Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Office Frontpage HIGH 8.5
CVE-2008-4252EPSS 21%

The DataGrid ActiveX control in Microsoft Visual Basic 6.0 and Visual FoxPro 8.0 SP1 and 9.0 SP1 and SP2 does not properly handle errors during acces…

Mitigation only
Fix from $1,950 2008-12-10
Aix MEDIUM 6.9
CVE-2008-5384

crontab in bos.rte.cron in IBM AIX 6.1.0 through 6.1.2 allows local users with aix.system.config.cron authorization to gain privileges by launching a…

Patch available
Fix from $1,600 2008-12-09
Aix MEDIUM 6.9
CVE-2008-5385

enq in bos.rte.printers in IBM AIX 6.1.0 through 6.1.2, when a print queue is defined in /etc/qconfig, allows local users to delete arbitrary files v…

Patch available
Fix from $1,600 2008-12-09
Unbuntu Privacy Remix HIGH 10.0
CVE-2008-5393

UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypas…

Fix: after 8.04
Fix from $1,950 2008-12-09
Tor HIGH 7.2
CVE-2008-5397

Tor before 0.2.0.32 does not properly process the (1) User and (2) Group configuration options, which might allow local users to gain privileges by l…

Fix: after 0.1.2.31
Fix from $1,950 2008-12-09
Tor HIGH 9.3
CVE-2008-5398

Tor before 0.2.0.32 does not properly process the ClientDNSRejectInternalAddresses configuration option in situations where an exit relay issues a po…

Fix: after 0.1.2.31
Fix from $1,950 2008-12-09
Jdk HIGH 10.0
CVE-2008-5340

Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlie…

Fix: after 6
Fix from $1,950 2008-12-05
Jdk HIGH 7.5
CVE-2008-5351

Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earli…

Fix: after 6
Fix from $1,950 2008-12-05
The Simple Forum HIGH 7.5
CVE-2008-5308EPSS 7%

The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which allows remote attackers to c…

No fix yet
Fix from $1,950 2008-12-02
Google Hack Honeypot File Upload Manager MEDIUM 6.4
CVE-2008-5283

Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action …

No fix yet
Fix from $1,600 2008-11-29
Todd Woolums Asp News Management MEDIUM 5.0
CVE-2008-5274

Todd Woolums ASP News Management 2.2 allows remote attackers to obtain news items via a direct request to (1) rss.asp, (2) viewheadings.asp, or (3) v…

Mitigation only
Fix from $1,600 2008-11-28
Enterprise Linux MEDIUM 6.0
CVE-2008-4313

A certain Red Hat patch for tog-pegasus in OpenGroup Pegasus 2.7.0 does not properly configure the PAM tty name, which allows remote authenticated us…

Patch available
Fix from $1,600 2008-11-27
Hf HIGH 7.2
CVE-2008-2378

Untrusted search path vulnerability in hfkernel in hf 0.7.3 and 0.8 allows local users to gain privileges via a Trojan horse killall program in a dir…

Patch available
Fix from $1,950 2008-11-26
Freeze Greetings MEDIUM 5.0
CVE-2008-5218

ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote attackers to obtain cleartext …

No fix yet
Fix from $1,600 2008-11-25
Opensolaris MEDIUM 5.8
CVE-2008-5133

ipnat in IP Filter in Sun Solaris 10 and OpenSolaris before snv_96, when running on a DNS server with Network Address Translation (NAT) configured, i…

Patch available
Fix from $1,600 2008-11-18
Membership Manager Pro MEDIUM 5.0
CVE-2008-5128

Ocean12 Membership Manager Pro stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt…

No fix yet
Fix from $1,600 2008-11-18
Poll Manager MEDIUM 5.0
CVE-2008-5129

Ocean12 Poll Manager Pro 1.00 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obta…

No fix yet
Fix from $1,600 2008-11-18
Calendar Manager MEDIUM 5.0
CVE-2008-5130

Ocean12 Calendar Manager Gold 2.04 stores sensitive information under the web root with insufficient access control, which allows remote attackers to…

No fix yet
Fix from $1,600 2008-11-18
Contact Manager MEDIUM 5.0
CVE-2008-5127

Ocean12 Contact Manager Pro 1.02 stores sensitive information under the web root with insufficient access control, which allows remote attackers to o…

No fix yet
Fix from $1,600 2008-11-18
Deterministic Network Enhancer HIGH 7.2
CVE-2008-5121

dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Client, (2) Blue Coat WinProxy, …

No fix yet
Fix from $1,950 2008-11-18
Service Manager HIGH 9.0
CVE-2008-4415

Unspecified vulnerability in HP Service Manager (HPSM) before 7.01.71 allows remote authenticated users to execute arbitrary code via unknown vectors.

Fix: after 7.0
Fix from $1,950 2008-11-17
Ro002 Router HIGH 7.5
CVE-2008-5041

Sweex RO002 Router with firmware Ts03-072 has "rdc123" as its default password for the "rdc123" account, which makes it easier for remote attackers t…

Mitigation only
Fix from $1,950 2008-11-12
Nagios MEDIUM 6.5
CVE-2008-5027EPSS 7%

The Nagios process in (1) Nagios before 3.0.5 and (2) op5 Monitor before 4.0.1 allows remote authenticated users to bypass authorization checks, and …

Fix: after 4.0.0
Fix from $1,600 2008-11-10
Coldfusion HIGH 7.2
CVE-2008-4831

Unspecified vulnerability in Adobe ColdFusion 8 and 8.0.1 and ColdFusion MX 7.0.2 allows local users to bypass sandbox restrictions, and obtain sensi…

Patch available
Fix from $1,950 2008-11-10
Ace MEDIUM 6.9
CVE-2008-4915

The CPU hardware emulation in VMware Workstation 6.0.5 and earlier and 5.5.8 and earlier; Player 2.0.x through 2.0.5 and 1.0.x through 1.0.8; ACE 2.0…

Fix: after 6.0.5
Fix from $1,600 2008-11-10
Tru64 HIGH 7.2
CVE-2008-4414

Unspecified vulnerability in the AdvFS showfile command in HP Tru64 UNIX 5.1B-3 and 5.1B-4 allows local users to gain privileges via unspecified vect…

Patch available
Fix from $1,950 2008-11-07
Acrobat HIGH 7.5
CVE-2008-4815EPSS 8%

Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.2 and earlier on Unix and Linux allows attackers to gain privileges via a Trojan …

Fix: after 8.1.2
Fix from $1,950 2008-11-05
Chipmunk Cms HIGH 7.5
CVE-2008-4921

board/admin/reguser.php in Chipmunk CMS 1.3 allows remote attackers to bypass authentication and gain administrator privileges via a direct request. …

No fix yet
Fix from $1,950 2008-11-04
System Management Homepage MEDIUM 6.2
CVE-2008-4413

Unspecified vulnerability in HP System Management Homepage (SMH) 2.2.6 and earlier on HP-UX B.11.11 and B.11.23, and SMH 2.2.6 and 2.2.8 and earlier …

Fix: after 2.2.6
Fix from $1,600 2008-11-04
Smarty HIGH 7.5
CVE-2008-4811

The _expand_quoted_text function in libs/Smarty_Compiler.class.php in Smarty 2.6.20 r2797 and earlier allows remote attackers to execute arbitrary PH…

Mitigation only
Fix from $1,950 2008-10-31