Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Java System Identity Manager MEDIUM 6.4
CVE-2009-1084

Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth…

Patch available
Fix from $1,600 2009-03-25
Compiz Fusion MEDIUM 6.2
CVE-2008-6514

The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using …

Patch available
Fix from $1,600 2009-03-24
Fubarforum MEDIUM 5.0
CVE-2009-1051

FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…

Fix: after 1.6
Fix from $1,600 2009-03-24
Fireant MEDIUM 5.0
CVE-2009-1052

FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…

Fix: after 1.3
Fix from $1,600 2009-03-24
Chaozzdb MEDIUM 5.0
CVE-2009-1053

chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …

Fix: after 1.2
Fix from $1,600 2009-03-24
Phpbb MEDIUM 5.0
CVE-2008-6506

Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknow…

Fix: after 3.0.3
Fix from $1,600 2009-03-23
Easy Content Management Publishing MEDIUM 5.0
CVE-2008-6493

Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to…

No fix yet
Fix from $1,600 2009-03-20
Asp User Engine.net MEDIUM 5.0
CVE-2008-6494

ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat…

No fix yet
Fix from $1,600 2009-03-20
Expert Pdf Editorx HIGH 8.8
CVE-2008-6496

Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows rem…

No fix yet
Fix from $1,950 2009-03-20
8100c Digital Sender HIGH 7.6
CVE-2009-0941

The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes i…

Mitigation only
Fix from $1,950 2009-03-18
Opensolaris MEDIUM 6.8
CVE-2009-0872

The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combinati…

Patch available
Fix from $1,600 2009-03-11
Opensolaris MEDIUM 6.8
CVE-2009-0873

The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security …

Patch available
Fix from $1,600 2009-03-11
Phnews MEDIUM 5.0
CVE-2009-0866

pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database…

No fix yet
Fix from $1,600 2009-03-10
Team Board MEDIUM 5.0
CVE-2009-0760

Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …

No fix yet
Fix from $1,600 2009-03-06
Kipper MEDIUM 5.0
CVE-2009-0767

Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contai…

No fix yet
Fix from $1,600 2009-03-06
Dotnetnuke MEDIUM 6.4
CVE-2008-6399

Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack …

Mitigation only
Fix from $1,600 2009-03-05
Bloghelper MEDIUM 5.0
CVE-2009-0826

BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file cont…

No fix yet
Fix from $1,600 2009-03-05
Pollhelper MEDIUM 5.0
CVE-2009-0827

PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containin…

No fix yet
Fix from $1,600 2009-03-05
Quotebook MEDIUM 5.0
CVE-2009-0828

QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informati…

No fix yet
Fix from $1,600 2009-03-05
Wesnoth HIGH 9.3
CVE-2009-0367EPSS 11%

The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a white…

Patch available
Fix from $1,950 2009-03-05
Ubuntu Linux MEDIUM 6.2
CVE-2009-0578

GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to cha…

Mitigation only
Fix from $1,600 2009-03-05
Opengoo MEDIUM 6.5
CVE-2009-0806

Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors.

Fix: after 1.2
Fix from $1,600 2009-03-04
Zfeeder HIGH 7.5
CVE-2009-0807

zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.

No fix yet
Fix from $1,950 2009-03-04
Squid Web Proxy Cache MEDIUM 5.4
CVE-2009-0801

Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to by…

Mitigation only
Fix from $1,600 2009-03-04
Wingate MEDIUM 5.4
CVE-2009-0802

Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacker…

Mitigation only
Fix from $1,600 2009-03-04
Networkguardian MEDIUM 5.4
CVE-2009-0803

SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, u…

Mitigation only
Fix from $1,600 2009-03-04
Ziproxy MEDIUM 5.4
CVE-2009-0804

Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacke…

Mitigation only
Fix from $1,600 2009-03-04
Mailinglistpro MEDIUM 5.0
CVE-2008-6374

CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote a…

No fix yet
Fix from $1,600 2009-03-02
Jbook MEDIUM 5.0
CVE-2008-6375

JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file v…

No fix yet
Fix from $1,600 2009-03-02
Aspportal MEDIUM 5.0
CVE-2008-6382

ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data…

No fix yet
Fix from $1,600 2009-03-02