Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
HIGH 7.5 CVE-2016-1656 The download implementation in Google Chrome before 50.0.2661.75 on Android allows remote attackers to bypass intended pathname restrictions via unsp… Chrome after 49.0.2623.112 Fix from $1,9502016-04-18 MEDIUM 6.5 CVE-2015-5247 The virStorageVolCreateXML API in libvirt 1.2.14 through 1.2.19 allows remote authenticated users with a read-write connection to cause a denial of s… Libvirt Mitigation only Fix from $1,6002016-04-14 MEDIUM 5.9 CVE-2011-4600 The networkReloadIptablesRules function in network/bridge_driver.c in libvirt before 0.9.9 does not properly handle firewall rules on bridge networks… Ubuntu Linux Mitigation only Fix from $1,6002016-04-14 HIGH 7.3 CVE-2016-4018 The Data Provisioning Agent (aka DP Agent) in SAP HANA does not properly restrict access to service functionality, which allows remote attackers to o… Hana Mitigation only Fix from $1,9502016-04-14 HIGH 8.2 CVE-2015-8550 Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privilege… Xen Mitigation only Fix from $1,9502016-04-14 CRITICAL 9.8 CVE-2015-7545EPSS 19% The (1) git-remote-ext and (2) unspecified other remote helper programs in Git before 2.3.10, 2.4.x before 2.4.10, 2.5.x before 2.5.4, and 2.6.x befo… Git after 2.3.9 Fix from $2,3002016-04-13 HIGH 7.8 CVE-2016-0153EPSS 21% OLE in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8… Windows 7 Mitigation only Fix from $1,9502016-04-12 CRITICAL 9.3 CVE-2016-0088EPSS 8% Hyper-V in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows 10 allows guest OS users to execute arbitrary code on the host OS via … Windows 10 Mitigation only Fix from $2,3002016-04-12 HIGH 7.5 CVE-2016-3165 The Form API in Drupal 6.x before 6.38 ignores access restrictions on submit buttons, which might allow remote attackers to bypass intended access re… Drupal Patch available Fix from $1,9502016-04-12 HIGH 8.1 CVE-2016-3162 The File module in Drupal 7.x before 7.43 and 8.x before 8.0.4 allows remote authenticated users to bypass access restrictions and read, delete, or s… Drupal Patch available Fix from $1,9502016-04-12 HIGH 8.1 CVE-2016-1866 Salt 2015.8.x before 2015.8.4 does not properly handle clear messages on the minion, which allows man-in-the-middle attackers to execute arbitrary co… Salt Mitigation only Fix from $1,9502016-04-12 CRITICAL 9.8 CVE-2016-3987EPSS 22% The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef… Password Manager No fix yet Fix from $2,3002016-04-12 MEDIUM 6.5 CVE-2016-3985 The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remot… Pulse Connect Secure Mitigation only Fix from $1,6002016-04-12 MEDIUM 5.1 CVE-2016-3984 The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333),… Active Response after 10.0.1 Fix from $1,6002016-04-08 HIGH 7.8 CVE-2015-8681 The ovisp driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10C92… P8 Firmware Mitigation only Fix from $1,9502016-04-07 HIGH 7.8 CVE-2015-8680 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10… P8 Mitigation only Fix from $1,9502016-04-07 MEDIUM 5.5 CVE-2015-8679 The Maxim_smartpa_dev driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before… Mate S Firmware Mitigation only Fix from $1,6002016-04-07 HIGH 7.8 CVE-2015-8307 The Graphics driver in Huawei P8 smartphones with software GRA-TL00 before GRA-TL00C01B230, GRA-CL00 before GRA-CL00C92B230, GRA-CL10 before GRA-CL10… Mate S Firmware Patch available Fix from $1,9502016-04-07 MEDIUM 6.3 CVE-2016-2277 IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbit… Integrated Architecture Builder after 9.6.0.7 Fix from $1,6002016-04-06 HIGH 7.5 CVE-2016-2272 Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie. Eg2 Web Control after 4.04p Fix from $1,9502016-04-06 HIGH 7.5 CVE-2015-8523 The server in IBM Tivoli Storage Manager FastBack 5.5.x and 6.x before 6.1.12.2 allows remote attackers to cause a denial of service (service crash) … Tivoli Storage Manager Fastback Mitigation only Fix from $1,9502016-04-05 MEDIUM 6.2 CVE-2016-1760 The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary… Iphone Os after 9.2.1 Fix from $1,6002016-03-29 HIGH 7.8 CVE-2016-0226 The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3… Informix Dynamic Server Patch available Fix from $1,9502016-03-28 MEDIUM 6.5 CVE-2016-1782 WebKit in Apple iOS before 9.3 and Safari before 9.1 does not properly restrict redirects that specify a TCP port number, which allows remote attacke… Safari after 9.2.1 Fix from $1,6002016-03-24 MEDIUM 5.3 CVE-2016-1776 Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtai… Mac Os X Server after 5.0.15 Fix from $1,6002016-03-24 MEDIUM 5.3 CVE-2016-1774 The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes… Mac Os X Server after 5.0.15 Fix from $1,6002016-03-24 MEDIUM 6.5 CVE-2016-1770 The Reminders component in Apple OS X before 10.11.4 allows attackers to bypass an intended user-confirmation requirement and trigger a dialing actio… Mac Os X after 10.11.3 Fix from $1,6002016-03-24 MEDIUM 6.5 CVE-2015-7560EPSS 13% The SMB1 implementation in smbd in Samba 3.x and 4.x before 4.1.23, 4.2.x before 4.2.9, 4.3.x before 4.3.6, and 4.4.x before 4.4.0rc4 allows remote a… Ubuntu Linux 4.1.23 / 4.2.9+ Fix from $1,6002016-03-13 MEDIUM 6.3 CVE-2016-1638 extensions/renderer/resources/platform_app.js in the Extensions subsystem in Google Chrome before 49.0.2623.75 does not properly restrict use of Web … Chrome after 48.0.2564.116 Fix from $1,6002016-03-06 HIGH 7.9 CVE-2016-2243 Sure Start on HP Commercial PCs 2015 allows local users to cause a denial of service (BIOS recovery failure) by leveraging administrative access. 700 Series Firmware Mitigation only Fix from $1,9502016-03-04