Vulnerability index

Browse CVEs

5,953 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Access ControlCWE-284 × clear
MEDIUM 6.1 CVE-2014-9422 The check_rpcsec_auth function in kadmin/server/kadm_rpc_svc.c in kadmind in MIT Kerberos 5 (aka krb5) through 1.11.5, 1.12.x through 1.12.2, and 1.1… Kerberos 5 Patch available Fix from $1,6002015-02-19 HIGH 8.3 CVE-2014-8757 LG On-Screen Phone (OSP) before 4.3.010 allows remote attackers to bypass authorization via a crafted request. On Screen Phone after 4.3.009 Fix from $1,9502015-02-17 HIGH 8.3 CVE-2015-0008EPSS 29% The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows… Windows 7 Patch available Fix from $1,9502015-02-11 HIGH 10.0 CVE-2015-0929 time.htm in the web interface on SerVision HVG Video Gateway devices with firmware before 2.2.26a78 allows remote attackers to bypass authentication … Hvg Video Gateway Firmware after 2.2.26a77 Fix from $1,9502015-02-03 MEDIUM 6.8 CVE-2015-0926 Labtech before 100.237 on Linux uses world-writable permissions for root-executed scripts, which allows local users to gain privileges by modifying a… Labtech after 55.170 Fix from $1,6002015-02-01 HIGH 7.8 CVE-2014-9197 The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access con… Etg3000 Factorycast Hmi Gateway Firmware Patch available Fix from $1,9502015-01-27 HIGH 7.5 CVE-2014-9572 MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain dat… Mantisbt after 1.2.18 Fix from $1,9502015-01-26 HIGH 7.2 CVE-2014-1949 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass … Ubuntu after 3.10.9 Fix from $1,9502015-01-16 MEDIUM 5.0 CVE-2014-1449 The Maxthon Cloud Browser application before 4.1.6.2000 for Android allows remote attackers to spoof the address bar via crafted JavaScript code that… Maxthon Cloud Browser after 4.1.5.2000 Fix from $1,6002014-12-25 MEDIUM 5.8 CVE-2014-7193 The Crumb plugin before 3.0.0 for Node.js does not properly restrict token access in situations where a hapi route handler has CORS enabled, which al… Hapi Crumb after 2.2.0 Fix from $1,6002014-12-25 HIGH 7.5 CVE-2014-5208EPSS 23% BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through R5.04.00, a… Exaopc after 3.71.10 Fix from $1,9502014-12-22 MEDIUM 5.0 CVE-2014-6078 IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a … Security Access Manager For Mobile Mitigation only Fix from $1,6002014-12-18 MEDIUM 5.0 CVE-2014-9388 bug_report.php in MantisBT before 1.2.18 allows remote attackers to assign arbitrary issues via the handler_id parameter. Mantisbt after 1.2.17 Fix from $1,6002014-12-17 MEDIUM 6.8 CVE-2014-1589 Mozilla Firefox before 34.0 and SeaMonkey before 2.31 provide stylesheets with an incorrect primary namespace, which allows remote attackers to bypas… Firefox after 33.0 Fix from $1,6002014-12-11 MEDIUM 5.4 CVE-2014-8680EPSS 9% The GeoIP functionality in ISC BIND 9.10.0 through 9.10.1 allows remote attackers to cause a denial of service (assertion failure and named exit) via… Bind Mitigation only Fix from $1,6002014-12-11 MEDIUM 5.0 CVE-2014-6319EPSS 10% Outlook Web App (OWA) in Microsoft Exchange Server 2007 SP3, 2010 SP3, and 2013 SP1 and Cumulative Update 6 does not properly validate tokens in requ… Exchange Server Mitigation only Fix from $1,6002014-12-11 MEDIUM 5.0 CVE-2014-9117 MantisBT before 1.2.18 uses the public_key parameter value as the key to the CAPTCHA answer, which allows remote attackers to bypass the CAPTCHA prot… Mantisbt after 1.2.17 Fix from $1,6002014-12-06 HIGH 7.5 CVE-2014-9151 The Services module 7.x-3.x before 7.x-3.10 for Drupal does not properly limit the rate of authentication attempts, which makes it easier for remote … Services Mitigation only Fix from $1,9502014-12-01 HIGH 9.0 CVE-2014-6627 Aruba Networks ClearPass before 6.3.5 and 6.4.x before 6.4.1 allows remote attackers to execute arbitrary commands via unspecified vectors, a differe… Clearpass after 6.3.4 Fix from $1,9502014-11-19 HIGH 10.0 CVE-2014-6626 Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 does not properly restrict access to unspecified administrative functions, which allows … Clearpass after 6.3.4 Fix from $1,9502014-11-19 HIGH 9.0 CVE-2014-6625 The Policy Manager in Aruba Networks ClearPass before 6.3.6 and 6.4.x before 6.4.1 allows remote authenticated users to gain privileges via unspecifi… Clearpass after 6.3.4 Fix from $1,9502014-11-19 MEDIUM 5.0 CVE-2014-7905 Google Chrome before 39.0.2171.65 on Android does not prevent navigation to a URL in cases where an intent for the URL lacks CATEGORY_BROWSABLE, whic… Chrome after 39.0.2171.45 Fix from $1,6002014-11-19 HIGH 8.1 CVE-2014-3120 KEVEPSS 89% The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions … Elasticsearch 1.2.0+ Fix from $1,9502014-07-28 MEDIUM 5.5 CVE-2014-2365 Unspecified vulnerability in Advantech WebAccess before 7.2 allows remote authenticated users to create or delete arbitrary files via unknown vectors. Advantech Webaccess after 7.1 Fix from $1,6002014-07-19 MEDIUM 5.0 CVE-2013-7293 The ASUS WL-330NUL router has a configuration process that relies on accessing the 192.168.1.1 IP address, but the documentation advises users to ins… Wl 330nul Mitigation only Fix from $1,6002014-01-15 HIGH 10.0 CVE-2013-4316EPSS 8% Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors. Struts after 3.0.4 Fix from $1,9502013-09-30 MEDIUM 5.0 CVE-2013-2175 HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows… Debian Linux Patch available Fix from $1,6002013-08-19 MEDIUM 6.4 CVE-2013-4213 Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attacker… Jboss Enterprise Application Platform Mitigation only Fix from $1,6002013-08-16 HIGH 7.5 CVE-2012-6435EPSS 33% When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P… Controllogix Controllers after 1400 Fix from $1,9502013-01-24 HIGH 8.5 CVE-2012-6439EPSS 23% When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or… Controllogix Controllers after 1400 Fix from $1,9502013-01-24