Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Drupal MEDIUM 6.0
CVE-2008-4789

The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restricti…

Fix: after 6.4
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4790

The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to…

Fix: after 5.10
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4791

The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and success…

Fix: 5.11 / 6.5+
Fix from $1,600 2008-10-29
Drupal MEDIUM 6.0
CVE-2008-4792

The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form…

Fix: 5.11 / 6.5+
Fix from $1,600 2008-10-29
Drupal HIGH 7.5
CVE-2008-4793

The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors…

Fix: after 5.10
Fix from $1,950 2008-10-29
Opera Browser MEDIUM 5.8
CVE-2008-4698

Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscript…

Fix: after 9.60
Fix from $1,600 2008-10-23
Access Essentials MEDIUM 6.8
CVE-2008-4676

Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti…

Fix: after 4.5
Fix from $1,600 2008-10-22
Mystats HIGH 7.5
CVE-2008-4644

hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header.

No fix yet
Fix from $1,950 2008-10-22
Pokermax Poker League Tournament Script HIGH 7.5
CVE-2008-4600

configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by sett…

No fix yet
Fix from $1,950 2008-10-18
Shindig Integrator HIGH 7.5
CVE-2008-4597

Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u…

Mitigation only
Fix from $1,950 2008-10-17
Site Builder HIGH 7.5
CVE-2008-4585

Belong Software Site Builder 0.1 beta allows remote attackers to bypass intended access restrictions and perform administrative actions via a direct …

Mitigation only
Fix from $1,950 2008-10-15
Dovecot MEDIUM 5.0
CVE-2008-4578

The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/…

Fix: after 1.1.3
Fix from $1,600 2008-10-15
Windows 2003 Server HIGH 7.2
CVE-2008-3464

afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly va…

Patch available
Fix from $1,950 2008-10-15
Nfs Utils HIGH 7.5
CVE-2008-4552

The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of argumen…

Fix: after 1.1.2
Fix from $1,950 2008-10-14
Mac Os X Server HIGH 7.5
CVE-2008-4215

Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that h…

Patch available
Fix from $1,950 2008-10-10
Lotus Quickr HIGH 7.5
CVE-2008-4507

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author …

Mitigation only
Fix from $1,950 2008-10-09
Asp News Management MEDIUM 5.0
CVE-2008-4511

Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attacker…

Mitigation only
Fix from $1,600 2008-10-09
Asp\/ms Access Shoutbox MEDIUM 5.0
CVE-2008-4512

ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers t…

Mitigation only
Fix from $1,600 2008-10-09
Lotus Quickr HIGH 7.5
CVE-2008-4506

Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" vi…

Mitigation only
Fix from $1,950 2008-10-09
Condor HIGH 7.2
CVE-2008-3830

Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to b…

Fix: after 7.0.4
Fix from $1,950 2008-10-08
Gallery MEDIUM 6.8
CVE-2008-4484

main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstr…

Fix: after 1.32
Fix from $1,600 2008-10-08
Design Review HIGH 9.3
CVE-2008-4472EPSS 8%

The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Revie…

No fix yet
Fix from $1,950 2008-10-07
System Analyzer Tool HIGH 7.2
CVE-2008-4451

The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via …

No fix yet
Fix from $1,950 2008-10-06
Light Imaging Toolkit HIGH 9.3
CVE-2008-4453EPSS 10%

The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePr…

Patch available
Fix from $1,950 2008-10-06
Player MEDIUM 6.8
CVE-2008-4279

The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000…

Fix: 1.0.8 / 2.0.5+
Fix from $1,600 2008-10-06
Xen HIGH 7.2
CVE-2008-4405

xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's writ…

No fix yet
Fix from $1,950 2008-10-03
Insight Diagnostics HIGH 7.8
CVE-2008-3542

Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors.

Fix: 7.9.1.2402+
Fix from $1,950 2008-10-02
Php Infoboard HIGH 7.5
CVE-2008-4334

PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1.

No fix yet
Fix from $1,950 2008-09-30
Netbackup Enterprise Server MEDIUM 6.5
CVE-2008-4339

Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7,…

Patch available
Fix from $1,600 2008-09-30
Myblog HIGH 7.5
CVE-2008-4341

add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=ye…

Fix: after 0.9.8
Fix from $1,950 2008-09-30