Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Opera Browser MEDIUM 5.0
CVE-2008-4195

Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows r…

Fix: after 9.51
Fix from $1,600 2008-09-27
Tivoli Netcool Webtop HIGH 7.2
CVE-2008-4294

IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a s…

Patch available
Fix from $1,950 2008-09-27
Mercurial MEDIUM 5.0
CVE-2008-4297

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbit…

Fix: after 1.0.1
Fix from $1,600 2008-09-27
Rianxosencabos Cms MEDIUM 6.5
CVE-2008-4245

The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a …

No fix yet
Fix from $1,600 2008-09-25
Firefox HIGH 7.5
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows rem…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview a…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4058EPSS 5%

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remo…

Fix: 1.1.12 / 2.0.0.17+
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chr…

Fix: after 2.0.0.17
Fix from $1,950 2008-09-24
Firefox HIGH 7.5
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create docum…

Fix: after 2.0.0.16
Fix from $1,950 2008-09-24
Talk MEDIUM 5.0
CVE-2008-4153

The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments,…

Fix: after 6.x-1.4
Fix from $1,600 2008-09-24
Solaris HIGH 7.2
CVE-2008-4131

Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1…

Patch available
Fix from $1,950 2008-09-19
Openssh MEDIUM 5.0
CVE-2008-4109EPSS 29%

A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functio…

Fix: after 4.3p2
Fix from $1,600 2008-09-18
Mac Os X MEDIUM 5.0
CVE-2008-2331

Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sha…

Patch available
Fix from $1,600 2008-09-16
Mac Os X HIGH 7.2
CVE-2008-3609

The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might al…

Patch available
Fix from $1,950 2008-09-16
Mac Os X HIGH 9.0
CVE-2008-3618

The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their …

Patch available
Fix from $1,950 2008-09-16
Aix HIGH 7.2
CVE-2008-4018

swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establi…

Mitigation only
Fix from $1,950 2008-09-11
Mybb HIGH 7.5
CVE-2008-3967

moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attac…

Fix: after 1.4.0
Fix from $1,950 2008-09-11
Pam Mount MEDIUM 6.9
CVE-2008-3970

pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which …

Mitigation only
Fix from $1,600 2008-09-11
Opensc MEDIUM 6.6
CVE-2008-3972

pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might …

Fix: after 0.11.5
Fix from $1,600 2008-09-11
Ipod Touch HIGH 7.1
CVE-2008-3631

Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which al…

Mitigation only
Fix from $1,950 2008-09-11
FreeBSD HIGH 7.2
CVE-2008-3890

The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local use…

Mitigation only
Fix from $1,950 2008-09-05
Bitlbee HIGH 7.5
CVE-2008-3920

Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors.

Fix: after 1.2.1
Fix from $1,950 2008-09-04
Linux Kernel HIGH 7.2
CVE-2008-3525

The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability b…

Mitigation only
Fix from $1,950 2008-09-03
Ace HIGH 7.2
CVE-2008-3698

Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 bu…

Fix: 1.0.7 / 1.0.8+
Fix from $1,950 2008-09-03
Opensolaris HIGH 7.2
CVE-2008-3875

The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions m…

Patch available
Fix from $1,950 2008-09-02
Db2 Universal Database MEDIUM 6.5
CVE-2008-3852

Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IB…

Fix: after 9.5
Fix from $1,600 2008-08-28
Db2 Universal Database HIGH 7.5
CVE-2008-3856

The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of …

Fix: after 9.1
Fix from $1,950 2008-08-28
Drupal MEDIUM 6.5
CVE-2008-3742

Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execut…

Mitigation only
Fix from $1,600 2008-08-27
Drupal MEDIUM 5.5
CVE-2008-3745

The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via u…

Patch available
Fix from $1,600 2008-08-27
WordPress HIGH 7.5
CVE-2008-3747

The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL commun…

Patch available
Fix from $1,950 2008-08-27