Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Chrome HIGH 10.0
CVE-2010-1663EPSS 54%

The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy…

Fix: after 4.1.249.1063
Fix from $1,950 2010-05-03
Deslock\+ HIGH 7.2
CVE-2009-4832

The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryp…

No fix yet
Fix from $1,950 2010-04-29
Jboss Enterprise Application Platform MEDIUM 5.0
CVE-2010-1429EPSS 54%

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obt…

Fix: after 4.3.0
Fix from $1,600 2010-04-28
Simple Blog MEDIUM 5.0
CVE-2009-4825

8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a datab…

No fix yet
Fix from $1,600 2010-04-27
Angelo Emlak MEDIUM 5.0
CVE-2009-4820

Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databa…

No fix yet
Fix from $1,600 2010-04-27
Chrome HIGH 10.0
CVE-2010-1505

Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.

Fix: after 4.1.249.1058
Fix from $1,950 2010-04-23
Diskos Cms MEDIUM 5.0
CVE-2009-4799

Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database…

No fix yet
Fix from $1,600 2010-04-22
Pvc2300 HIGH 9.0
CVE-2010-0593

The Cisco RVS4000 4-port Gigabit Security Router before 1.3.2.0, PVC2300 Business Internet Video Camera before 1.1.2.6, WVC200 Wireless-G PTZ Interne…

Fix: after 1.3.1.0
Fix from $1,950 2010-04-22
Windows Xp MEDIUM 6.4
CVE-2010-0812EPSS 17%

Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 allow remote attackers to bypass intended I…

Mitigation only
Fix from $1,600 2010-04-14
Hikaye Portal MEDIUM 5.0
CVE-2009-4765

CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d…

No fix yet
Fix from $1,600 2010-04-13
Ms Pro Portal Scripti MEDIUM 5.0
CVE-2009-4766

YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with insufficient access control, whi…

No fix yet
Fix from $1,600 2010-04-13
Workstation MEDIUM 6.9
CVE-2010-1140

The USB service in VMware Workstation 7.0 before 7.0.1 build 227600 and VMware Player 3.0 before 3.0.1 build 227600 on Windows might allow host OS us…

Patch available
Fix from $1,600 2010-04-12
Workstation HIGH 8.5
CVE-2010-1141

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 buil…

Patch available
Fix from $1,950 2010-04-12
Workstation HIGH 8.5
CVE-2010-1142

VMware Tools in VMware Workstation 6.5.x before 6.5.4 build 246459; VMware Player 2.5.x before 2.5.4 build 246459; VMware ACE 2.5.x before 2.5.4 buil…

Patch available
Fix from $1,950 2010-04-12
Linux Kernel MEDIUM 6.9
CVE-2010-1146

The Linux kernel 2.6.33.2 and earlier, when a ReiserFS filesystem exists, does not restrict read or write access to the .reiserfs_priv directory, whi…

Fix: after 2.6.33.2
Fix from $1,600 2010-04-12
Director Agent HIGH 7.2
CVE-2010-1347

Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/direct…

Mitigation only
Fix from $1,950 2010-04-12
Airport Utility MEDIUM 6.8
CVE-2009-2822

AirPort Utility before 5.5.1 for Apple AirPort Base Station does not properly distribute MAC address ACLs to network extenders, which allows remote a…

Fix: after 5.4.2
Fix from $1,600 2010-04-05
Brltty MEDIUM 6.9
CVE-2008-3279

Untrusted search path vulnerability in libbrlttybba.so in brltty 3.7.2 allows local users to gain privileges via a crafted library, related to an inc…

Mitigation only
Fix from $1,600 2010-04-05
Moinmoin MEDIUM 5.0
CVE-2010-1238

MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have…

Mitigation only
Fix from $1,600 2010-04-05
Acrobat Reader HIGH 9.3
CVE-2010-1240EPSS 74%

Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch…

No fix yet
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 7.5
CVE-2000-1245

Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended…

Fix: after 5.01i
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 7.5
CVE-2003-1593

NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote…

Mitigation only
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 7.5
CVE-2003-1594

NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to by…

Mitigation only
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 10.0
CVE-2003-1595

NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and at…

No fix yet
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 7.5
CVE-2003-1596

NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home dire…

Fix: after 5.03b
Fix from $1,950 2010-04-05
Netware Ftp Server HIGH 7.5
CVE-2007-6735

NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, w…

Mitigation only
Fix from $1,950 2010-04-05
Virtual Pc HIGH 9.3
CVE-2010-1225EPSS 28%

The memory-management implementation in the Virtual Machine Monitor (aka VMM or hypervisor) in Microsoft Virtual PC 2007 Gold and SP1, Virtual Server…

No fix yet
Fix from $1,950 2010-04-01
Mac Os X Server HIGH 9.0
CVE-2010-0522

Server Admin in Apple Mac OS X Server 10.5.8 does not properly determine the privileges of users who had former membership in the admin group, which …

Patch available
Fix from $1,950 2010-03-30
Mac Os X HIGH 7.5
CVE-2010-0524

The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of a…

Mitigation only
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.5
CVE-2010-0535

Dovecot in Apple Mac OS X 10.6 before 10.6.3, when Kerberos is enabled, does not properly enforce the service access control list (SACL) for sending …

Mitigation only
Fix from $1,600 2010-03-30