Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Rapid Classified MEDIUM 5.0
CVE-2008-6388

Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which allows remote attackers to down…

No fix yet
Fix from $1,600 2009-03-02
Aspired2poll MEDIUM 5.0
CVE-2008-6354

The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…

No fix yet
Fix from $1,600 2009-03-02
Aspired2protect MEDIUM 5.0
CVE-2008-6355

The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl…

No fix yet
Fix from $1,600 2009-03-02
Evcal Events Calendar MEDIUM 5.0
CVE-2008-6356

evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a d…

No fix yet
Fix from $1,600 2009-03-02
Mycal Personal Events Calendar MEDIUM 5.0
CVE-2008-6357

MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

No fix yet
Fix from $1,600 2009-03-02
Cf Shopkart MEDIUM 5.0
CVE-2008-6321

CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attackers to obtain sensitive info…

No fix yet
Fix from $1,600 2009-02-27
Local Classifieds HIGH 7.5
CVE-2008-6302

TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a direct request to Site_Admin/adm…

No fix yet
Fix from $1,950 2009-02-26
Acc Php Email HIGH 7.5
CVE-2008-6291

Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLETTERLOGIN cookie to "admin".

No fix yet
Fix from $1,950 2009-02-26
Acc Autos HIGH 7.5
CVE-2008-6292

Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) username_cookie to "admin," (2) righ…

No fix yet
Fix from $1,950 2009-02-26
Acc Real Estate HIGH 7.5
CVE-2008-6293

admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie…

No fix yet
Fix from $1,950 2009-02-26
Acc Statistics HIGH 7.5
CVE-2008-6294

admin/Index.php in Acc Statistics 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie …

No fix yet
Fix from $1,950 2009-02-26
Php Shop HIGH 7.5
CVE-2008-6296

admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting the user cookie to "demo."

No fix yet
Fix from $1,950 2009-02-26
Downloadcenter MEDIUM 5.0
CVE-2009-0732

Downloadcenter 2.1 stores common.h under the web root with insufficient access control, which allows remote attackers to obtain user credentials and …

Mitigation only
Fix from $1,600 2009-02-24
Mercury Quality Center HIGH 7.6
CVE-2007-5289EPSS 9%

HP Mercury Quality Center (QC) 9.2 and earlier, and possibly TestDirector, relies on cached client-side scripts to implement "workflow" and decisions…

Fix: after 9.2
Fix from $1,950 2009-02-24
Websphere Mq HIGH 7.2
CVE-2009-0439

Unspecified vulnerability in the queue manager in IBM WebSphere MQ (WMQ) 5.3, 6.0 before 6.0.2.6, and 7.0 before 7.0.0.2 allows local users to gain p…

Patch available
Fix from $1,950 2009-02-24
FreeBSD HIGH 9.3
CVE-2009-0641EPSS 9%

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in olde…

Patch available
Fix from $1,950 2009-02-20
Semantically Interconnected Online Communities MEDIUM 5.0
CVE-2008-6160

Semantically-Interconnected Online Communities (SIOC) 5.x before 5.x-1.2 and 6.x before 6.x-1.1, a module for Drupal, does not properly implement men…

Fix: after 6.x_1.0
Fix from $1,600 2009-02-18
Interscan Web Security Suite MEDIUM 6.0
CVE-2009-0613

Trend Micro InterScan Web Security Suite (IWSS) 3.1 before build 1237 allows remote authenticated Auditor and Report Only users to bypass intended pe…

Mitigation only
Fix from $1,600 2009-02-17
Forumapp MEDIUM 5.0
CVE-2008-6147

ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database v…

No fix yet
Fix from $1,600 2009-02-16
Everyblog HIGH 7.5
CVE-2008-6136

Unspecified vulnerability in EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to gain privileges as another user or an administrat…

No fix yet
Fix from $1,950 2009-02-14
Everyblog HIGH 7.5
CVE-2008-6137

EveryBlog 5.x and 6.x, a module for Drupal, allows remote attackers to bypass access restrictions via unknown vectors.

No fix yet
Fix from $1,950 2009-02-14
Mailist MEDIUM 5.0
CVE-2009-0571

admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access control, which allows remote …

No fix yet
Fix from $1,600 2009-02-13
Moodle MEDIUM 6.5
CVE-2008-6125

Unspecified vulnerability in the user editing interface in Moodle 1.5.x, 1.6 before 1.6.6, and 1.7 before 1.7.3 allows remote authenticated users to …

Fix: 1.6.6 / 1.7.3+
Fix from $1,600 2009-02-13
Mac Os X HIGH 7.2
CVE-2009-0011

Certificate Assistant in Apple Mac OS X 10.5.6 allows local users to overwrite arbitrary files via unknown vectors related to an "insecure file opera…

Patch available
Fix from $1,950 2009-02-13
Websphere Application Server HIGH 7.2
CVE-2009-0436

The (1) mod_ibm_ssl and (2) mod_cgid modules in IBM HTTP Server 6.0.x before 6.0.2.31 and 6.1.x before 6.1.0.19, as used in WebSphere Application Ser…

Patch available
Fix from $1,950 2009-02-10
Websphere Application Server MEDIUM 5.0
CVE-2009-0438

IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows allows remote attackers to bypass "Authorization checking" and obtain sensitive in…

Patch available
Fix from $1,600 2009-02-10
Fulltext Search Cgi HIGH 7.5
CVE-2009-0469

Unspecified vulnerability in futomi's CGI Cafe Fulltext search CGI 1.1.2 allows remote attackers to gain administrative privileges via unknown vector…

No fix yet
Fix from $1,950 2009-02-10
Virtual Guestbook MEDIUM 5.0
CVE-2009-0498

Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

No fix yet
Fix from $1,600 2009-02-10
Opensolaris HIGH 7.2
CVE-2009-0477

Unspecified vulnerability in the process (aka proc) filesystem in Sun OpenSolaris snv_85 through snv_100 allows local users to gain privileges via ve…

No fix yet
Fix from $1,950 2009-02-08
Database Server MEDIUM 5.1
CVE-2008-6065

Oracle Database Server 10.1, 10.2, and 11g grants directory WRITE permissions for arbitrary pathnames that are aliased in a CREATE OR REPLACE DIRECTO…

Mitigation only
Fix from $1,600 2009-02-05