Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth…
The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using …
FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…
FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…
chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …
Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknow…
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to…
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat…
Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows rem…
The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes i…
The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combinati…
The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security …
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database…
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contai…
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack …
BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file cont…
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containin…
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informati…
The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a white…
GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to cha…
Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to by…
Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacker…
SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, u…
Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacke…
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote a…
JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file v…
ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data…