Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Linux Kernel MEDIUM 6.6
CVE-2009-3889

The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the…

Fix: after 2.6.26
Fix from $1,600 2009-11-16
Mac Os X Server MEDIUM 5.0
CVE-2009-2818

Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote …

Fix: after 10.6.1
Fix from $1,600 2009-11-10
Openjdk MEDIUM 5.0
CVE-2009-3880

The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not…

Fix: after 1.6.0
Fix from $1,600 2009-11-09
Crmngp MEDIUM 5.0
CVE-2009-3920

An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform the expected access control, wh…

Patch available
Fix from $1,600 2009-11-09
Linux Kernel HIGH 7.2
CVE-2009-3725

The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (…

Fix: 2.6.31.5+
Fix from $1,950 2009-11-06
Cubecart HIGH 7.5
CVE-2009-3904EPSS 9%

classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to…

Patch available
Fix from $1,950 2009-11-06
Comraider MEDIUM 5.8
CVE-2009-3860

Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateF…

No fix yet
Fix from $1,600 2009-11-04
Mahara MEDIUM 6.5
CVE-2009-3298

Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspe…

Fix: after 1.0.12
Fix from $1,600 2009-11-03
Linux Kernel HIGH 7.1
CVE-2009-3722

The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege …

Fix: after 2.6.31
Fix from $1,950 2009-10-30
Firefox HIGH 7.5
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce i…

Patch available
Fix from $1,950 2009-10-29
Acrobat HIGH 9.3
CVE-2009-3461

Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors.

Patch available
Fix from $1,950 2009-10-19
Mcshoutbox MEDIUM 6.5
CVE-2009-3716

Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file…

No fix yet
Fix from $1,600 2009-10-16
Fusion HIGH 7.2
CVE-2009-3281

The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privi…

Fix: after 2.0.5
Fix from $1,950 2009-10-16
Windows 2000 HIGH 9.3
CVE-2009-0090EPSS 21%

Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unint…

Mitigation only
Fix from $1,950 2009-10-14
Ajox Poll HIGH 7.5
CVE-2009-3596

JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain ad…

No fix yet
Fix from $1,950 2009-10-08
Commentrss MEDIUM 5.0
CVE-2009-3568

Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS fee…

Patch available
Fix from $1,600 2009-10-06
Xen HIGH 7.2
CVE-2009-3525

The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows…

Patch available
Fix from $1,950 2009-10-05
Db2 MEDIUM 6.5
CVE-2009-3472

IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, inser…

Mitigation only
Fix from $1,600 2009-09-29
Meta Tags MEDIUM 5.0
CVE-2009-3442

The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows…

Patch available
Fix from $1,600 2009-09-28
Hp Ux HIGH 7.2
CVE-2009-2682

Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictio…

Patch available
Fix from $1,950 2009-09-24
Backuppc HIGH 8.5
CVE-2009-3369

CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias…

Mitigation only
Fix from $1,950 2009-09-24
Vtiger Crm HIGH 9.0
CVE-2009-3258

vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie…

Mitigation only
Fix from $1,950 2009-09-18
PostgreSQL MEDIUM 6.5
CVE-2009-3230

The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7…

Mitigation only
Fix from $1,600 2009-09-17
Imagecache MEDIUM 6.8
CVE-2009-3207

The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly …

Patch available
Fix from $1,600 2009-09-16
Fedora MEDIUM 6.0
CVE-2009-2813

Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Wi…

Mitigation only
Fix from $1,600 2009-09-14
Greensql Firewall HIGH 7.5
CVE-2008-7229

GreenSQL Firewall (greensql-fw) before 0.9.2 allows remote attackers to bypass SQL injection protection via a crafted string, possibly involving an e…

Patch available
Fix from $1,950 2009-09-14
Groupware HIGH 10.0
CVE-2008-7219

Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo…

Patch available
Fix from $1,950 2009-09-13
Gazelle Cms MEDIUM 6.8
CVE-2009-3182

Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbi…

No fix yet
Fix from $1,600 2009-09-11
Onecms HIGH 7.5
CVE-2008-7209EPSS 6%

Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arb…

Fix: after 2.4
Fix from $1,950 2009-09-11
Mambo MEDIUM 5.0
CVE-2008-7212

MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/edit…

Fix: after 4.6.3
Fix from $1,600 2009-09-11