Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Nukedit MEDIUM 5.0
CVE-2008-5773

Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databas…

No fix yet
Fix from $1,600 2008-12-30
Forest Blog MEDIUM 5.0
CVE-2008-5780

Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the dat…

No fix yet
Fix from $1,600 2008-12-30
FreeBSD HIGH 7.2
CVE-2008-5736

Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p1, 7.0 before 7.0-RELEASE-p7,…

No fix yet
Fix from $1,950 2008-12-26
Mysql Calendar HIGH 7.5
CVE-2008-5738

Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the nodstrumCalendarV2…

No fix yet
Fix from $1,950 2008-12-26
Smart Security HIGH 7.2
CVE-2008-5724

The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows local users to gain privileges vi…

Fix: after 3.0.672
Fix from $1,950 2008-12-26
Powerstrip HIGH 7.2
CVE-2008-5725

The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local users to gain privileges via…

Fix: after 3.84
Fix from $1,950 2008-12-26
Xen HIGH 7.2
CVE-2008-5716

xend in Xen 3.3.0 does not properly restrict a guest VM's write access within the /local/domain xenstore directory tree, which allows guest OS users …

Mitigation only
Fix from $1,950 2008-12-24
Mediawiki MEDIUM 5.0
CVE-2008-5687

MediaWiki 1.11, and other versions before 1.13.3, does not properly protect against the download of backups of deleted images, which might allow remo…

Mitigation only
Fix from $1,600 2008-12-19
Websphere Portal HIGH 10.0
CVE-2008-5675

Unspecified vulnerability in IBM WebSphere Portal 6.0 before 6.0.1.5 has unknown impact and attack vectors related to "Access problems with BasicAuth…

Fix: after 6.0.1.4
Fix from $1,950 2008-12-19
Phparanoid MEDIUM 6.5
CVE-2008-5673

PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vect…

Fix: after 0.3
Fix from $1,600 2008-12-19
Firefox HIGH 7.5
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed previe…

Fix: after 2.0.0.18
Fix from $1,950 2008-12-17
Firefox MEDIUM 5.0
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to …

Fix: after 3.0.4
Fix from $1,600 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5506

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to…

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Firefox MEDIUM 6.8
CVE-2008-5512

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x …

Fix: 1.1.14 / 2.0.0.19+
Fix from $1,600 2008-12-17
Rsyslog HIGH 8.5
CVE-2008-5617

The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass inte…

Patch available
Fix from $1,950 2008-12-17
Mac Os X HIGH 9.3
CVE-2008-4234

Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers …

Fix: after 10.5.5
Fix from $1,950 2008-12-17
Ikon Admanager MEDIUM 5.0
CVE-2008-5596

Ikon AdManager 2.1 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

Fix: after 2.1
Fix from $1,600 2008-12-16
Cold Bbs MEDIUM 5.0
CVE-2008-5597

Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fil…

No fix yet
Fix from $1,600 2008-12-16
Teamworx Server MEDIUM 5.0
CVE-2008-5600

Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th…

No fix yet
Fix from $1,600 2008-12-16
Asp User Engine MEDIUM 5.0
CVE-2008-5601

User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the …

No fix yet
Fix from $1,600 2008-12-16
Natterchat MEDIUM 5.0
CVE-2008-5602

Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the datab…

No fix yet
Fix from $1,600 2008-12-16
Aspticker MEDIUM 5.0
CVE-2008-5603

ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databas…

No fix yet
Fix from $1,600 2008-12-16
Qmail Mailing List Manager MEDIUM 5.0
CVE-2008-5606

Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attacker…

No fix yet
Fix from $1,600 2008-12-16
Asp Autodealer MEDIUM 5.0
CVE-2008-5608

ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the databa…

No fix yet
Fix from $1,600 2008-12-16
Nightfall Personal Diary MEDIUM 5.0
CVE-2008-5592

Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downl…

No fix yet
Fix from $1,600 2008-12-16
Postecards MEDIUM 5.0
CVE-2008-5560

PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database f…

No fix yet
Fix from $1,600 2008-12-15
Aspportal MEDIUM 5.0
CVE-2008-5562EPSS 5%

ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database fi…

No fix yet
Fix from $1,600 2008-12-15
Professional Download Assistant MEDIUM 5.0
CVE-2008-5572EPSS 7%

Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers t…

No fix yet
Fix from $1,600 2008-12-15
Java System Portal Server MEDIUM 5.0
CVE-2008-5549

Unspecified vulnerability in the Sun Java Web Console components in Sun Java System Portal Server 7.1 and 7.2 allows remote attackers to access local…

Patch available
Fix from $1,600 2008-12-12
Ray Server Software HIGH 7.5
CVE-2008-5422

Sun Sun Ray Server Software 3.1 through 4.0 does not properly restrict access, which allows remote attackers to discover the Sun Ray administration p…

Patch available
Fix from $1,950 2008-12-11