Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Recoverpoint For Virtual Machines HIGH 7.2
CVE-2015-4526

EMC RecoverPoint for Virtual Machines (VMs) 4.2 allows local users to obtain root-shell access by bypassing the Installation Manager Boxmgmt CLI inte…

Mitigation only
Fix from $1,950 2015-07-10
Player HIGH 7.2
CVE-2015-3650

vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1…

Patch available
Fix from $1,950 2015-07-10
Flash Player MEDIUM 5.0
CVE-2015-5116EPSS 22%

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Flash Player MEDIUM 5.0
CVE-2015-3125

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Flash Player MEDIUM 5.0
CVE-2015-3116

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Flash Player MEDIUM 5.0
CVE-2015-3115

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Flash Player MEDIUM 5.0
CVE-2015-3114

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Flash Player MEDIUM 5.0
CVE-2014-0578

Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 1…

Fix: after 18.0.0.144
Fix from $1,600 2015-07-09
Galaxy S5 HIGH 7.9
CVE-2015-4034

The createFromParcel method in the com.absolute.android.persistence.MethodSpec class in Samsung Galaxy S5s allows remote attackers to execute arbitra…

Mitigation only
Fix from $1,950 2015-07-06
Mac Os X MEDIUM 6.8
CVE-2015-3692

Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not enforce a locking protection mechanism upon being woken fr…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Mac Os X HIGH 9.3
CVE-2015-3691

The Monitor Control Command Set kernel extension in the Display Drivers subsystem in Apple OS X before 10.10.4 allows attackers to execute arbitrary …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X MEDIUM 5.0
CVE-2015-3675

The default configuration of the Apache HTTP Server on Apple OS X before 10.10.4 does not enable the mod_hfs_apple module, which allows remote attack…

Fix: after 10.10.3
Fix from $1,600 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3672

Admin Framework in Apple OS X before 10.10.4 does not properly handle authentication errors, which allows local users to obtain admin privileges via …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Mac Os X HIGH 7.2
CVE-2015-3671

Admin Framework in Apple OS X before 10.10.4 does not properly verify XPC entitlements, which allows local users to bypass authentication and obtain …

Fix: after 10.10.3
Fix from $1,950 2015-07-03
Milkystep Light MEDIUM 6.5
CVE-2015-2952

The user-information management functionality in Igreks MilkyStep Light 0.94 and earlier and Professional 1.82 and earlier allows remote authenticate…

Fix: after 1.82
Fix from $1,600 2015-06-13
Manageengine Netflow Analyzer MEDIUM 5.0
CVE-2015-4418

Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote atta…

Mitigation only
Fix from $1,600 2015-06-09
Manageengine Netflow Analyzer HIGH 7.5
CVE-2015-2959

Zoho NetFlow Analyzer build 10250 and earlier does not check for administrative authorization, which allows remote attackers to obtain sensitive info…

Patch available
Fix from $1,950 2015-06-09
Ipc Diagnostics HIGH 9.0
CVE-2015-4051EPSS 6%

Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of ser…

Fix: after 1.7
Fix from $1,950 2015-06-08
Debian Linux MEDIUM 5.0
CVE-2014-7810EPSS 14%

The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16 does not properly consider t…

Patch available
Fix from $1,600 2015-06-07
Powervc HIGH 7.5
CVE-2015-1937

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL da…

Patch available
Fix from $1,950 2015-05-30
Anyconnect Secure Mobility Client MEDIUM 6.8
CVE-2015-0755

The Posture module for Cisco Identity Services Engine (ISE), as distributed in Cisco AnyConnect Secure Mobility Client 4.0(64), allows local users to…

Mitigation only
Fix from $1,600 2015-05-29
Infosphere Information Server MEDIUM 5.5
CVE-2015-0180

The Connector Migration Tool in IBM InfoSphere Information Server 8.1 through 11.3 allows remote authenticated users to bypass intended restrictions …

Patch available
Fix from $1,600 2015-05-25
Telepresence Tc Software HIGH 8.3
CVE-2014-2174

Cisco TelePresence T, TelePresence TE, and TelePresence TC before 7.1 do not properly implement access control, which allows remote attackers to obta…

Mitigation only
Fix from $1,950 2015-05-25
E587 Mobile Wifi Firmware HIGH 9.0
CVE-2015-3911

Huawei E587 Mobile WiFi with firmware before 11.203.30.00.00 allows remote attackers to bypass authentication, change configurations, send messages, …

Fix: after 11.100.00.00.00
Fix from $1,950 2015-05-21
Debian Linux HIGH 7.5
CVE-2015-1253

core/html/parser/HTMLConstructionSite.cpp in the DOM implementation in Blink, as used in Google Chrome before 43.0.2357.65, allows remote attackers t…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Websphere Application Server HIGH 10.0
CVE-2015-1920EPSS 7%

IBM WebSphere Application Server (WAS) 6.1 through 6.1.0.47, 7.0 before 7.0.0.39, 8.0 before 8.0.0.11, and 8.5 before 8.5.5.6 allows remote attackers…

Patch available
Fix from $1,950 2015-05-20
Ubuntu Linux MEDIUM 5.0
CVE-2015-3407

Module::Signature before 0.74 allows remote attackers to bypass signature verification for files via a signature file that does not list the files.

Fix: after 0.73
Fix from $1,600 2015-05-19
Proftpd HIGH 10.0
CVE-2015-3306EPSS 97%

The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

Mitigation only
Fix from $1,950 2015-05-18
Stunnel MEDIUM 5.8
CVE-2015-3644

Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, …

Patch available
Fix from $1,600 2015-05-14
Acrobat HIGH 10.0
CVE-2015-3074EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13