Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Joomla HIGH 10.0
CVE-2008-3225

Joomla! before 1.5.4 allows attackers to access administration functionality, which has unknown impact and attack vectors related to a missing "LDAP …

Fix: after 1.5.3
Fix from $1,950 2008-07-18
Joomla MEDIUM 5.0
CVE-2008-3226

The file caching implementation in Joomla! before 1.5.4 allows attackers to access cached pages via unknown attack vectors.

Fix: after 1.5.3
Fix from $1,600 2008-07-18
Openssh MEDIUM 6.5
CVE-2008-3234EPSS 6%

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux rol…

No fix yet
Fix from $1,600 2008-07-18
Safari MEDIUM 6.8
CVE-2008-3170

Apple Safari allows web sites to set cookies for country-specific top-level domains, such as co.uk and com.au, which could allow remote attackers to …

Mitigation only
Fix from $1,600 2008-07-14
Opera MEDIUM 6.8
CVE-2008-3172

Opera allows web sites to set cookies for country-specific top-level domains that have DNS A records, such as co.tv, which could allow remote attacke…

Mitigation only
Fix from $1,600 2008-07-14
Panda Activescan HIGH 9.3
CVE-2008-3156

The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (C…

No fix yet
Fix from $1,950 2008-07-11
Novell Client For Windows MEDIUM 6.9
CVE-2008-3158EPSS 5%

Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests…

Patch available
Fix from $1,600 2008-07-11
Jdk MEDIUM 6.8
CVE-2008-3104

Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK an…

Fix: after 6
Fix from $1,600 2008-07-09
Jdk HIGH 10.0
CVE-2008-3107

Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Updat…

Fix: after 6
Fix from $1,950 2008-07-09
Jdk HIGH 10.0
CVE-2008-3112EPSS 26%

Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x bef…

Fix: after 6
Fix from $1,950 2008-07-09
Jdk HIGH 10.0
CVE-2008-3113EPSS 6%

Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to …

Fix: after 5.0
Fix from $1,950 2008-07-09
Outline Designer Module MEDIUM 6.5
CVE-2008-3096

The Outline Designer module 5.x before 5.x-1.4 for Drupal changes each content reader's authentication level to match that of the content author, whi…

Patch available
Fix from $1,600 2008-07-09
Firefox HIGH 7.5
CVE-2008-2802

Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allow remote attackers to execute arbitrary code via a…

Fix: after 2.0.0.14
Fix from $1,950 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2803

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does …

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Firefox MEDIUM 6.8
CVE-2008-2810

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assiste…

Fix: after 2.0.0.14
Fix from $1,600 2008-07-07
Dam Frontend Extension HIGH 7.5
CVE-2008-3041

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "…

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Dam Frontend Extension HIGH 10.0
CVE-2008-3042

Unspecified vulnerability in the DAM Frontend (dam_frontend) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors related to "…

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Packman Extension HIGH 7.5
CVE-2008-3046

Incomplete blacklist vulnerability in the Packman (kb_packman) extension 0.2.1 and earlier for TYPO3 has unknown impact and attack vectors.

Fix: after 0.2.1
Fix from $1,950 2008-07-07
Kb Unpack Extension HIGH 7.5
CVE-2008-3047

Incomplete blacklist vulnerability in the KB Unpack (kb_unpack) extension 0.1.0 and earlier for TYPO3 has unknown impact and attack vectors.

Fix: after 0.1.0
Fix from $1,950 2008-07-07
Aggregation Module MEDIUM 6.8
CVE-2008-3000

The Aggregation module 5.x before 5.x-4.4 for Drupal, when node access modules are used, does not properly implement access control, which allows rem…

Patch available
Fix from $1,600 2008-07-03
Mac Os X MEDIUM 6.8
CVE-2008-2309

Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a…

Patch available
Fix from $1,600 2008-07-01
Unified Communications Manager MEDIUM 5.0
CVE-2008-2062

The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)S…

Fix: 4.2 / 4.3+
Fix from $1,600 2008-06-26
Shibby Shop MEDIUM 5.0
CVE-2008-2873

sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

Fix: after 2.2
Fix from $1,600 2008-06-26
Shibby Shop HIGH 7.5
CVE-2008-2882

upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers to update a file or have uns…

Fix: after 2.2
Fix from $1,950 2008-06-26
Safari HIGH 9.3
CVE-2008-2306

Apple Safari before 3.1.2 on Windows does not properly interpret the URLACTION_SHELL_EXECUTE_HIGHRISK Internet Explorer zone setting, which allows re…

Fix: after 3.1.1
Fix from $1,950 2008-06-23
Mac Os X HIGH 7.2
CVE-2008-2830

Open Scripting Architecture in Apple Mac OS X 10.4.11 and 10.5.4, and some other 10.4 and 10.5 versions, does not properly restrict the loading of sc…

No fix yet
Fix from $1,950 2008-06-23
Workcentre HIGH 10.0
CVE-2008-2824

Unspecified vulnerability in the Extensible Interface Platform in Web Services in Xerox WorkCentre 7655, 7665, and 7675 allows remote attackers to ma…

Patch available
Fix from $1,950 2008-06-23
Altiris Notification Server MEDIUM 6.8
CVE-2008-2794

Unspecified vulnerability in the GUI in Symantec Altiris Notification Server Agent 6.x before 6.0 SP3 R8 allows local users to gain privileges via un…

Patch available
Fix from $1,600 2008-06-20
Spamdyke MEDIUM 6.4
CVE-2008-2784

The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attack…

Mitigation only
Fix from $1,600 2008-06-19
Drupal MEDIUM 5.0
CVE-2008-2771

The Node Hierarchy module 5.x before 5.x-1.1 and 6.x before 6.x-1.0 for Drupal does not properly implement access checks, which allows remote attacke…

Patch available
Fix from $1,600 2008-06-18