Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
CRITICAL 9.8 CVE-2016-10193 The espeak-ruby gem before 1.0.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the speak, sa… Espeak Ruby after 1.0.2 Fix from $2,3002017-03-03 MEDIUM 6.5 CVE-2016-9815 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host panic) by sending an asynchronous abort. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9816 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at EL2. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9817 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving a (1) data or (2) prefetch abort wi… Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-9818 Xen through 4.7.x allows local ARM guest OS users to cause a denial of service (host crash) via vectors involving an asynchronous abort while at HYP. Xen Patch available Fix from $1,6002017-02-27 MEDIUM 6.5 CVE-2016-8915 IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager and queue, to deny service to other channels running under th… Websphere Mq Patch available Fix from $1,6002017-02-22 MEDIUM 6.5 CVE-2016-8986 IBM WebSphere MQ 8.0 could allow an authenticated user with access to the queue manager to bring down MQ channels using specially crafted HTTP reques… Websphere Mq Patch available Fix from $1,6002017-02-22 MEDIUM 5.5 CVE-2016-9378 Xen 4.5.x through 4.7.x on AMD systems without the NRip feature, when emulating instructions that generate software interrupts, allows local HVM gues… Xen Patch available Fix from $1,6002017-02-22 HIGH 7.5 CVE-2016-9956 The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script. Debian Linux after 2016.4.3 Fix from $1,9502017-02-22 MEDIUM 5.3 CVE-2016-6077 IBM Cognos Disclosure Management 10.2 could allow a malicious attacker to execute commands as a lower privileged user that opens a malicious document… Cognos Disclosure Management Patch available Fix from $1,6002017-02-15 MEDIUM 5.4 CVE-2016-10223 An issue was discovered in BigTree CMS before 4.2.15. The vulnerability exists due to insufficient filtration of user-supplied data in the "id" HTTP … Bigtree Cms after 4.2.14 Fix from $1,6002017-02-14 HIGH 7.8 CVE-2016-9356 An issue was discovered in Moxa DACenter Versions 1.4 and older. The application may suffer from an unquoted search path issue. Dacenter after 1.4 Fix from $1,9502017-02-13 HIGH 7.5 CVE-2016-5801 An issue was discovered in OmniMetrix OmniView, Version 1.2. Insufficient password requirements for the OmniView web application may allow an attacke… Omniview Mitigation only Fix from $1,9502017-02-13 CRITICAL 9.8 CVE-2016-5815 An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 ser… Ion5000 Mitigation only Fix from $2,3002017-02-13 HIGH 7.5 CVE-2016-10026 ikiwiki 3.20161219 does not properly check if a revision changes the access permissions for a page on sites with the git and recentchanges plugins an… Ikiwiki Mitigation only Fix from $1,9502017-02-13 MEDIUM 5.3 CVE-2016-2787 The Puppet Communications Protocol in Puppet Enterprise 2015.3.x before 2015.3.3 does not properly validate certificates for the broker node, which a… Puppet Enterprise Mitigation only Fix from $1,6002017-02-13 CRITICAL 9.8 CVE-2016-2788 MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the … Marionette Collective 3.8.6 / 2016.2.1+ Fix from $2,3002017-02-13 CRITICAL 9.8 CVE-2016-7565 install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter. Exponent Cms Patch available Fix from $2,3002017-02-13 HIGH 7.3 CVE-2015-6023EPSS 11% ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intende… Hspa 3g10wve Firmware No fix yet Fix from $1,9502017-02-09 HIGH 8.8 CVE-2015-8832 Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage th… Dotclear after 2.8.1 Fix from $1,9502017-02-09 MEDIUM 5.5 CVE-2015-1976 IBM Security Directory Server could allow an authenticated user to execute commands into the web administration tool that would cause the tool to cra… Security Directory Server after 6.4.0.6 Fix from $1,6002017-02-08 HIGH 7.8 CVE-2016-0214 IBM Tivoli Endpoint Manager could allow a remote attacker to upload arbitrary files. A remote attacker could exploit this vulnerability to upload a m… Bigfix Platform Patch available Fix from $1,9502017-02-08 CRITICAL 9.8 CVE-2016-9005 IBM System Storage TS3100-TS3200 Tape Library could allow an unauthenticated user with access to the company network, to change a user's password and… System Storage Ts3100 Ts3200 Tape Library Mitigation only Fix from $2,3002017-02-08 CRITICAL 9.8 CVE-2016-8418 A remote code execution vulnerability in the Qualcomm crypto driver could enable a remote attacker to execute arbitrary code within the context of th… Android after 6.0.1 Fix from $2,3002017-02-08 HIGH 8.1 CVE-2016-1894 NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors. Oncommand Workflow Automation after 3.1 Fix from $1,9502017-02-07 CRITICAL 9.1 CVE-2016-9639 Salt before 2015.8.11 allows deleted minions to read or write to minions with the same id, related to caching. Salt after 2015.8.10 Fix from $2,3002017-02-07 MEDIUM 5.5 CVE-2016-3020 IBM Security Access Manager for Web 7.0.0, 8.0.0, and 9.0.0 could allow a remote attacker to bypass security restrictions, caused by improper content… Security Access Manager For Web 7.0 Firmware Patch available Fix from $1,6002017-02-07 CRITICAL 9.8 CVE-2016-6095 IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account cre… Security Key Lifecycle Manager Patch available Fix from $2,3002017-02-02 HIGH 7.5 CVE-2016-9008 IBM UrbanCode Deploy could allow a malicious user to access the Agent Relay ActiveMQ Broker JMX interface and run plugins on the agent. Urbancode Deploy Patch available Fix from $1,9502017-02-01 HIGH 7.5 CVE-2016-2942 IBM UrbanCode Deploy could allow an authenticated attacker with special permissions to craft a script on the server in a way that will cause processe… Urbancode Deploy Patch available Fix from $1,9502017-02-01