Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
Bigtree Cms MEDIUM 6.5
CVE-2017-9378

BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed …

Fix: after 4.2.18
Fix from $1,600 2017-06-02
Junos Space HIGH 8.8
CVE-2017-2305

On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrativ…

Fix: after 16.1
Fix from $1,950 2017-05-30
Junos Space HIGH 8.8
CVE-2017-2306

On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrativ…

Fix: after 16.1
Fix from $1,950 2017-05-30
Foreman HIGH 8.8
CVE-2017-7505

Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so…

Patch available
Fix from $1,950 2017-05-26
Workstation Player HIGH 7.8
CVE-2017-4915EPSS 5%

VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation o…

Patch available
Fix from $1,950 2017-05-22
Screen HIGH 7.8
CVE-2017-5618

GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile…

Fix: after 4.5.0
Fix from $1,950 2017-03-20
Drupal HIGH 7.5
CVE-2017-6377

When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resul…

Mitigation only
Fix from $1,950 2017-03-16
Unified Computing System Director HIGH 8.8
CVE-2017-3801

A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary work…

Mitigation only
Fix from $1,950 2017-02-15
Pt 7728 HIGH 7.7
CVE-2016-4514

Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local prox…

Mitigation only
Fix from $1,950 2016-06-19
Keystone MEDIUM 6.5
CVE-2014-3520

OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to …

Fix: 2013.2.4 / 2014.1.2+
Fix from $1,600 2014-10-26
Ruggedcom Rugged Operating System HIGH 8.0
CVE-2013-6926

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ…

Fix: 3.12.2+
Fix from $1,950 2013-12-17
Websphere Application Server MEDIUM 6.8
CVE-2013-0543

IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP…

Mitigation only
Fix from $1,600 2013-04-24
Chrome MEDIUM 6.8
CVE-2013-0889

Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement bef…

Fix: 25.0.1364.97 / 25.0.1364.99+
Fix from $1,600 2013-02-23
Carrier Routing System MEDIUM 5.8
CVE-2012-1342

Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975.

Mitigation only
Fix from $1,600 2012-08-06
Rational System Architect HIGH 9.3
CVE-2011-1207EPSS 5%

The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect…

Fix: after 11.4.0.2
Fix from $1,950 2011-05-05
Chrome HIGH 7.5
CVE-2011-1123

Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack ve…

Fix: 9.0.597.107+
Fix from $1,950 2011-03-01
Workstation HIGH 7.2
CVE-2010-4296

vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.…

Mitigation only
Fix from $1,950 2010-12-06
1756 Enbt\/a Firmware CRITICAL 9.8
CVE-2010-2965EPSS 58%

The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3…

Fix: after 6.9.4.12
Fix from $2,300 2010-08-05
Scanner File Utility CRITICAL 9.8
CVE-2008-7109

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to th…

No fix yet
Fix from $2,300 2009-08-28
Netscaler Access Gateway Firmware MEDIUM 6.5
CVE-2009-2213

The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1,…

Fix: after 8.1
Fix from $1,600 2009-06-25
Enterprise Linux MEDIUM 5.0
CVE-2008-6123

The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does …

Fix: after 5.4.2.1
Fix from $1,600 2009-02-12
Esx HIGH 7.8
CVE-2009-0034

parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions …

Mitigation only
Fix from $1,950 2009-01-30
Fedora HIGH 7.5
CVE-2008-4577

The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended…

Fix: 1.1.4+
Fix from $1,950 2008-10-15
Fedora HIGH 7.5
CVE-2008-3424

Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in …

Fix: 7.0.4+
Fix from $1,950 2008-07-31
Dirlist Php MEDIUM 5.3
CVE-2007-3968

index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.

Fix: after 0.1.1
Fix from $1,600 2007-07-25
iOS HIGH 9.3
CVE-2007-2586EPSS 14%

The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, an…

No fix yet
Fix from $1,950 2007-05-10
Chetcpasswd HIGH 7.5
CVE-2006-6679

Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows…

Fix: 2.4+
Fix from $1,950 2006-12-21
FreeBSD CRITICAL 9.8
CVE-2001-1155

TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS loo…

Fix: after 4.3
Fix from $2,300 2001-08-23