Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2016-6342 elog 3.1.1 allows remote attackers to post data as any username in the logbook. Fedora Mitigation only Fix from $1,9502017-06-27 MEDIUM 6.8 CVE-2017-7918EPSS 7% An Improper Access Control issue was discovered in Cambium Networks ePMP. After a valid user has used SNMP configuration export, an attacker is able … Epmp 1000 Firmware Mitigation only Fix from $1,6002017-06-21 MEDIUM 5.5 CVE-2016-10335 In all Android releases from CAF using the Linux kernel, libtomcrypt was updated. Android No fix yet Fix from $1,6002017-06-13 HIGH 7.8 CVE-2014-9961 In all Android releases from CAF using the Linux kernel, a vulnerability in eMMC write protection exists that can be used to bypass power-on write pr… Android Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2015-9021 In all Android releases from CAF using the Linux kernel, access control to SMEM memory was not enabled. Android Mitigation only Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2015-9024 In all Android releases from CAF using the Linux kernel, some interfaces were improperly exposed to QTEE applications. Android Mitigation only Fix from $1,6002017-06-13 HIGH 7.8 CVE-2015-9029 In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory. Android Mitigation only Fix from $1,9502017-06-13 MEDIUM 5.5 CVE-2016-10333 In all Android releases from CAF using the Linux kernel, a sensitive system call was allowed to be called by HLOS. Android No fix yet Fix from $1,6002017-06-13 MEDIUM 5.5 CVE-2016-10334 In all Android releases from CAF using the Linux kernel, a dynamically-protected DDR region could potentially get overwritten. Android No fix yet Fix from $1,6002017-06-13 HIGH 8.8 CVE-2016-7824 Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug opti… Wnc01wh Firmware after 1.0.0.8 Fix from $1,9502017-06-09 HIGH 7.5 CVE-2016-7833 Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file v… Dezie Mitigation only Fix from $1,9502017-06-09 HIGH 7.5 CVE-2016-7807 I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inse… Wfs Sr01 Firmware after 1.10 Fix from $1,9502017-06-09 HIGH 8.8 CVE-2016-7811 Corega CG-WLR300NX firmware Ver. 1.20 and earlier allows an attacker on the same network segment to bypass access restriction to perform arbitrary op… Cg Wlr300nx Firmware after 1.20 Fix from $1,9502017-06-09 CRITICAL 10.0 CVE-2015-2692 AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters. Adblock after 2.20.1 Fix from $2,3002017-06-08 HIGH 8.1 CVE-2016-6098 IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be … Security Key Lifecycle Manager Patch available Fix from $1,9502017-06-08 MEDIUM 5.5 CVE-2016-3107 The Node certificate in Pulp before 2.8.3 contains the private key, and is stored in a world-readable file in the "/etc/pki/pulp/nodes/" directory, w… Pulp after 2.8.2-1 Fix from $1,6002017-06-08 HIGH 7.5 CVE-2016-3112 client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows r… Pulp after 2.8.2-1 Fix from $1,9502017-06-08 MEDIUM 5.3 CVE-2015-3295 markdown-it before 4.1.0 does not block data: URLs. Markdown It Patch available Fix from $1,6002017-06-07 MEDIUM 5.5 CVE-2016-6089 IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to i… Websphere Mq Patch available Fix from $1,6002017-06-07 HIGH 7.5 CVE-2016-0768 PostgreSQL PL/Java after 9.0 does not honor access controls on large objects. PostgreSQL after 9.0 Fix from $1,9502017-06-06 HIGH 7.8 CVE-2015-9006 In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially e… Android Patch available Fix from $1,9502017-06-06 HIGH 8.8 CVE-2017-8438 Elastic X-Pack Security versions 5.0.0 to 5.4.0 contain a privilege escalation bug in the run_as functionality. This bug prevents transitioning into … X Pack Patch available Fix from $1,9502017-06-05 HIGH 7.3 CVE-2017-6016 An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions… Ltda Me Laquis Scada after 4.1 Fix from $1,9502017-05-19 HIGH 7.8 CVE-2016-10237 If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases … Android Patch available Fix from $1,9502017-05-16 HIGH 7.5 CVE-2016-10370 An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does n… Oxygenos No fix yet Fix from $1,9502017-05-11 HIGH 7.8 CVE-2016-10369 unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing termi… Lxterminal after 0.3.0 Fix from $1,9502017-05-08 HIGH 7.5 CVE-2016-2930 IBM BigFix Remote Control 9.1.3 could allow a remote attacker to perform actions reserved for an administrator without authentication. IBM X-Force ID… Bigfix Remote Control Patch available Fix from $1,9502017-05-03 HIGH 8.4 CVE-2016-9976 IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-craf… Maximo Asset Management Patch available Fix from $1,9502017-05-03 CRITICAL 9.8 CVE-2016-8584EPSS 6% Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication… Threat Discovery Appliance after 2.6.1062 Fix from $2,3002017-04-28 HIGH 7.3 CVE-2016-8587 dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code vi… Threat Discovery Appliance after 2.6.1062 Fix from $1,9502017-04-28