Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aix HIGH 7.2
CVE-2009-2669

A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables,…

Patch available
Fix from $1,950 2009-08-05
Envision MEDIUM 5.0
CVE-2008-6886

RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attacker…

Patch available
Fix from $1,600 2009-08-03
Air HIGH 9.3
CVE-2009-1863EPSS 6%

Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a …

Fix: after 10.0.22.87
Fix from $1,950 2009-07-31
Guestbook MEDIUM 5.0
CVE-2009-2648

FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo fu…

No fix yet
Fix from $1,600 2009-07-30
Visual C\+\+ HIGH 8.8
CVE-2009-2493EPSS 38%

The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and…

Patch available
Fix from $1,950 2009-07-29
R2 Newsletter Lite MEDIUM 5.0
CVE-2009-2602

R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to…

No fix yet
Fix from $1,600 2009-07-27
Asp Football Pool MEDIUM 5.0
CVE-2009-2606

ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…

No fix yet
Fix from $1,600 2009-07-27
Educate Server MEDIUM 5.0
CVE-2008-6870

Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) c…

No fix yet
Fix from $1,600 2009-07-23
Educate Server MEDIUM 5.0
CVE-2008-6871

Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitiv…

No fix yet
Fix from $1,600 2009-07-23
Oramon MEDIUM 5.0
CVE-2008-6869EPSS 6%

Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote at…

No fix yet
Fix from $1,600 2009-07-23
Minitwitter MEDIUM 6.5
CVE-2009-2574

index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action.

No fix yet
Fix from $1,600 2009-07-22
Admin News Tools HIGH 7.5
CVE-2009-2558

system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct reques…

No fix yet
Fix from $1,950 2009-07-21
Getplus Download Manager HIGH 7.2
CVE-2009-2564EPSS 6%

NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.…

No fix yet
Fix from $1,950 2009-07-21
Netbsd MEDIUM 6.9
CVE-2009-2482

The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is alread…

Mitigation only
Fix from $1,600 2009-07-16
Isa Server HIGH 9.0
CVE-2009-1135EPSS 26%

Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w…

Mitigation only
Fix from $1,950 2009-07-15
Virtual Pc HIGH 9.0
CVE-2009-1542EPSS 8%

The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CP…

Mitigation only
Fix from $1,950 2009-07-15
Mathtex HIGH 7.2
CVE-2009-2461

mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vect…

Fix: after 1.02
Fix from $1,950 2009-07-14
Presentation Server HIGH 7.5
CVE-2009-2453

Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva…

Patch available
Fix from $1,950 2009-07-14
Siteframe Cms MEDIUM 5.0
CVE-2009-2443

Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which cal…

Patch available
Fix from $1,600 2009-07-13
WordPress MEDIUM 5.0
CVE-2009-2432

WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals…

Fix: after 2.7.1
Fix from $1,600 2009-07-10
Virtue Online Test Generator MEDIUM 6.5
CVE-2009-2393

admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to hav…

No fix yet
Fix from $1,600 2009-07-09
Advanced Forum MEDIUM 6.5
CVE-2009-2371

Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has…

Patch available
Fix from $1,600 2009-07-08
3d Sensor HIGH 9.0
CVE-2009-2344EPSS 9%

The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges …

Fix: after 4.8.1
Fix from $1,950 2009-07-07
Websphere Application Server MEDIUM 6.4
CVE-2009-0904

The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM…

Mitigation only
Fix from $1,600 2009-07-05
Ez Publish HIGH 7.5
CVE-2008-6844

The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote at…

Fix: after 3.5.6
Fix from $1,950 2009-07-02
Ard 9808 Software HIGH 7.5
CVE-2009-2306

The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers…

No fix yet
Fix from $1,950 2009-07-02
Logintoboggan MEDIUM 6.8
CVE-2009-2291

Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using their e-mail address" is ena…

Patch available
Fix from $1,600 2009-07-01
Tutorial Share HIGH 7.5
CVE-2009-2293

Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the …

Fix: after 3.5.0
Fix from $1,950 2009-07-01
Debian Linux MEDIUM 5.8
CVE-2009-1888

The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe…

Fix: 3.2.13 / 3.3.6+
Fix from $1,600 2009-06-25
Torrenttrader Classic MEDIUM 5.0
CVE-2009-2160

TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpin…

No fix yet
Fix from $1,600 2009-06-22