Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Week MEDIUM 5.0
CVE-2010-0752

The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restricti…

Patch available
Fix from $1,600 2010-02-27
Uzbl HIGH 7.5
CVE-2010-0011

The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arb…

Fix: after 2009.12.22
Fix from $1,950 2010-02-25
Sudo MEDIUM 6.9
CVE-2010-0426

sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the…

Patch available
Fix from $1,600 2010-02-24
Zeuscms MEDIUM 5.0
CVE-2010-0681

ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive infor…

No fix yet
Fix from $1,600 2010-02-22
Statcountex MEDIUM 5.0
CVE-2010-0674

StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databas…

No fix yet
Fix from $1,600 2010-02-22
Firefox MEDIUM 5.0
CVE-2009-3988

Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties i…

Fix: after 3.0.17
Fix from $1,600 2010-02-22
Jag MEDIUM 5.0
CVE-2010-0665

JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to …

No fix yet
Fix from $1,600 2010-02-19
Secure File Transfer Appliance HIGH 7.2
CVE-2009-4648

Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sud…

No fix yet
Fix from $1,950 2010-02-19
Chrome MEDIUM 6.8
CVE-2010-0661

WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypa…

Fix: after 4.0.249.0
Fix from $1,600 2010-02-18
Dokuwiki HIGH 7.5
CVE-2010-0288EPSS 11%

A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers …

No fix yet
Fix from $1,950 2010-02-15
Linux Kernel MEDIUM 6.5
CVE-2010-0298

The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available t…

Fix: after 2.6.33
Fix from $1,600 2010-02-12
Windows 2000 MEDIUM 6.9
CVE-2010-0023

The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes afte…

Mitigation only
Fix from $1,600 2010-02-10
Windows 2000 HIGH 10.0
CVE-2010-0231EPSS 41%

The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,…

Mitigation only
Fix from $1,950 2010-02-10
Openvms Rms MEDIUM 6.8
CVE-2010-0443

Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain…

Patch available
Fix from $1,600 2010-02-04
Maildrop MEDIUM 6.9
CVE-2010-0301

main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's hom…

Fix: after 2.3.0
Fix from $1,600 2010-02-04
Bugzilla MEDIUM 5.0
CVE-2009-3387

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a differen…

Patch available
Fix from $1,600 2010-02-03
Coldfusion MEDIUM 5.0
CVE-2010-0185

The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows re…

Mitigation only
Fix from $1,600 2010-02-03
Viewvc HIGH 7.5
CVE-2010-0005

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might …

Fix: after 1.1.2
Fix from $1,950 2010-01-29
Unified Meetingplace HIGH 8.5
CVE-2010-0142

MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentic…

Patch available
Fix from $1,950 2010-01-28
Php Calendars Script MEDIUM 5.0
CVE-2010-0380

install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application set…

No fix yet
Fix from $1,600 2010-01-22
Opensuse HIGH 7.5
CVE-2010-0230

SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers…

Mitigation only
Fix from $1,950 2010-01-22
phpMyAdmin HIGH 10.0
CVE-2008-7251

libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack…

Mitigation only
Fix from $1,950 2010-01-19
FreeBSD MEDIUM 6.9
CVE-2010-0318

The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777…

Patch available
Fix from $1,600 2010-01-15
Runtime Agent HIGH 7.2
CVE-2010-0184

The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveM…

Fix: after 5.6.1
Fix from $1,950 2010-01-14
Solaris MEDIUM 6.8
CVE-2010-0310

Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software upd…

Patch available
Fix from $1,600 2010-01-14
Webdrive HIGH 7.2
CVE-2009-4606

South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop t…

Mitigation only
Fix from $1,950 2010-01-13
Snap Server 410 HIGH 7.2
CVE-2009-4607

The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the …

Mitigation only
Fix from $1,950 2010-01-13
Uranyumsoft Listing Service MEDIUM 5.0
CVE-2009-4585

UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

No fix yet
Fix from $1,600 2010-01-06
Antivirus Plus 2009 HIGH 7.2
CVE-2009-4556

Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product f…

Mitigation only
Fix from $1,950 2010-01-04
Img Assist MEDIUM 5.0
CVE-2009-4558

The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before …

Patch available
Fix from $1,600 2010-01-04