Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Acrobat HIGH 10.0
CVE-2015-3073EPSS 25%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3072EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat Reader HIGH 10.0
CVE-2015-3071EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3068EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3069EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3067EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3066EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat Reader HIGH 10.0
CVE-2015-3065EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3064EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat HIGH 10.0
CVE-2015-3063EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat Reader HIGH 10.0
CVE-2015-3062EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat Reader HIGH 10.0
CVE-2015-3061EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Acrobat Reader HIGH 10.0
CVE-2015-3060EPSS 10%

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScrip…

Patch available
Fix from $1,950 2015-05-13
Sourceone Email Management MEDIUM 5.0
CVE-2015-0531

EMC SourceOne Email Management before 7.2 does not have a lockout mechanism for invalid login attempts, which makes it easier for remote attackers to…

Fix: after 7.1
Fix from $1,600 2015-05-07
Easyctf MEDIUM 5.0
CVE-2015-0914

EasyCTF before 1.4 does not validate the session ID, which allows remote attackers to obtain access via a crafted HTTP request.

Fix: after 1.3
Fix from $1,600 2015-05-01
Os X Server MEDIUM 5.0
CVE-2015-1151

Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from a…

Fix: after 4.0
Fix from $1,600 2015-04-28
Fedora MEDIUM 5.0
CVE-2015-3148EPSS 14%

cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other …

Fix: after 7.5.3.1
Fix from $1,600 2015-04-24
Jboss Operations Network HIGH 9.0
CVE-2015-0297

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java met…

Mitigation only
Fix from $1,950 2015-04-24
Adaptive Security Appliance Software HIGH 8.3
CVE-2015-0675

The failover ipsec implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1 before 9.1(6), 9.2 before 9.2(3.3), and 9.3 before 9.3(3) d…

Mitigation only
Fix from $1,950 2015-04-13
Ios Xr MEDIUM 5.0
CVE-2015-0694

Cisco ASR 9000 devices with software 5.3.0.BASE do not recognize that certain ACL entries have a single-host constraint, which allows remote attacker…

Mitigation only
Fix from $1,600 2015-04-11
Tivoli Storage Manager Fastback HIGH 7.5
CVE-2015-0119

FastBack Mount in IBM Tivoli Storage Manager FastBack 6.1.x before 6.1.11.1 allows remote attackers to execute arbitrary code by connecting to the Mo…

Fix: after 6.1.11.0
Fix from $1,950 2015-04-06
Netscaler MEDIUM 5.0
CVE-2015-2841EPSS 6%

Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type …

No fix yet
Fix from $1,600 2015-04-03
Afaria HIGH 7.5
CVE-2015-2816

The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted req…

No fix yet
Fix from $1,950 2015-04-01
Wpml HIGH 7.5
CVE-2015-2792

The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request, which allows remote attackers to bypass nonce chec…

Fix: after 3.1.8
Fix from $1,950 2015-03-30
Dokuwiki MEDIUM 6.5
CVE-2015-2172

DokuWiki before 2014-05-05d and before 2014-09-29c does not properly check permissions for the ACL plugins, which allows remote authenticated users t…

Fix: 2014-05-05d / 2014-09-29c+
Fix from $1,600 2015-03-30
Content Services Switch 11500 Firmware MEDIUM 5.0
CVE-2015-0667

The Management Interface on Cisco Content Services Switch (CSS) 11500 devices 8.20.4.02 and earlier allows remote attackers to bypass intended restri…

Fix: after 8.20.4.02
Fix from $1,600 2015-03-18
Operations Manager I Management Pack MEDIUM 6.8
CVE-2015-2107

HP Operations Manager i Management Pack 1.x before 1.01 for SAP allows local users to execute OS commands by leveraging SAP administrative privileges.

Mitigation only
Fix from $1,600 2015-03-14
Telepresence Server Software HIGH 7.2
CVE-2015-0660

Cisco Virtual TelePresence Server Software does not properly restrict use of the serial port, which allows local users to execute arbitrary OS comman…

Mitigation only
Fix from $1,950 2015-03-14
Exchange Server MEDIUM 5.0
CVE-2015-1631EPSS 9%

Microsoft Exchange Server 2013 SP1 and Cumulative Update 7 allows remote attackers to spoof meeting organizers via unspecified vectors, aka "Exchange…

Mitigation only
Fix from $1,600 2015-03-11
Fedora MEDIUM 6.4
CVE-2015-1464

RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

Fix: after 4.0.22
Fix from $1,600 2015-03-09