Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Logoshows Bbs MEDIUM 5.0
CVE-2009-4545

Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a datab…

No fix yet
Fix from $1,600 2010-01-04
Storm MEDIUM 5.0
CVE-2009-4515

The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to …

Patch available
Fix from $1,600 2009-12-31
Commentreference MEDIUM 5.0
CVE-2009-4520

The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access re…

Fix: after 6.x-1.2
Fix from $1,600 2009-12-31
Print MEDIUM 5.0
CVE-2009-4526

The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drup…

Patch available
Fix from $1,600 2009-12-31
Og Vocab MEDIUM 6.5
CVE-2009-4528

The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restricti…

Patch available
Fix from $1,600 2009-12-31
Zabbix HIGH 9.3
CVE-2009-4502EPSS 22%

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRe…

Fix: after 1.6.6
Fix from $1,950 2009-12-31
Deluxebb HIGH 7.5
CVE-2009-4465

DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and confi…

No fix yet
Fix from $1,950 2009-12-30
Adaptive Security Appliance 5500 MEDIUM 6.5
CVE-2009-4455

The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to …

Mitigation only
Fix from $1,600 2009-12-29
Kaspersky Anti Virus MEDIUM 6.8
CVE-2009-4452

Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and In…

No fix yet
Fix from $1,600 2009-12-29
Db2 MEDIUM 6.5
CVE-2009-4438

The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege require…

Patch available
Fix from $1,600 2009-12-28
Framework MEDIUM 5.0
CVE-2009-4417

The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages t…

Fix: after 1.9.6
Fix from $1,600 2009-12-24
Db2 HIGH 7.2
CVE-2009-4331

The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and a…

Patch available
Fix from $1,950 2009-12-16
Moodle MEDIUM 5.0
CVE-2009-4299

mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which a…

Patch available
Fix from $1,600 2009-12-16
Moodle MEDIUM 6.0
CVE-2009-4301

mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remo…

Patch available
Fix from $1,600 2009-12-16
Linux Kernel HIGH 7.2
CVE-2009-4131

The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to ove…

Fix: after 2.6.32
Fix from $1,950 2009-12-13
Hb Ns HIGH 7.5
CVE-2009-4262

Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to obtain access to the admin control panel via a direct request to admin.php.

No fix yet
Fix from $1,950 2009-12-10
Acpid MEDIUM 6.9
CVE-2009-4033

A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users t…

Mitigation only
Fix from $1,600 2009-12-08
Acpid MEDIUM 6.9
CVE-2009-4235

acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive informati…

Patch available
Fix from $1,600 2009-12-08
Panda Antivirus HIGH 7.2
CVE-2009-4215

Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi…

Patch available
Fix from $1,950 2009-12-07
Phpbazar HIGH 7.5
CVE-2009-4222

phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to t…

Fix: after 2.1.1
Fix from $1,950 2009-12-07
Srr For Solaris HIGH 9.3
CVE-2009-4211

The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary di…

Mitigation only
Fix from $1,950 2009-12-04
Adaptive Security Appliance MEDIUM 6.8
CVE-2009-2631

Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL …

Mitigation only
Fix from $1,600 2009-12-04
FreeBSD HIGH 7.2
CVE-2009-4147

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBR…

Patch available
Fix from $1,950 2009-12-02
Cutenews MEDIUM 6.0
CVE-2009-4174

The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with…

No fix yet
Fix from $1,600 2009-12-02
FreeBSD HIGH 7.2
CVE-2009-4146

The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environme…

Patch available
Fix from $1,950 2009-12-02
Cacti HIGH 9.0
CVE-2009-4112EPSS 11%

Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memo…

Fix: after 0.8.7e
Fix from $1,950 2009-11-30
Simplog MEDIUM 5.0
CVE-2009-4091EPSS 7%

comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments vi…

No fix yet
Fix from $1,600 2009-11-29
Operations Manager HIGH 10.0
CVE-2009-3843EPSS 79%

HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to condu…

Mitigation only
Fix from $1,950 2009-11-24
Web Services HIGH 7.5
CVE-2009-4044

The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API …

Mitigation only
Fix from $1,950 2009-11-20
Infinity Script HIGH 7.5
CVE-2009-3949

cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows rem…

Fix: after 2.0.5
Fix from $1,950 2009-11-16