Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
WordPress HIGH 7.5
CVE-2008-2146

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attacke…

Fix: after 2.2.2
Fix from $1,950 2008-05-12
Appliance Platform Agent MEDIUM 6.5
CVE-2008-2139

The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, includin…

Mitigation only
Fix from $1,600 2008-05-12
Application Server Portal MEDIUM 5.0
CVE-2008-2138EPSS 16%

Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/p…

No fix yet
Fix from $1,600 2008-05-12
Robocode HIGH 7.5
CVE-2008-2078

Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT…

Fix: after 1.5.4
Fix from $1,950 2008-05-05
Smf HIGH 7.5
CVE-2008-2019

Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA,…

Mitigation only
Fix from $1,950 2008-04-30
Db2 HIGH 8.5
CVE-2008-1998

The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users …

Mitigation only
Fix from $1,950 2008-04-28
Badblue HIGH 7.5
CVE-2008-2003

BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1…

Mitigation only
Fix from $1,950 2008-04-28
Java System Directory Server HIGH 7.5
CVE-2008-1995

Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect applicati…

Mitigation only
Fix from $1,950 2008-04-28
Acidcat Cms HIGH 7.5
CVE-2008-1992

Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, whic…

No fix yet
Fix from $1,950 2008-04-27
Acidcat Cms HIGH 7.5
CVE-2008-1993

Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files.

No fix yet
Fix from $1,950 2008-04-27
Hd Audio Codec Drivers MEDIUM 6.8
CVE-2008-1931

Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry…

Fix: after 6.0.1.5604
Fix from $1,600 2008-04-25
Moinmoin MEDIUM 6.8
CVE-2008-1937

The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, whic…

Patch available
Fix from $1,600 2008-04-25
Windows Nt HIGH 9.0
CVE-2008-1436EPSS 37%

Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalSer…

No fix yet
Fix from $1,950 2008-04-21
Directory Server HIGH 7.5
CVE-2008-0893

Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows re…

Patch available
Fix from $1,950 2008-04-16
Socialware MEDIUM 6.5
CVE-2008-1790

Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo…

No fix yet
Fix from $1,600 2008-04-15
Reviews MEDIUM 6.4
CVE-2008-1783

Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.ph…

No fix yet
Fix from $1,600 2008-04-15
Topsites HIGH 7.5
CVE-2008-1784

Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php…

No fix yet
Fix from $1,950 2008-04-15
Simple Access HIGH 7.5
CVE-2008-1731

The Simple Access module for Drupal 5.x through 5.x-1.2-2 does not properly handle the privacy information for nodes, which might allow remote attack…

Patch available
Fix from $1,950 2008-04-11
Coldfusion HIGH 7.5
CVE-2008-1656

Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these metho…

Patch available
Fix from $1,950 2008-04-09
Aix HIGH 7.2
CVE-2008-1710

Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable.

Mitigation only
Fix from $1,950 2008-04-09
Eterm MEDIUM 6.9
CVE-2008-1692

Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users…

Mitigation only
Fix from $1,600 2008-04-07
Select Identity MEDIUM 5.5
CVE-2008-0709

Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other us…

Mitigation only
Fix from $1,600 2008-04-07
Db2 Content Manager HIGH 10.0
CVE-2008-1681

Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privileg…

Fix: after 8.3
Fix from $1,950 2008-04-04
Openssh MEDIUM 6.5
CVE-2008-1657

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc ses…

Patch available
Fix from $1,600 2008-04-02
Avast Antivirus Home MEDIUM 6.8
CVE-2008-1625

aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain p…

Mitigation only
Fix from $1,600 2008-04-02
Nik Sharpener Pro MEDIUM 6.8
CVE-2008-1638

Nik Sharpener Pro, possibly 2.0, uses world-writable permissions for plug-in files, which allows local users to gain privileges by replacing a plug-i…

Mitigation only
Fix from $1,600 2008-04-02
Otrs MEDIUM 6.4
CVE-2008-1515

The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related …

Fix: 2.1.8 / 2.2.6+
Fix from $1,600 2008-04-01
Aix HIGH 7.2
CVE-2008-1593

The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to re…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1596

Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to…

Patch available
Fix from $1,950 2008-03-31
Aix HIGH 7.2
CVE-2008-1599

The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoki…

Patch available
Fix from $1,950 2008-03-31