Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Chrome HIGH 7.5
CVE-2016-1656

The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unsp…

Fix: after 49.0.2623.112
Fix from $1,950 2016-04-18
Libvirt MEDIUM 6.5
CVE-2015-5247

The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s…

Mitigation only
Fix from $1,600 2016-04-14
Ubuntu Linux MEDIUM 5.9
CVE-2011-4600

The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks…

Mitigation only
Fix from $1,600 2016-04-14
Hana HIGH 7.3
CVE-2016-4018

The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to o…

Mitigation only
Fix from $1,950 2016-04-14
Xen HIGH 8.2
CVE-2015-8550

Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privilege…

Mitigation only
Fix from $1,950 2016-04-14
Git CRITICAL 9.8
CVE-2015-7545EPSS 19%

The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x befo…

Fix: after 2.3.9
Fix from $2,300 2016-04-13
Windows 7 HIGH 7.8
CVE-2016-0153EPSS 21%

OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8…

Mitigation only
Fix from $1,950 2016-04-12
Windows 10 CRITICAL 9.3
CVE-2016-0088EPSS 8%

Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via …

Mitigation only
Fix from $2,300 2016-04-12
Drupal HIGH 7.5
CVE-2016-3165

The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access re…

Patch available
Fix from $1,950 2016-04-12
Drupal HIGH 8.1
CVE-2016-3162

The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or s…

Patch available
Fix from $1,950 2016-04-12
Salt HIGH 8.1
CVE-2016-1866

Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary co…

Mitigation only
Fix from $1,950 2016-04-12
Password Manager CRITICAL 9.8
CVE-2016-3987EPSS 22%

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef…

No fix yet
Fix from $2,300 2016-04-12
Pulse Connect Secure MEDIUM 6.5
CVE-2016-3985

The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remot…

Mitigation only
Fix from $1,600 2016-04-12
Active Response MEDIUM 5.1
CVE-2016-3984

The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333),…

Fix: after 10.0.1
Fix from $1,600 2016-04-08
P8 Firmware HIGH 7.8
CVE-2015-8681

The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92…

Mitigation only
Fix from $1,950 2016-04-07
P8 HIGH 7.8
CVE-2015-8680

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10…

Mitigation only
Fix from $1,950 2016-04-07
Mate S Firmware MEDIUM 5.5
CVE-2015-8679

The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before…

Mitigation only
Fix from $1,600 2016-04-07
Mate S Firmware HIGH 7.8
CVE-2015-8307

The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10…

Patch available
Fix from $1,950 2016-04-07
Integrated Architecture Builder MEDIUM 6.3
CVE-2016-2277

IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbit…

Fix: after 9.6.0.7
Fix from $1,600 2016-04-06
Eg2 Web Control HIGH 7.5
CVE-2016-2272

Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.

Fix: after 4.04p
Fix from $1,950 2016-04-06
Tivoli Storage Manager Fastback HIGH 7.5
CVE-2015-8523

The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) …

Mitigation only
Fix from $1,950 2016-04-05
Iphone Os MEDIUM 6.2
CVE-2016-1760

The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary…

Fix: after 9.2.1
Fix from $1,600 2016-03-29
Informix Dynamic Server HIGH 7.8
CVE-2016-0226

The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3…

Patch available
Fix from $1,950 2016-03-28
Safari MEDIUM 6.5
CVE-2016-1782

WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attacke…

Fix: after 9.2.1
Fix from $1,600 2016-03-24
Mac Os X Server MEDIUM 5.3
CVE-2016-1776

Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtai…

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Mac Os X Server MEDIUM 5.3
CVE-2016-1774

The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes…

Fix: after 5.0.15
Fix from $1,600 2016-03-24
Mac Os X MEDIUM 6.5
CVE-2016-1770

The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing actio…

Fix: after 10.11.3
Fix from $1,600 2016-03-24
Ubuntu Linux MEDIUM 6.5
CVE-2015-7560EPSS 13%

The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote a…

Fix: 4.1.23 / 4.2.9+
Fix from $1,600 2016-03-13
Chrome MEDIUM 6.3
CVE-2016-1638

extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web …

Fix: after 48.0.2564.116
Fix from $1,600 2016-03-06
700 Series Firmware HIGH 7.9
CVE-2016-2243

Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access.

Mitigation only
Fix from $1,950 2016-03-04