp MEDIUM 5.5
CVE-2016-3107

The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, w…

Fix: after 2.8.2-1
Fix from $1,600 2017-06-08
Pulp HIGH 7.5
CVE-2016-3112

client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows r…

Fix: after 2.8.2-1
Fix from $1,950 2017-06-08
Markdown It MEDIUM 5.3
CVE-2015-3295

markdown-it before 4.1.0 does not block data: URLs.

Patch available
Fix from $1,600 2017-06-07
Websphere Mq MEDIUM 5.5
CVE-2016-6089

IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to i…

Patch available
Fix from $1,600 2017-06-07
PostgreSQL HIGH 7.5
CVE-2016-0768

PostgreSQL PL/Java after 9.0 does not honor access controls on large objects.

Fix: after 9.0
Fix from $1,950 2017-06-06
Android HIGH 7.8
CVE-2015-9006

In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially e…

Patch available
Fix from $1,950 2017-06-06
X Pack HIGH 8.8
CVE-2017-8438

Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into …

Patch available
Fix from $1,950 2017-06-05
Ltda Me Laquis Scada HIGH 7.3
CVE-2017-6016

An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions…

Fix: after 4.1
Fix from $1,950 2017-05-19
Android HIGH 7.8
CVE-2016-10237

If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases …

Patch available
Fix from $1,950 2017-05-16
Oxygenos HIGH 7.5
CVE-2016-10370

An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does n…

No fix yet
Fix from $1,950 2017-05-11
Lxterminal HIGH 7.8
CVE-2016-10369

unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing termi…

Fix: after 0.3.0
Fix from $1,950 2017-05-08
Bigfix Remote Control HIGH 7.5
CVE-2016-2930

IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID…

Patch available
Fix from $1,950 2017-05-03
Maximo Asset Management HIGH 8.4
CVE-2016-9976

IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-craf…

Patch available
Fix from $1,950 2017-05-03
Threat Discovery Appliance CRITICAL 9.8
CVE-2016-8584EPSS 6%

Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication…

Fix: after 2.6.1062
Fix from $2,300 2017-04-28
Threat Discovery Appliance HIGH 7.3
CVE-2016-8587

dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi…

Fix: after 2.6.1062
Fix from $1,950 2017-04-28