Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 5.9 CVE-2015-7315 Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to… Plone Patch available Fix from $1,6002017-09-25 HIGH 7.5 CVE-2015-1854 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn ca… Fedora after 1.3.3.9 Fix from $1,9502017-09-19 MEDIUM 6.5 CVE-2015-0110 IBM Business Process Manager (aka BPM) 7.5.x, 8.0.x, and 8.5.x and WebSphere Lombardi Edition (aka WLE) 7.2.x allow remote authenticated users to byp… Business Process Manager Mitigation only Fix from $1,6002017-09-15 MEDIUM 5.3 CVE-2014-8677 The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing databa… Soplanning after 1.32 Fix from $1,6002017-08-31 HIGH 7.5 CVE-2016-8752 Apache Atlas versions 0.6.0 (incubating), 0.7.0 (incubating), and 0.7.1 (incubating) allow access to the webapp directory contents by pointing to URI… Atlas Mitigation only Fix from $1,9502017-08-29 HIGH 7.2 CVE-2015-3653 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files wi… Clearpass after 6.4.6 Fix from $1,9502017-08-29 HIGH 7.2 CVE-2015-3654 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un… Clearpass after 6.4.6 Fix from $1,9502017-08-29 HIGH 7.2 CVE-2015-3657 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Adm… Clearpass after 6.4.6 Fix from $1,9502017-08-29 HIGH 7.2 CVE-2015-4649 Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to gain root privileges via un… Clearpass after 6.4.6 Fix from $1,9502017-08-29 MEDIUM 6.1 CVE-2014-8168 Red Hat Satellite 6 allows local users to access mongod and delete pulp_database. Satellite Mitigation only Fix from $1,6002017-08-28 CRITICAL 9.8 CVE-2014-9513 Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code. Xbindkeys Config No fix yet Fix from $2,3002017-08-28 MEDIUM 5.9 CVE-2015-5293 Red Hat Enterprise Virtualization Manager 3.6 and earlier gives valid SLAAC IPv6 addresses to interfaces when "boot protocol" is set to None, which m… Enterprise Virtualization Manager after 3.6.0 Fix from $1,6002017-08-24 CRITICAL 9.8 CVE-2015-9064 In all Qualcomm products with Android releases from CAF using the Linux kernel, the UE can send IMEI or IMEISV to the network on a network request be… Android Mitigation only Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2016-10382 In all Qualcomm products with Android releases from CAF using the Linux kernel, access control to the I2C bus is not sufficient. Android Mitigation only Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2015-9040 In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in a GERAN API. Android No fix yet Fix from $2,3002017-08-18 CRITICAL 9.8 CVE-2015-9047 In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in GNSS when performing a scan after bootup. Android No fix yet Fix from $2,3002017-08-18 MEDIUM 6.5 CVE-2017-6866 A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileg… Xhq Server after 5.0.0.1 Fix from $1,6002017-08-07 HIGH 8.8 CVE-2014-9827 coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file. Imagemagick 6.9.4-0+ Fix from $1,9502017-08-07 HIGH 8.8 CVE-2014-9828 coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file. Imagemagick 6.9.4-0+ Fix from $1,9502017-08-07 HIGH 8.8 CVE-2014-9830 coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file. Imagemagick 6.9.4-0+ Fix from $1,9502017-08-07 HIGH 8.8 CVE-2014-9831 coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file. Imagemagick 6.9.4-0+ Fix from $1,9502017-08-07 HIGH 8.1 CVE-2015-7887 NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups. Snapcenter Server Patch available Fix from $1,9502017-08-07 CRITICAL 10.0 CVE-2017-7928 An Improper Access Control issue was discovered in Schweitzer Engineering Laboratories (SEL) SEL-3620 and SEL-3622 Security Gateway Versions R202 and… Sel 3620 Firmware Mitigation only Fix from $2,3002017-08-07 HIGH 7.5 CVE-2016-10042 Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguratio… Swisscom Internet Box Firmware Mitigation only Fix from $1,9502017-06-29 MEDIUM 5.5 CVE-2015-3840 The MessageStatusReceiver service in the AndroidManifest.XML in Android 5.1.1 and earlier allows local users to alter sent/received statuses of SMS a… Android after 5.1.1 Fix from $1,6002017-06-27 MEDIUM 5.5 CVE-2015-7895 Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). Samsung Mobile No fix yet Fix from $1,6002017-06-27 MEDIUM 5.5 CVE-2015-7898 Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). Samsung Mobile No fix yet Fix from $1,6002017-06-27 MEDIUM 5.5 CVE-2015-8697 stalin 0.11-5 allows local users to write to arbitrary files. Stalin No fix yet Fix from $1,6002017-06-27 HIGH 8.4 CVE-2016-4383 The glance-manage db in all versions of HPE Helion Openstack Glance allows deleted image ids to be reassigned, which allows remote authenticated user… Helion Openstack Glance Mitigation only Fix from $1,9502017-06-27 HIGH 7.5 CVE-2016-5414 FreeIPA 4.4.0 allows remote attackers to request an arbitrary SAN name for services. Freeipa Patch available Fix from $1,9502017-06-27