Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Webkit MEDIUM 5.0
CVE-2008-6059

xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 …

Mitigation only
Fix from $1,600 2009-02-05
Catalyst 3750 Series Integrated Wireless Lan Controller HIGH 9.0
CVE-2009-0062

Unspecified vulnerability in the Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 In…

Mitigation only
Fix from $1,950 2009-02-05
Firefox MEDIUM 5.4
CVE-2009-0355

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab rest…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Firefox MEDIUM 5.0
CVE-2009-0357

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTT…

Fix: after 3.0.5
Fix from $1,600 2009-02-04
Xml Core Services MEDIUM 5.0
CVE-2009-0419EPSS 15%

Microsoft XML Core Services, as used in Microsoft Expression Web, Office, Internet Explorer 6 and 7, and other products, does not properly restrict a…

Mitigation only
Fix from $1,600 2009-02-04
Metacart MEDIUM 5.0
CVE-2008-6051

MetaCart Free stores metacart.mdb under the web root with insufficient access control, which allows remote attackers to obtain usernames and password…

Mitigation only
Fix from $1,600 2009-02-04
Pre E Learning Portal MEDIUM 5.0
CVE-2008-6052

PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers to obtai…

No fix yet
Fix from $1,600 2009-02-04
Pre Resume Submitter MEDIUM 5.0
CVE-2008-6053

PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers to obtain…

No fix yet
Fix from $1,600 2009-02-04
Pre Courier And Cargo Business MEDIUM 5.0
CVE-2008-6054

PreProjects Pre Courier and Cargo Business stores dbcourior.mdb under the web root with insufficient access control, which allows remote attackers to…

No fix yet
Fix from $1,600 2009-02-04
Pre Classified Listings MEDIUM 5.0
CVE-2008-6055

PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to obtain pa…

No fix yet
Fix from $1,600 2009-02-04
Liberum Help Desk MEDIUM 5.0
CVE-2008-6057

Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote attackers to …

No fix yet
Fix from $1,600 2009-02-04
Chipmunk Blogger HIGH 7.5
CVE-2009-0399

Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vul…

No fix yet
Fix from $1,950 2009-02-03
Chrome MEDIUM 5.0
CVE-2009-0411

Google Chrome before 1.0.154.46 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, whi…

Fix: after 1.0.154.43
Fix from $1,600 2009-02-03
Max.blog MEDIUM 6.4
CVE-2009-0383

delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog posts via a direct request.

Patch available
Fix from $1,600 2009-02-02
Hybook MEDIUM 5.0
CVE-2008-6008

hyBook Guestbook Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a…

Mitigation only
Fix from $1,600 2009-01-30
Systrace HIGH 7.2
CVE-2009-0342

Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall w…

Fix: after 1.6e
Fix from $1,950 2009-01-29
Systrace HIGH 7.2
CVE-2009-0343

Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit sysc…

Fix: after 1.6e
Fix from $1,950 2009-01-29
Fire X2100 M2 HIGH 10.0
CVE-2009-0344

Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 a…

Fix: after 3.19
Fix from $1,950 2009-01-29
Fire X2100 M2 HIGH 10.0
CVE-2009-0345

Unspecified vulnerability in the Embedded Lights Out Manager (ELOM) on the Sun Fire X2100 M2 and X2200 M2 x86 platforms before SP/BMC firmware 3.20 a…

Fix: after 3.19
Fix from $1,950 2009-01-29
Digital Sales Ipn MEDIUM 5.0
CVE-2009-0328EPSS 7%

ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root with insufficient access contr…

No fix yet
Fix from $1,600 2009-01-29
Blogit\! MEDIUM 5.0
CVE-2009-0336

Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the …

No fix yet
Fix from $1,600 2009-01-29
Adnforum HIGH 7.5
CVE-2008-6001

index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpusuario cookie composed of an …

Fix: after 1.0b
Fix from $1,950 2009-01-28
Mailing List Manager MEDIUM 5.0
CVE-2008-5980

Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allows remote attackers to downloa…

No fix yet
Fix from $1,600 2009-01-27
Pacpoll MEDIUM 5.0
CVE-2008-5981

PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database vi…

No fix yet
Fix from $1,600 2009-01-27
Webboard MEDIUM 5.0
CVE-2008-5956

Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers…

No fix yet
Fix from $1,600 2009-01-23
Template Creature MEDIUM 5.0
CVE-2008-5951

ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…

No fix yet
Fix from $1,600 2009-01-23
Rankem MEDIUM 5.0
CVE-2009-0249

Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat…

No fix yet
Fix from $1,600 2009-01-22
Phosheezy MEDIUM 5.0
CVE-2009-0250EPSS 6%

Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…

No fix yet
Fix from $1,600 2009-01-22
Xm Events Diary MEDIUM 5.0
CVE-2008-5925

ASP-DEv XM Events Diary stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t…

No fix yet
Fix from $1,600 2009-01-21
Vp Asp Shopping Cart MEDIUM 5.0
CVE-2008-5929

VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…

No fix yet
Fix from $1,600 2009-01-21