Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Umg 508 HIGH 7.5
CVE-2015-3971

The debug interface on Janitza UMG 508, 509, 511, 604, and 605 devices does not require authentication, which allows remote attackers to read or writ…

Patch available
Fix from $1,950 2015-10-28
Mac Os X HIGH 8.8
CVE-2015-6984

libarchive in Apple OS X before 10.11.1 allows attackers to write to arbitrary files via a crafted app that conducts an unspecified symlink attack.

Fix: after 10.11.0
Fix from $1,950 2015-10-23
Satellite MEDIUM 5.3
CVE-2015-4902 KEVEPSS 13%

Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployme…

Patch available
Fix from $1,600 2015-10-22
Firefox MEDIUM 6.8
CVE-2015-7184

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user cre…

Fix: after 41.0.1
Fix from $1,600 2015-10-18
Revive Adserver HIGH 7.5
CVE-2015-7369

The default Flash cross-domain policy (crossdomain.xml) in Revive Adserver before 3.2.2 does not restrict access cross domain access, which allows re…

Fix: after 3.2.1
Fix from $1,950 2015-10-14
Revive Adserver HIGH 7.5
CVE-2015-7367

Revive Adserver before 3.2.2 allows remote attackers to perform unspecified actions by leveraging an unexpired session after the user has been (1) de…

Fix: after 3.2.1
Fix from $1,950 2015-10-14
Chrome HIGH 7.5
CVE-2015-1304

object-observe.js in Google V8, as used in Google Chrome before 45.0.2454.101, does not properly restrict method calls on access-checked objects, whi…

Fix: after 45.0.2454.93
Fix from $1,950 2015-10-12
Mac Os X MEDIUM 6.8
CVE-2015-5913

Heimdal, as used in Apple OS X before 10.11, allows remote attackers to conduct replay attacks against the SMB server via packet data that represents…

Fix: after 10.10.5
Fix from $1,600 2015-10-09
Android HIGH 7.2
CVE-2015-3860

packages/Keyguard/res/layout/keyguard_password_view.xml in Lockscreen in Android 5.x before 5.1.1 LMY48M does not restrict the number of characters i…

Fix: after 5.1
Fix from $1,950 2015-10-01
Cubecart MEDIUM 6.8
CVE-2015-6928

classes/admin.class.php in CubeCart 5.2.12 through 5.2.16 and 6.x before 6.0.7 does not properly validate that a password reset request was made, whi…

Patch available
Fix from $1,600 2015-09-28
Watchos HIGH 7.2
CVE-2015-5882

The processor_set_tasks API implementation in Apple iOS before 9 allows local users to bypass an entitlement protection mechanism and obtain access t…

Fix: after 10.10.5
Fix from $1,950 2015-09-18
Teta Web HIGH 7.5
CVE-2015-1173

Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 does not properly restrict access to the (1) Design Mode and (2) Debug Logger mode modules,…

Fix: after 22.62.3.4
Fix from $1,950 2015-09-16
Unified Web And E Mail Interaction Manager MEDIUM 5.5
CVE-2015-4299

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) improperly performs authorization, which allows remote authenticated users to remove default …

Mitigation only
Fix from $1,600 2015-08-19
Unified Web And E Mail Interaction Manager MEDIUM 6.5
CVE-2015-4298

Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to rea…

Mitigation only
Fix from $1,600 2015-08-19
Firesight System Software MEDIUM 6.4
CVE-2015-4302

The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in…

Mitigation only
Fix from $1,600 2015-08-19
Me Aliases MEDIUM 5.0
CVE-2015-5512

The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argum…

Patch available
Fix from $1,600 2015-08-18
Storage Api HIGH 7.5
CVE-2015-5502

The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not no…

Patch available
Fix from $1,950 2015-08-18
Picketlink MEDIUM 6.0
CVE-2015-0277

The Service Provider (SP) in PicketLink before 2.7.0 does not ensure that it is a member of an Audience element when an AudienceRestriction is specif…

Fix: after 2.6.0
Fix from $1,600 2015-08-17
Iphone Os MEDIUM 5.0
CVE-2015-5746

AppleFileConduit in Apple iOS before 8.4.1 allows attackers to bypass intended restrictions on filesystem access via an afc command that leverages sy…

Fix: after 8.4
Fix from $1,600 2015-08-17
Iphone Os HIGH 7.2
CVE-2015-3806

Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism by appending code to a crafted executa…

Fix: after 10.10.4
Fix from $1,950 2015-08-17
Foreman MEDIUM 5.0
CVE-2015-3155

Foreman before 1.8.1 does not set the secure flag for the _session_id cookie in an https session, which makes it easier for remote attackers to captu…

Fix: after 1.8.0
Fix from $1,600 2015-08-14
Clutter HIGH 7.2
CVE-2015-3213

The gesture handling code in Clutter before 1.16.2 allows physically proximate attackers to bypass the lock screen via certain (1) mouse or (2) touch…

Fix: after 1.16.0
Fix from $1,950 2015-08-12
Tuxedo Touch MEDIUM 5.0
CVE-2015-2847

Honeywell Tuxedo Touch before 5.2.19.0_VA relies on client-side authentication involving JavaScript, which allows remote attackers to bypass intended…

Fix: after 5.1.13.0_va
Fix from $1,600 2015-07-26
Telepresence Tc Software MEDIUM 6.4
CVE-2015-4271

Cisco TelePresence TC before 7.3.4 on Integrator C devices allows remote attackers to bypass authentication via vectors involving multiple request pa…

Mitigation only
Fix from $1,600 2015-07-15
Sql Server HIGH 8.5
CVE-2015-1763EPSS 12%

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 does not prevent use of uninitialized memory in certain attemp…

Mitigation only
Fix from $1,950 2015-07-14
Sql Server MEDIUM 6.5
CVE-2015-1761EPSS 19%

Microsoft SQL Server 2008 SP3 and SP4, 2008 R2 SP2 and SP3, 2012 SP1 and SP2, and 2014 uses an incorrect class during casts of unspecified pointers, …

Mitigation only
Fix from $1,600 2015-07-14
Junos HIGH 7.2
CVE-2015-3007

The Juniper SRX Series services gateways with Junos OS 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 do not …

Mitigation only
Fix from $1,950 2015-07-14
Websphere Application Server MEDIUM 6.0
CVE-2015-1936

The administrative console in IBM WebSphere Application Server (WAS) 8.0.0 before 8.0.0.11 and 8.5 before 8.5.5.6, when the Security feature is disab…

Patch available
Fix from $1,600 2015-07-14
Websphere Application Server MEDIUM 6.8
CVE-2015-1927

The default configuration of IBM WebSphere Application Server (WAS) 7.0.0 before 7.0.0.39, 8.0.0 before 8.0.0.11, and 8.5 before 8.5.5.6 has a false …

Patch available
Fix from $1,600 2015-07-14
Business Process Manager HIGH 9.0
CVE-2015-1961

The REST API in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.…

Patch available
Fix from $1,950 2015-07-13