Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Nodequeue HIGH 7.5
CVE-2009-2075

Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when displaying node titles, which has un…

Patch available
Fix from $1,950 2009-06-16
The Ticket System HIGH 7.5
CVE-2009-2080

admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration in…

No fix yet
Fix from $1,950 2009-06-16
Firefox MEDIUM 5.4
CVE-2009-1839EPSS 7%

Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote…

Fix: after 3.0.10
Fix from $1,600 2009-06-12
Firefox HIGH 9.3
CVE-2009-1840

Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows …

Fix: after 3.0.10
Fix from $1,950 2009-06-12
Safari HIGH 7.2
CVE-2009-2027

The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the…

Fix: after 3.2.3
Fix from $1,950 2009-06-10
Windows 2000 HIGH 9.0
CVE-2009-0230EPSS 35%

The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote…

Mitigation only
Fix from $1,950 2009-06-10
Windows 2000 HIGH 10.0
CVE-2009-0568EPSS 32%

The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 do…

Mitigation only
Fix from $1,950 2009-06-10
Fipscms Light MEDIUM 5.0
CVE-2009-2022EPSS 5%

fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the dat…

No fix yet
Fix from $1,600 2009-06-09
Asp Vt Auth MEDIUM 5.0
CVE-2009-2024

Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

No fix yet
Fix from $1,600 2009-06-09
Dm Filemanager HIGH 7.5
CVE-2009-2025

admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) …

No fix yet
Fix from $1,950 2009-06-09
Pad Site Scripts MEDIUM 5.0
CVE-2009-1941

PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to down…

No fix yet
Fix from $1,600 2009-06-05
Jre HIGH 10.0
CVE-2004-2764

Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and un…

Mitigation only
Fix from $1,950 2009-06-02
Registration Manager MEDIUM 5.0
CVE-2009-1821

DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to …

No fix yet
Fix from $1,600 2009-05-29
Template Monster Clone MEDIUM 5.0
CVE-2009-1767

admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrar…

No fix yet
Fix from $1,600 2009-05-22
Flyspeck Cms HIGH 7.5
CVE-2009-1771

index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to c…

No fix yet
Fix from $1,950 2009-05-22
Office Message System HIGH 7.5
CVE-2009-1752

exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain …

No fix yet
Fix from $1,950 2009-05-22
Profense Web Application Firewall HIGH 7.5
CVE-2009-1594

Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows re…

Fix: after 2.2.21
Fix from $1,950 2009-05-21
Answer And Question Script MEDIUM 6.4
CVE-2009-1665

myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter wi…

No fix yet
Fix from $1,600 2009-05-18
Business Community Script HIGH 7.5
CVE-2009-1652EPSS 6%

admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and ad…

No fix yet
Fix from $1,950 2009-05-16
Simple Customer MEDIUM 6.4
CVE-2009-1637

profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address a…

No fix yet
Fix from $1,600 2009-05-15
Job Script Job Board Software HIGH 7.5
CVE-2009-1610EPSS 6%

admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator pri…

No fix yet
Fix from $1,950 2009-05-11
Garmin Communicator Plugin HIGH 9.3
CVE-2009-0194

The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4…

Mitigation only
Fix from $1,950 2009-05-11
Firefox HIGH 9.3
CVE-2009-1597

Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline …

No fix yet
Fix from $1,950 2009-05-11
Opera Browser HIGH 9.3
CVE-2009-1599

Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, …

Mitigation only
Fix from $1,950 2009-05-11
Safari HIGH 9.3
CVE-2009-1600

Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF…

Mitigation only
Fix from $1,950 2009-05-11
Linux MEDIUM 6.8
CVE-2009-1601

The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working director…

Patch available
Fix from $1,600 2009-05-11
Flashchat HIGH 7.5
CVE-2008-6799

connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s par…

No fix yet
Fix from $1,950 2009-05-07
Million Dollar Text Links HIGH 7.5
CVE-2009-1582

Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended res…

No fix yet
Fix from $1,950 2009-05-07
Abc Advertise MEDIUM 5.0
CVE-2009-1550

Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator log…

No fix yet
Fix from $1,600 2009-05-06
Nodeaccess Userreference HIGH 7.5
CVE-2009-1507

The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user refere…

Patch available
Fix from $1,950 2009-05-01