Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Ajaxtable MEDIUM 6.4
CVE-2009-3122

The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecifi…

Mitigation only
Fix from $1,600 2009-09-09
Coppermine Photo Gallery MEDIUM 5.0
CVE-2008-7186

Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as t…

Patch available
Fix from $1,600 2009-09-09
Clipshare HIGH 7.5
CVE-2008-7188

ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via …

No fix yet
Fix from $1,950 2009-09-09
Altiris Deployment Solution HIGH 7.2
CVE-2009-3108

The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyo…

Mitigation only
Fix from $1,950 2009-09-08
Websphere Application Server MEDIUM 5.0
CVE-2009-3106

The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security const…

Patch available
Fix from $1,600 2009-09-08
Page Manager HIGH 7.5
CVE-2008-7167

Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file…

No fix yet
Fix from $1,950 2009-09-08
Gsc HIGH 10.0
CVE-2008-7170EPSS 10%

GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator…

No fix yet
Fix from $1,950 2009-09-08
Lightweight News Portal HIGH 7.5
CVE-2008-7172

Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administra…

No fix yet
Fix from $1,950 2009-09-08
Internet Connectivity Kit HIGH 10.0
CVE-2008-7173

The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remot…

Mitigation only
Fix from $1,950 2009-09-08
Butterfly Organizer HIGH 7.5
CVE-2008-7181

Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with t…

No fix yet
Fix from $1,950 2009-09-08
Robohelp Server HIGH 9.3
CVE-2009-3068EPSS 78%

Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute …

No fix yet
Fix from $1,950 2009-09-04
Fortigate 1000 HIGH 7.5
CVE-2008-7161EPSS 6%

Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reque…

No fix yet
Fix from $1,950 2009-09-04
Netrisk HIGH 7.5
CVE-2008-7155

NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users v…

No fix yet
Fix from $1,950 2009-09-02
Ekinboard MEDIUM 6.8
CVE-2008-7157

Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file w…

Fix: after 1.1.0
Fix from $1,600 2009-09-02
Spip HIGH 7.5
CVE-2009-3041EPSS 7%

SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which all…

Patch available
Fix from $1,950 2009-09-01
Xyssl HIGH 7.5
CVE-2008-7128

The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which…

Fix: after 0.8
Fix from $1,950 2009-08-31
Scanner File Utility HIGH 9.3
CVE-2008-7111

The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it …

Mitigation only
Fix from $1,950 2009-08-28
F5d7632 4 HIGH 10.0
CVE-2008-7115

The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication …

No fix yet
Fix from $1,950 2009-08-28
Webid MEDIUM 5.0
CVE-2008-7117

eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with …

No fix yet
Fix from $1,600 2009-08-28
Webid MEDIUM 5.0
CVE-2008-7118

WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain …

No fix yet
Fix from $1,600 2009-08-28
Bios MEDIUM 6.9
CVE-2008-7096

Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local …

Patch available
Fix from $1,600 2009-08-27
Aruba Mobility Controller HIGH 7.8
CVE-2008-7095

The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP com…

Mitigation only
Fix from $1,950 2009-08-27
Chrome HIGH 10.0
CVE-2009-2935EPSS 5%

Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain…

Fix: after 2.0.172.37
Fix from $1,950 2009-08-27
Cuteflow HIGH 7.5
CVE-2009-2960

CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords…

No fix yet
Fix from $1,950 2009-08-25
Lovecms MEDIUM 6.8
CVE-2008-7062EPSS 7%

Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute a…

No fix yet
Fix from $1,600 2009-08-25
Openforum HIGH 7.5
CVE-2008-7066

OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update paramete…

No fix yet
Fix from $1,950 2009-08-25
Stararticles MEDIUM 6.5
CVE-2008-7076

Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to ex…

No fix yet
Fix from $1,600 2009-08-25
Php Classifieds Script MEDIUM 5.0
CVE-2008-7080EPSS 8%

Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…

No fix yet
Fix from $1,600 2009-08-25
Bandsite Cms MEDIUM 5.0
CVE-2008-7056

BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a…

No fix yet
Fix from $1,600 2009-08-24
Gemini Lite MEDIUM 6.8
CVE-2008-7024

admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by …

No fix yet
Fix from $1,600 2009-08-21