Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aspired2blog MEDIUM 5.0
CVE-2008-5931

The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…

No fix yet
Fix from $1,600 2009-01-21
Freeforum MEDIUM 5.0
CVE-2008-5932EPSS 6%

CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t…

No fix yet
Fix from $1,600 2009-01-21
Factosystem Weblog MEDIUM 5.0
CVE-2008-5935

Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file c…

Mitigation only
Fix from $1,600 2009-01-21
Git HIGH 7.5
CVE-2008-5516

The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se…

Mitigation only
Fix from $1,950 2009-01-20
Nfs Utils HIGH 7.5
CVE-2009-0180

Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which migh…

Fix: after 1.1.2
Fix from $1,950 2009-01-20
Java System Access Manager HIGH 9.0
CVE-2009-0169

Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin a…

Patch available
Fix from $1,950 2009-01-16
Java System Access Manager MEDIUM 6.0
CVE-2009-0170

Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obt…

Patch available
Fix from $1,600 2009-01-16
Sparc Enterprise Server HIGH 10.0
CVE-2009-0171

The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root pass…

Mitigation only
Fix from $1,950 2009-01-16
Hplip MEDIUM 6.9
CVE-2009-0122

hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via u…

Patch available
Fix from $1,600 2009-01-15
Bea Product Suite MEDIUM 5.0
CVE-2008-5459

Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality via unknown ve…

No fix yet
Fix from $1,600 2009-01-14
Bea Product Suite MEDIUM 6.8
CVE-2008-5461

Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remot…

Mitigation only
Fix from $1,600 2009-01-14
Bea Product Suite MEDIUM 6.8
CVE-2008-5462

Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to…

No fix yet
Fix from $1,600 2009-01-14
Linux Kernel HIGH 7.2
CVE-2009-0024

The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileg…

Fix: after 2.6.24
Fix from $1,950 2009-01-13
Aspired2quote MEDIUM 5.0
CVE-2008-5885EPSS 6%

The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa…

No fix yet
Fix from $1,600 2009-01-12
Discussion Web MEDIUM 5.0
CVE-2008-5886

TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

No fix yet
Fix from $1,600 2009-01-12
Ratemysite HIGH 7.5
CVE-2008-5896

CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …

No fix yet
Fix from $1,950 2009-01-12
Freewallpaper HIGH 7.5
CVE-2008-5897EPSS 6%

CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

No fix yet
Fix from $1,950 2009-01-12
Directory HIGH 7.5
CVE-2008-5898EPSS 6%

CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t…

No fix yet
Fix from $1,950 2009-01-12
Freeforall HIGH 7.5
CVE-2008-5899EPSS 6%

CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …

No fix yet
Fix from $1,950 2009-01-12
Articles HIGH 7.5
CVE-2008-5900EPSS 6%

CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th…

No fix yet
Fix from $1,950 2009-01-12
Iyzi Forum HIGH 7.5
CVE-2008-5901

iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the…

No fix yet
Fix from $1,950 2009-01-12
Phpauctions HIGH 7.5
CVE-2009-0108

PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID,…

No fix yet
Fix from $1,950 2009-01-09
Service Level Management HIGH 10.0
CVE-2009-0043EPSS 53%

The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which …

Patch available
Fix from $1,950 2009-01-08
Yerba HIGH 7.5
CVE-2008-5873

Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a …

Fix: after 6.3
Fix from $1,950 2009-01-08
Emefa Guestbook MEDIUM 5.0
CVE-2008-5852

Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the d…

No fix yet
Fix from $1,600 2009-01-06
Chicomas MEDIUM 5.0
CVE-2008-5853

Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, w…

Fix: after 2.0.4
Fix from $1,600 2009-01-06
Login Session MEDIUM 5.0
CVE-2008-5855

myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dis…

No fix yet
Fix from $1,600 2009-01-06
Phpicalendar HIGH 7.5
CVE-2008-5840

PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1.

Fix: after 2.24
Fix from $1,950 2009-01-05
Simple Text File Login Script MEDIUM 5.0
CVE-2008-5762

Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote …

No fix yet
Fix from $1,600 2008-12-30
Worksimple MEDIUM 5.0
CVE-2008-5765EPSS 6%

WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data…

No fix yet
Fix from $1,600 2008-12-30