Vulnerability index

Browse CVEs

2,848 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect AuthorizationCWE-863 × clear
MEDIUM 6.5 CVE-2017-9378 BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed … Bigtree Cms after 4.2.18 Fix from $1,6002017-06-02 HIGH 8.8 CVE-2017-2305 On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrativ… Junos Space after 16.1 Fix from $1,9502017-05-30 HIGH 8.8 CVE-2017-2306 On Juniper Networks Junos Space versions prior to 16.1R1, due to an insufficient authorization check, readonly users on the Junos Space administrativ… Junos Space after 16.1 Fix from $1,9502017-05-30 HIGH 8.8 CVE-2017-7505 Foreman since version 1.5 is vulnerable to an incorrect authorization check due to which users with user management permission who are assigned to so… Foreman Patch available Fix from $1,9502017-05-26 HIGH 7.8 CVE-2017-4915EPSS 5% VMware Workstation Pro/Player contains an insecure library loading vulnerability via ALSA sound driver configuration files. Successful exploitation o… Workstation Player Patch available Fix from $1,9502017-05-22 HIGH 7.8 CVE-2017-5618 GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile… Screen after 4.5.0 Fix from $1,9502017-03-20 HIGH 7.5 CVE-2017-6377 When adding a private file via the editor in Drupal 8.2.x before 8.2.7, the editor will not correctly check access for the file being attached, resul… Drupal Mitigation only Fix from $1,9502017-03-16 HIGH 8.8 CVE-2017-3801 A vulnerability in the web-based GUI of Cisco UCS Director 6.0.0.0 and 6.0.0.1 could allow an authenticated, local attacker to execute arbitrary work… Unified Computing System Director Mitigation only Fix from $1,9502017-02-15 HIGH 7.7 CVE-2016-4514 Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change the configuration via vectors involving a local prox… Pt 7728 Mitigation only Fix from $1,9502016-06-19 MEDIUM 6.5 CVE-2014-3520 OpenStack Identity (Keystone) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2 allows remote authenticated trustees to gain access to … Keystone 2013.2.4 / 2014.1.2+ Fix from $1,6002014-10-26 HIGH 8.0 CVE-2013-6926 The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrativ… Ruggedcom Rugged Operating System 3.12.2+ Fix from $1,9502013-12-17 MEDIUM 6.8 CVE-2013-0543 IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP… Websphere Application Server Mitigation only Fix from $1,6002013-04-24 MEDIUM 6.8 CVE-2013-0889 Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement bef… Chrome 25.0.1364.97 / 25.0.1364.99+ Fix from $1,6002013-02-23 MEDIUM 5.8 CVE-2012-1342 Cisco Carrier Routing System (CRS) 3.9, 4.0, and 4.1 allows remote attackers to bypass ACL entries via fragmented packets, aka Bug ID CSCtj10975. Carrier Routing System Mitigation only Fix from $1,6002012-08-06 HIGH 9.3 CVE-2011-1207EPSS 5% The ActiveBar1 ActiveX control in the Data Dynamics ActiveBar ActiveX controls, as distributed in ActBar.ocx 1.0.6.5 in IBM Rational System Architect… Rational System Architect after 11.4.0.2 Fix from $1,9502011-05-05 HIGH 7.5 CVE-2011-1123 Google Chrome before 9.0.597.107 does not properly restrict access to internal extension functions, which has unspecified impact and remote attack ve… Chrome 9.0.597.107+ Fix from $1,9502011-03-01 HIGH 7.2 CVE-2010-4296 vmware-mount in VMware Workstation 7.x before 7.1.2 build 301548 on Linux, VMware Player 3.1.x before 3.1.2 build 301548 on Linux, VMware Server 2.0.… Workstation Mitigation only Fix from $1,9502010-12-06 CRITICAL 9.8 CVE-2010-2965EPSS 58% The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3… 1756 Enbt\/a Firmware after 6.9.4.12 Fix from $2,3002010-08-05 CRITICAL 9.8 CVE-2008-7109 The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 allows remote attackers to bypass authorization and upload arbitrary files to th… Scanner File Utility No fix yet Fix from $2,3002009-08-28 MEDIUM 6.5 CVE-2009-2213 The default configuration of the Security global settings on the Citrix NetScaler Access Gateway appliance with Enterprise Edition firmware 9.0, 8.1,… Netscaler Access Gateway Firmware after 8.1 Fix from $1,6002009-06-25 MEDIUM 5.0 CVE-2008-6123 The netsnmp_udp_fmtaddr function (snmplib/snmpUDPDomain.c) in net-snmp 5.0.9 through 5.4.2.1, when using TCP wrappers for client authorization, does … Enterprise Linux after 5.4.2.1 Fix from $1,6002009-02-12 HIGH 7.8 CVE-2009-0034 parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group) in the sudoers file during authorization decisions … Esx Mitigation only Fix from $1,9502009-01-30 HIGH 7.5 CVE-2008-4577 The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended… Fedora 1.1.4+ Fix from $1,9502008-10-15 HIGH 7.5 CVE-2008-3424 Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in … Fedora 7.0.4+ Fix from $1,9502008-07-31 MEDIUM 5.3 CVE-2007-3968 index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name. Dirlist Php after 0.1.1 Fix from $1,6002007-07-25 HIGH 9.3 CVE-2007-2586EPSS 14% The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers to execute arbitrary code, an… iOS No fix yet Fix from $1,9502007-05-10 HIGH 7.5 CVE-2006-6679 Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client's status on an IP address ACL, which allows… Chetcpasswd 2.4+ Fix from $1,9502006-12-21 CRITICAL 9.8 CVE-2001-1155 TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS loo… FreeBSD after 4.3 Fix from $2,3002001-08-23