Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Mac Os X MEDIUM 6.9
CVE-2010-0064

DesktopServices in Apple Mac OS X 10.6 before 10.6.3 preserves file ownership during an authenticated Finder copy, which might allow local users to b…

Patch available
Fix from $1,600 2010-03-30
Mac Os X HIGH 7.2
CVE-2010-0509

SFLServer in OS Services in Apple Mac OS X before 10.6.3 allows local users to gain privileges via vectors related to use of wheel group membership d…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Mac Os X Server MEDIUM 5.0
CVE-2010-0511

Podcast Producer in Apple Mac OS X 10.6 before 10.6.3 deletes the access restrictions of a Podcast Composer workflow when this workflow is overwritte…

Patch available
Fix from $1,600 2010-03-30
Mac Os X HIGH 9.3
CVE-2010-0512

The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window ac…

Patch available
Fix from $1,950 2010-03-30
Mac Os X MEDIUM 6.4
CVE-2009-2801

The Application Firewall in Apple Mac OS X 10.5.8 drops unspecified firewall rules after a reboot, which might allow remote attackers to bypass inten…

Patch available
Fix from $1,600 2010-03-30
Mac Os X HIGH 7.5
CVE-2010-0057

AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to b…

Fix: after 10.6.2
Fix from $1,950 2010-03-30
Moinmoin HIGH 7.5
CVE-2009-4762

MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, …

Patch available
Fix from $1,950 2010-03-29
Asp Guestbook MEDIUM 5.0
CVE-2009-4760

Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl…

No fix yet
Fix from $1,600 2010-03-29
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2010-1136

The Standard Remember method in TikiWiki CMS/Groupware 3.x before 3.5 allows remote attackers to bypass access restrictions related to "persistent lo…

Mitigation only
Fix from $1,950 2010-03-27
Firefox HIGH 7.6
CVE-2010-0168EPSS 12%

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.…

Patch available
Fix from $1,950 2010-03-25
Lookmer Muzik Portal MEDIUM 5.0
CVE-2010-1116

LookMer Music Portal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…

No fix yet
Fix from $1,600 2010-03-25
Safari MEDIUM 5.0
CVE-2010-1099

Integer overflow in Apple Safari allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside t…

Mitigation only
Fix from $1,600 2010-03-24
Erolife Ajxgaleri Vt MEDIUM 5.0
CVE-2010-1064

Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…

No fix yet
Fix from $1,600 2010-03-23
Ziyaretci Defteri MEDIUM 5.0
CVE-2010-1065

Lebisoft Ziyaretci Defteri 7.4 and 7.5 stores sensitive information under the web root with insufficient access control, which allows remote attacker…

No fix yet
Fix from $1,600 2010-03-23
Ar Web Content Manager MEDIUM 5.0
CVE-2010-1066

AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to …

No fix yet
Fix from $1,600 2010-03-23
E Membres MEDIUM 5.0
CVE-2010-1067

E-membres 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …

No fix yet
Fix from $1,600 2010-03-23
Seamonkey HIGH 7.1
CVE-2009-3385

The mail component in Mozilla SeaMonkey before 1.1.19 does not properly restrict execution of scriptable plugin content, which allows user-assisted r…

Fix: after 1.1.18
Fix from $1,950 2010-03-23
Libcurl MEDIUM 6.8
CVE-2010-0734

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an applicat…

Patch available
Fix from $1,600 2010-03-19
Acidcat Cms HIGH 7.5
CVE-2010-0976

Acidcat CMS 3.5.x does not prevent access to install.asp after installation finishes, which might allow remote attackers to restart the installation …

No fix yet
Fix from $1,950 2010-03-16
Pd Portal MEDIUM 5.0
CVE-2010-0977

PD PORTAL 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …

No fix yet
Fix from $1,600 2010-03-16
Guestbook MEDIUM 5.0
CVE-2010-0978

KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to d…

No fix yet
Fix from $1,600 2010-03-16
Acidcat Cms MEDIUM 5.0
CVE-2010-0984

Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to down…

Fix: after 3.5.3
Fix from $1,600 2010-03-16
Jevci Siparis Formu Scripti MEDIUM 5.0
CVE-2010-0965

Jevci Siparis Formu Scripti stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

No fix yet
Fix from $1,600 2010-03-16
Employee Timeclock Software MEDIUM 5.0
CVE-2010-0123

The database backup implementation in Employee Timeclock Software 0.99 stores sensitive information under the web root with insufficient access contr…

Mitigation only
Fix from $1,600 2010-03-15
Airport Express MEDIUM 5.0
CVE-2010-0962

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specifie…

No fix yet
Fix from $1,600 2010-03-10
Samba HIGH 8.5
CVE-2010-0728

smbd in Samba 3.3.11, 3.4.6, and 3.5.0, when libcap support is enabled, runs with the CAP_DAC_OVERRIDE capability, which allows remote authenticated …

Mitigation only
Fix from $1,950 2010-03-10
Abb Forum MEDIUM 5.0
CVE-2010-0939

Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …

No fix yet
Fix from $1,600 2010-03-08
Cups MEDIUM 6.9
CVE-2010-0393

The _cupsGetlang function, as used by lppasswd.c in lppasswd in CUPS 1.2.2, 1.3.7, 1.3.9, and 1.4.1, relies on an environment variable to determine t…

Mitigation only
Fix from $1,600 2010-03-05
Digital Media Manager HIGH 8.5
CVE-2010-0571

Unspecified vulnerability in Cisco Digital Media Manager (DMM) 5.0.x and 5.1.x allows remote authenticated users to gain privileges via unknown vecto…

Patch available
Fix from $1,950 2010-03-05
Fipsforum MEDIUM 5.0
CVE-2010-0765

fipsForum 2.6 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …

No fix yet
Fix from $1,600 2010-03-02