Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
Kerberos 5 MEDIUM 6.1
CVE-2014-9422

The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.1…

Patch available
Fix from $1,600 2015-02-19
On Screen Phone HIGH 8.3
CVE-2014-8757

LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request.

Fix: after 4.3.009
Fix from $1,950 2015-02-17
Windows 7 HIGH 8.3
CVE-2015-0008EPSS 29%

The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…

Patch available
Fix from $1,950 2015-02-11
Hvg Video Gateway Firmware HIGH 10.0
CVE-2015-0929

time.htm in the web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a78 allows remote attackers to bypass authentication …

Fix: after 2.2.26a77
Fix from $1,950 2015-02-03
Labtech MEDIUM 6.8
CVE-2015-0926

Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a…

Fix: after 55.170
Fix from $1,600 2015-02-01
Etg3000 Factorycast Hmi Gateway Firmware HIGH 7.8
CVE-2014-9197

The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con…

Patch available
Fix from $1,950 2015-01-27
Mantisbt HIGH 7.5
CVE-2014-9572

MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain dat…

Fix: after 1.2.18
Fix from $1,950 2015-01-26
Ubuntu HIGH 7.2
CVE-2014-1949

GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass …

Fix: after 3.10.9
Fix from $1,950 2015-01-16
Maxthon Cloud Browser MEDIUM 5.0
CVE-2014-1449

The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that…

Fix: after 4.1.5.2000
Fix from $1,600 2014-12-25
Hapi Crumb MEDIUM 5.8
CVE-2014-7193

The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which al…

Fix: after 2.2.0
Fix from $1,600 2014-12-25
Exaopc HIGH 7.5
CVE-2014-5208EPSS 23%

BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, a…

Fix: after 3.71.10
Fix from $1,950 2014-12-22
Security Access Manager For Mobile MEDIUM 5.0
CVE-2014-6078

IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a …

Mitigation only
Fix from $1,600 2014-12-18
Mantisbt MEDIUM 5.0
CVE-2014-9388

bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter.

Fix: after 1.2.17
Fix from $1,600 2014-12-17
Firefox MEDIUM 6.8
CVE-2014-1589

Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas…

Fix: after 33.0
Fix from $1,600 2014-12-11
Bind MEDIUM 5.4
CVE-2014-8680EPSS 9%

The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via…

Mitigation only
Fix from $1,600 2014-12-11
Exchange Server MEDIUM 5.0
CVE-2014-6319EPSS 10%

Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requ…

Mitigation only
Fix from $1,600 2014-12-11
Mantisbt MEDIUM 5.0
CVE-2014-9117

MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA prot…

Fix: after 1.2.17
Fix from $1,600 2014-12-06
Services HIGH 7.5
CVE-2014-9151

The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote …

Mitigation only
Fix from $1,950 2014-12-01
Clearpass HIGH 9.0
CVE-2014-6627

Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a differe…

Fix: after 6.3.4
Fix from $1,950 2014-11-19
Clearpass HIGH 10.0
CVE-2014-6626

Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows …

Fix: after 6.3.4
Fix from $1,950 2014-11-19
Clearpass HIGH 9.0
CVE-2014-6625

The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecifi…

Fix: after 6.3.4
Fix from $1,950 2014-11-19
Chrome MEDIUM 5.0
CVE-2014-7905

Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, whic…

Fix: after 39.0.2171.45
Fix from $1,600 2014-11-19
Elasticsearch HIGH 8.1
CVE-2014-3120 KEVEPSS 89%

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions …

Fix: 1.2.0+
Fix from $1,950 2014-07-28
Advantech Webaccess MEDIUM 5.5
CVE-2014-2365

Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors.

Fix: after 7.1
Fix from $1,600 2014-07-19
Wl 330nul MEDIUM 5.0
CVE-2013-7293

The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to ins…

Mitigation only
Fix from $1,600 2014-01-15
Struts HIGH 10.0
CVE-2013-4316EPSS 8%

Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.

Fix: after 3.0.4
Fix from $1,950 2013-09-30
Debian Linux MEDIUM 5.0
CVE-2013-2175

HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows…

Patch available
Fix from $1,600 2013-08-19
Jboss Enterprise Application Platform MEDIUM 6.4
CVE-2013-4213

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker…

Mitigation only
Fix from $1,600 2013-08-16
Controllogix Controllers HIGH 7.5
CVE-2012-6435EPSS 33%

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…

Fix: after 1400
Fix from $1,950 2013-01-24
Controllogix Controllers HIGH 8.5
CVE-2012-6439EPSS 23%

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or…

Fix: after 1400
Fix from $1,950 2013-01-24