Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Sip Enablement Services HIGH 7.5
CVE-2008-3778

The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on t…

Mitigation only
Fix from $1,950 2008-08-25
Mailscan MEDIUM 5.0
CVE-2008-3728

Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access…

No fix yet
Fix from $1,600 2008-08-20
Harmoni MEDIUM 5.0
CVE-2008-3717

Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sens…

Fix: after 1.4.7
Fix from $1,600 2008-08-19
Postfix MEDIUM 6.2
CVE-2008-2936

Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, al…

Patch available
Fix from $1,600 2008-08-18
Linux Imaging And Printing Project HIGH 7.2
CVE-2008-2940

The alert-mailing implementation in HP Linux Imaging and Printing (HPLIP) 1.6.7 allows local users to gain privileges and send e-mail messages from t…

Mitigation only
Fix from $1,950 2008-08-14
Com User HIGH 7.5
CVE-2008-3681EPSS 9%

components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows remote attackers to reset the…

No fix yet
Fix from $1,950 2008-08-14
Hp Ux HIGH 10.0
CVE-2008-1668

ftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which P…

Mitigation only
Fix from $1,950 2008-08-13
Ruby HIGH 7.5
CVE-2008-3655EPSS 14%

Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 does not properly restrict access to critical varia…

Fix: after 1.8.5
Fix from $1,950 2008-08-13
Outlook Express HIGH 7.1
CVE-2008-1448EPSS 27%

The MHTML protocol handler in a component of Microsoft Outlook Express 5.5 SP2 and 6 through SP1, and Windows Mail, does not assign the correct Inter…

Patch available
Fix from $1,950 2008-08-13
Php Ring Webring System HIGH 7.5
CVE-2008-3602

admin/wr_admin.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9.1 allows remote attackers to bypass authentication and gain administrative …

No fix yet
Fix from $1,950 2008-08-12
Encrypted Usb Manager MEDIUM 6.8
CVE-2008-3605

Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to con…

Patch available
Fix from $1,600 2008-08-12
Enterprise Application Platform MEDIUM 5.0
CVE-2008-3273EPSS 47%

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensiti…

Fix: after 4.3.0
Fix from $1,600 2008-08-10
Php Nuke MEDIUM 5.0
CVE-2008-3573

The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random number (the ts_random value) w…

No fix yet
Fix from $1,600 2008-08-10
J2me HIGH 10.0
CVE-2008-3553EPSS 6%

Multiple unspecified vulnerabilities in Nokia Series 40 3rd edition devices allow remote attackers to execute arbitrary code via unknown vectors, pro…

No fix yet
Fix from $1,950 2008-08-08
Free Hosting Manager HIGH 7.5
CVE-2008-3557

Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by setting both the adminuser and lo…

No fix yet
Fix from $1,950 2008-08-08
Litenews MEDIUM 5.0
CVE-2008-3508

LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administrative access by setting the a…

No fix yet
Fix from $1,600 2008-08-07
R3000 Internet Filter HIGH 7.8
CVE-2008-3494

8e6 R3000 Internet Filter 2.0.12.10 allows remote attackers to bypass intended restrictions via an extra HTTP Host header with additional leading tex…

No fix yet
Fix from $1,950 2008-08-06
Metaframe Presentation Server HIGH 7.2
CVE-2008-3485

Untrusted search path vulnerability in Citrix MetaFrame Presentation Server allows local users to gain privileges via a malicious icabar.exe placed i…

Fix: after 3.0
Fix from $1,950 2008-08-06
Imanager HIGH 7.5
CVE-2008-3488

Unspecified vulnerability in Novell iManager before 2.7 SP1 (2.7.1) allows remote attackers to delete Plug-in Studio created Property Book Pages via …

Patch available
Fix from $1,950 2008-08-06
Php Hosting Directory HIGH 7.5
CVE-2008-3454

JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the "adm" cookie value …

No fix yet
Fix from $1,950 2008-08-04
Sunos HIGH 7.2
CVE-2008-3450

Unspecified vulnerability in the namefs kernel module in Sun Solaris 8 through 10 allows local users to gain privileges or cause a denial of service …

Patch available
Fix from $1,950 2008-08-04
Websphere Portal HIGH 7.5
CVE-2008-3423

IBM WebSphere Portal 5.1 through 6.1.0.0 allows remote attackers to bypass authentication and obtain administrative access via unspecified vectors.

Patch available
Fix from $1,950 2008-08-04
Nfs Utils HIGH 7.5
CVE-2008-1376

A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allo…

Mitigation only
Fix from $1,950 2008-08-01
Atmail MEDIUM 5.0
CVE-2008-3395

Calacode @Mail 5.41 on Linux uses weak world-readable permissions for (1) webmail/libs/Atmail/Config.php and (2) webmail/webadmin/.htpasswd, which al…

Mitigation only
Fix from $1,600 2008-07-31
Jamroom HIGH 10.0
CVE-2008-3376

Multiple unspecified vulnerabilities in JamRoom before 3.4.0 have unknown impact and attack vectors.

Fix: after 3.3.8
Fix from $1,950 2008-07-30
Realplayer HIGH 10.0
CVE-2008-3064

Unspecified vulnerability in RealNetworks RealPlayer Enterprise, RealPlayer 10, and RealPlayer 10.5 before build 6.0.12.1675 has unknown impact and a…

Mitigation only
Fix from $1,950 2008-07-28
Data Ontap HIGH 10.0
CVE-2008-3349

Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary c…

Mitigation only
Fix from $1,950 2008-07-28
Alphadmin Cms HIGH 7.5
CVE-2008-3300EPSS 6%

AlphAdmin CMS 1.0.5/03 allows remote attackers to bypass authentication and gain administrative access by setting the aa_login cookie value to 1. NO…

No fix yet
Fix from $1,950 2008-07-25
Bilboblog MEDIUM 6.8
CVE-2008-3303EPSS 5%

admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication and obtain administrative acce…

No fix yet
Fix from $1,600 2008-07-25
Phpscheduleit MEDIUM 6.8
CVE-2008-3268

Unspecified vulnerability in phpScheduleIt 1.2.0 through 1.2.9, when useLogonName is enabled, allows remote attackers with administrator email addres…

Mitigation only
Fix from $1,600 2008-07-24