Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Watson Developer Cloud CRITICAL 9.8
CVE-2016-0391

The IBM Watson Developer Cloud services on Bluemix platforms do not properly generate random numbers for service-instance credentials, which makes it…

Mitigation only
Fix from $2,300 2016-07-02
Business Process Manager MEDIUM 6.5
CVE-2016-0349

IBM Business Process Manager 8.5.6 through 8.5.6.2 and 8.5.7 before 8.5.7.CF201606 allows remote authenticated users to bypass intended access restri…

Mitigation only
Fix from $1,600 2016-06-30
Opera Mail HIGH 8.8
CVE-2016-5101

Unspecified vulnerability in Opera Mail before 2016-02-16 on Windows allows user-assisted remote attackers to execute arbitrary code via a crafted e-…

Mitigation only
Fix from $1,950 2016-06-29
Linux Kernel MEDIUM 5.5
CVE-2016-1237

nfsd in the Linux kernel through 4.6.3 allows local users to bypass intended file-permission restrictions by setting a POSIX ACL, related to nfs2acl.…

Fix: after 4.6.3
Fix from $1,600 2016-06-29
Domino HIGH 8.1
CVE-2016-0304

The Java Console in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6, when a certain unsupported configuration involving UNC share pat…

Mitigation only
Fix from $1,950 2016-06-29
Linux Kernel HIGH 7.1
CVE-2016-3713

The msr_mtrr_valid function in arch/x86/kvm/mtrr.c in the Linux kernel before 4.6.1 supports MSR 0x2f8, which allows guest OS users to read or write …

Fix: after 4.6
Fix from $1,950 2016-06-27
Linux Kernel Rt HIGH 8.1
CVE-2016-3707

The icmp_check_sysrq function in net/ipv4/icmp.c in the kernel.org projects/rt patches for the Linux kernel, as used in the kernel-rt package before …

Fix: after 3.10.0
Fix from $1,950 2016-06-27
Domino HIGH 7.8
CVE-2016-0279

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2016-06-26
Domino HIGH 7.8
CVE-2016-0278

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2016-06-26
Domino HIGH 7.8
CVE-2016-0277

Heap-based buffer overflow in the KeyView PDF filter in IBM Domino 8.5.x before 8.5.3 FP6 IF13 and 9.x before 9.0.1 FP6 allows remote attackers to ex…

Mitigation only
Fix from $1,950 2016-06-26
Garoon MEDIUM 6.5
CVE-2016-1190

Cybozu Garoon 3.1 through 4.2 allows remote authenticated users to bypass intended restrictions on MultiReport reading via unspecified vectors.

Mitigation only
Fix from $1,600 2016-06-25
Documentum Administrator MEDIUM 6.3
CVE-2016-0914

EMC Documentum WebTop 6.8 before Patch 13 and 6.8.1 before Patch 02, Documentum Administrator 7.x before 7.2 Patch 13, Documentum Capital Projects 1.…

Mitigation only
Fix from $1,600 2016-06-23
Japan Connected Free Wi Fi MEDIUM 5.6
CVE-2016-4811

The NTT Broadband Platform Japan Connected-free Wi-Fi application 1.15.1 and earlier for Android and 1.13.0 and earlier for iOS allows man-in-the-mid…

Mitigation only
Fix from $1,600 2016-06-19
Elastic Storage Server HIGH 8.4
CVE-2016-0392

IBM General Parallel File System (GPFS) in GPFS Storage Server 2.0.0 through 2.0.7 and Elastic Storage Server 2.5.x through 2.5.5, 3.x before 3.5.5, …

No fix yet
Fix from $1,950 2016-06-19
Netcommons HIGH 8.8
CVE-2016-4813

NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account.

Fix: after 2.4.2.1
Fix from $1,950 2016-06-19
Honor Ws851 Firmware HIGH 7.5
CVE-2016-5366

Huawei Honor WS851 routers with software 1.1.21.1 and earlier allow remote attackers to modify configuration data via vectors related to a "file inje…

Fix: after 1.1.21.1
Fix from $1,950 2016-06-14
Enterprise Linux Desktop HIGH 8.1
CVE-2016-3698

libndp before 1.6, as used in NetworkManager, does not properly validate the origin of Neighbor Discovery Protocol (NDP) messages, which allows remot…

Patch available
Fix from $1,950 2016-06-13
Leap HIGH 7.5
CVE-2014-9773

modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, …

Fix: after 7.2.6
Fix from $1,950 2016-06-13
Xenserver CRITICAL 9.8
CVE-2016-5302

Citrix XenServer 7.0 before Hotfix XS70E003, when a deployment has been upgraded from an earlier release, might allow remote attackers on the managem…

Fix: after 7.0
Fix from $2,300 2016-06-13
Ubuntu Linux MEDIUM 5.3
CVE-2016-5104

The socket_create function in common/socket.c in libimobiledevice and libusbmuxd allows remote attackers to bypass intended access restrictions and c…

Fix: after 1.2.0
Fix from $1,600 2016-06-13
Bladelogic Server Automation Console HIGH 7.5
CVE-2016-1543EPSS 72%

The RPC API in the RSCD agent in BMC BladeLogic Server Automation (BSA) 8.2.x, 8.3.x, 8.5.x, 8.6.x, and 8.7.x on Linux and UNIX allows remote attacke…

Patch available
Fix from $1,950 2016-06-13
Ubuntu Linux HIGH 8.8
CVE-2016-2831

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allo…

Fix: after 46.0.1
Fix from $1,950 2016-06-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-2829

Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission request…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Ubuntu Linux MEDIUM 6.5
CVE-2016-2825

Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Debian Linux MEDIUM 6.5
CVE-2016-2822

Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent m…

Fix: after 46.0.1
Fix from $1,600 2016-06-13
Puppet CRITICAL 9.8
CVE-2016-2785

Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass i…

Patch available
Fix from $2,300 2016-06-10
Pcm600 MEDIUM 6.5
CVE-2016-4524

ABB PCM600 before 2.7 improperly stores OPC Server IEC61850 passwords in unspecified temporary circumstances, which allows local users to obtain sens…

Fix: after 2.6
Fix from $1,600 2016-06-10
Bac 5051e Firmware MEDIUM 5.3
CVE-2016-4495

KMC Controls BAC-5051E devices with firmware before E0.2.0.2 allow remote attackers to bypass intended access restrictions and read a configuration f…

Mitigation only
Fix from $1,600 2016-06-10
Enterprise Linux HIGH 7.1
CVE-2016-2150

SPICE allows local guest OS users to read from or write to arbitrary host memory locations via crafted primary surface parameters, a similar issue to…

Mitigation only
Fix from $1,950 2016-06-09
Ubuntu Linux MEDIUM 5.5
CVE-2016-1581

LXD before 2.0.2 uses world-readable permissions for /var/lib/lxd/zfs.img when setting up a loop based ZFS pool, which allows local users to copy and…

Fix: after 2.0.1
Fix from $1,600 2016-06-09