Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.1 CVE-2016-3708 Red Hat OpenShift Enterprise 3.2, when multi-tenant SDN is enabled and a build is run in a namespace that would normally be isolated from pods in oth… Openshift Mitigation only Fix from $1,9502016-06-08 MEDIUM 5.3 CVE-2016-3703 Red Hat OpenShift Enterprise 3.2 and 3.1 do not properly validate the origin of a request when anonymous access is granted to a service/proxy or pod/… Openshift Mitigation only Fix from $1,6002016-06-08 HIGH 8.8 CVE-2016-4369 HPE Discovery and Dependency Mapping Inventory (DDMi) 9.30, 9.31, 9.32, 9.32 update 1, 9.32 update 2, and 9.32 update 3 allows remote authenticated u… Discovery And Dependency Mapping Inventory Mitigation only Fix from $1,9502016-06-08 MEDIUM 6.5 CVE-2014-8177 The Red Hat gluster-swift package, as used in Red Hat Gluster Storage (formerly Red Hat Storage Server), allows remote authenticated users to bypass … Gluster Storage Management Console Mitigation only Fix from $1,6002016-06-07 MEDIUM 6.5 CVE-2016-1699 WebKit/Source/devtools/front_end/devtools.js in the Developer Tools (aka DevTools) subsystem in Blink, as used in Google Chrome before 51.0.2704.79, … Ubuntu Linux after 51.0.2704.63 Fix from $1,6002016-06-05 HIGH 8.8 CVE-2016-1697 The FrameLoader::startLoad function in WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 51.0.2704.79, does not pre… Chrome after 51.0.2704.63 Fix from $1,9502016-06-05 HIGH 8.8 CVE-2016-1696 The extensions subsystem in Google Chrome before 51.0.2704.79 does not properly restrict bindings access, which allows remote attackers to bypass the… Chrome after 51.0.2704.63 Fix from $1,9502016-06-05 MEDIUM 5.3 CVE-2016-1694 browser/browsing_data/browsing_data_remover.cc in Google Chrome before 51.0.2704.63 deletes HPKP pins during cache clearing, which makes it easier fo… Chrome after 50.0.2661.102 Fix from $1,6002016-06-05 MEDIUM 5.3 CVE-2016-1693 browser/safe_browsing/srt_field_trial_win.cc in Google Chrome before 51.0.2704.63 does not use the HTTPS service on dl.google.com to obtain the Softw… Debian Linux after 50.0.2661.102 Fix from $1,6002016-06-05 MEDIUM 5.3 CVE-2016-1692 WebKit/Source/core/css/StyleSheetContents.cpp in Blink, as used in Google Chrome before 51.0.2704.63, permits cross-origin loading of CSS stylesheets… Ubuntu Linux after 50.0.2661.102 Fix from $1,6002016-06-05 MEDIUM 6.1 CVE-2016-1682 The ServiceWorkerContainer::registerServiceWorkerImpl function in WebKit/Source/modules/serviceworkers/ServiceWorkerContainer.cpp in Blink, as used i… Chrome after 50.0.2661.102 Fix from $1,6002016-06-05 HIGH 8.8 CVE-2016-1676 extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allow… Debian Linux after 50.0.2661.102 Fix from $1,9502016-06-05 HIGH 8.8 CVE-2016-1675 Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Docume… Ubuntu Linux after 50.0.2661.102 Fix from $1,9502016-06-05 HIGH 8.8 CVE-2016-1672 The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 m… Chrome after 50.0.2661.102 Fix from $1,9502016-06-05 HIGH 7.5 CVE-2016-4810 Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set … Xenapp Mitigation only Fix from $1,9502016-06-01 HIGH 7.5 CVE-2016-4502 Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier allows remote attackers to bypass intended access restrictions and exec… Esc 8832 Data Controller after 3.02 Fix from $1,9502016-05-31 CRITICAL 9.1 CVE-2016-4501 Environmental Systems Corporation (ESC) 8832 Data Controller 3.02 and earlier mishandles sessions, which allows remote attackers to bypass authentica… Esc 8832 Data Controller after 3.02 Fix from $2,3002016-05-31 CRITICAL 9.8 CVE-2016-1999EPSS 6% The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, rel… Release Control Patch available Fix from $2,3002016-05-30 HIGH 8.8 CVE-2016-1406 The API web interface in Cisco Prime Infrastructure before 3.1 and Cisco Evolved Programmable Network Manager before 1.2.4 allows remote authenticate… Evolved Programmable Network Manager Mitigation only Fix from $1,9502016-05-25 HIGH 8.8 CVE-2016-3728 Eval injection vulnerability in tftp_api.rb in the TFTP module in the Smart-Proxy in Foreman before 1.10.4 and 1.11.x before 1.11.2 allows remote att… Foreman Patch available Fix from $1,9502016-05-20 MEDIUM 5.4 CVE-2016-2100 Foreman before 1.10.3 and 1.11.0 before 1.11.0-RC2 allow remote authenticated users to read, modify, or delete private bookmarks by leveraging the (1… Foreman after 1.10.2 Fix from $1,6002016-05-20 MEDIUM 5.3 CVE-2016-1844 The Messages component in Apple OS X before 10.11.5 mishandles roster changes, which allows remote attackers to modify contact lists via unspecified … Mac Os X after 10.11.4 Fix from $1,6002016-05-20 HIGH 7.5 CVE-2016-1842 MapKit in Apple iOS before 9.3.2, OS X before 10.11.5, and watchOS before 2.2.1 does not use HTTPS for shared links, which allows remote attackers to… Iphone Os after 10.11.4 Fix from $1,9502016-05-20 HIGH 7.8 CVE-2016-1806 Crash Reporter in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app. Mac Os X after 10.11.4 Fix from $1,9502016-05-20 HIGH 7.8 CVE-2016-1805 CoreStorage in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context via a crafted app. Mac Os X after 10.11.4 Fix from $1,9502016-05-20 HIGH 7.8 CVE-2016-1797 Apple Type Services (ATS) in Apple OS X before 10.11.5 allows attackers to bypass intended FontValidator sandbox-policy restrictions and execute arbi… Mac Os X after 10.11.4 Fix from $1,9502016-05-20 MEDIUM 6.5 CVE-2016-0323 The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate val… Bluemix Mitigation only Fix from $1,6002016-05-17 HIGH 8.8 CVE-2016-1668 The forEachForBinding function in WebKit/Source/bindings/core/v8/Iterable.h in the V8 bindings in Blink, as used in Google Chrome before 50.0.2661.10… Chrome after 50.0.2661.87 Fix from $1,9502016-05-14 HIGH 8.8 CVE-2016-1667 The TreeScope::adoptIfNeeded function in WebKit/Source/core/dom/TreeScope.cpp in the DOM implementation in Blink, as used in Google Chrome before 50.… Debian Linux after 50.0.2661.87 Fix from $1,9502016-05-14 MEDIUM 5.5 CVE-2016-2016 Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 1… Base Vxfs 50 Patch available Fix from $1,6002016-05-14