Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aix HIGH 7.2
CVE-2008-1600

The lsmcode program on IBM AIX 5.2, 5.3, and 6.1 does not properly handle environment variables, which allows local users to gain privileges, a diffe…

Patch available
Fix from $1,950 2008-03-31
Open Vms Tcp Ip Services HIGH 10.0
CVE-2008-0704

Unspecified vulnerability in the SSH server in HP OpenVMS TCP/IP Services on OpenVMS on the Alpha platform with 5.4 before ECO 7, and on the Integrit…

Fix: after 5.6
Fix from $1,950 2008-03-28
Prestige 660 MEDIUM 6.5
CVE-2008-1521

ZyXEL Prestige routers, including P-660 and P-661 models with firmware 3.40(AGD.2) through 3.40(AHQ.3), allow remote authenticated users to gain priv…

Mitigation only
Fix from $1,600 2008-03-26
Freewebshop HIGH 10.0
CVE-2007-6711

Unspecified vulnerability in customer.php in FreeWebshop.org 2.2.5, 2.2.6 and 2.2.7WIP1/2 allows remote attackers to gain administrator privileges vi…

Patch available
Fix from $1,950 2008-03-24
Openssh MEDIUM 6.9
CVE-2008-1483

OpenSSH 4.3p2, and probably other versions, allows local users to hijack forwarded X connections by causing ssh to set DISPLAY to :10, even when anot…

Mitigation only
Fix from $1,600 2008-03-24
Altiris Deployment Solution HIGH 7.2
CVE-2008-1473

The Altiris Client Service (AClient.exe) in Symantec Altiris Deployment Solution 6.8.x before 6.9.164 allows local users to gain privileges via a "Sh…

Patch available
Fix from $1,950 2008-03-24
Roundup MEDIUM 6.4
CVE-2008-1475

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted pr…

Fix: after 1.4.3
Fix from $1,600 2008-03-24
Storageworks Library And Tape Tools HIGH 7.2
CVE-2008-0707

HP StorageWorks Library and Tape Tools (LTT) before 4.5 SR1 on HP-UX B.11.11 and B.11.23 allows local users to gain privileges via unspecified vector…

Fix: after 4.5_sr1
Fix from $1,950 2008-03-20
Asterisk HIGH 8.8
CVE-2008-1332

Unspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…

Fix: after 1.4.19
Fix from $1,950 2008-03-20
Ace MEDIUM 6.8
CVE-2008-1361

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 …

Patch available
Fix from $1,600 2008-03-20
Ace HIGH 7.2
CVE-2008-1362

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 …

Patch available
Fix from $1,950 2008-03-20
Ace HIGH 7.2
CVE-2008-1363

VMware Workstation 6.0.x before 6.0.3 and 5.5.x before 5.5.6, VMware Player 2.0.x before 2.0.3 and 1.0.x before 1.0.6, VMware ACE 2.0.x before 2.0.1 …

Fix: 1.0.5 / 1.0.6+
Fix from $1,950 2008-03-20
Check Point Vpn 1 Pro MEDIUM 6.5
CVE-2008-1397

Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to…

Patch available
Fix from $1,600 2008-03-20
Mac Os X MEDIUM 6.9
CVE-2008-0998

Unspecified vulnerability in NetCfgTool in the System Configuration component in Apple Mac OS X 10.4.11 and 10.5.2 allows local users to bypass autho…

Patch available
Fix from $1,600 2008-03-18
Mac Os X HIGH 7.1
CVE-2008-0045

Unspecified vulnerability in AFP Server in Apple Mac OS X 10.4.11 allows remote attackers to bypass cross-realm authentication via unknown manipulati…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 5.0
CVE-2008-0046

The Application Firewall in Apple Mac OS X 10.5.2 has an incorrect German translation for the "Set access for specific services and applications" rad…

Patch available
Fix from $1,600 2008-03-18
Sunos HIGH 10.0
CVE-2008-1369

A certain incorrect Sun Solaris 10 image on SPARC Enterprise T5120 and T5220 servers has /etc/default/login and /etc/ssh/sshd_config files that confi…

Mitigation only
Fix from $1,950 2008-03-18
Wag54gs HIGH 7.5
CVE-2007-6709

The Cisco Linksys WAG54GS Wireless-G ADSL Gateway with 1.01.03 and earlier firmware has "admin" as its default password for the "admin" account, whic…

No fix yet
Fix from $1,950 2008-03-13
Jspwiki HIGH 9.3
CVE-2008-1230

Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbitrary .jsp files via an unspe…

No fix yet
Fix from $1,950 2008-03-10
F5d7230 4 HIGH 10.0
CVE-2008-1242

The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to…

Mitigation only
Fix from $1,950 2008-03-10
Pix Asa Finesse Operation System HIGH 7.8
CVE-2008-1246

The Cisco PIX/ASA Finesse Operation System 7.1 and 7.2 allows local users to gain privileges by entering characters at the enable prompt, erasing the…

Mitigation only
Fix from $1,950 2008-03-10
Wrt54g HIGH 10.0
CVE-2008-1247EPSS 5%

The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts, which allows remote attackers…

No fix yet
Fix from $1,950 2008-03-10
P 660hw HIGH 10.0
CVE-2008-1255

The ZyXEL P-660HW series router maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing …

Mitigation only
Fix from $1,950 2008-03-10
Jdk HIGH 9.3
CVE-2008-1185EPSS 6%

Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, an…

Patch available
Fix from $1,950 2008-03-06
Jdk HIGH 9.3
CVE-2008-1186EPSS 6%

Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and e…

Patch available
Fix from $1,950 2008-03-06
Jdk MEDIUM 6.8
CVE-2008-1187EPSS 5%

Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and e…

Fix: after 6
Fix from $1,600 2008-03-06
Jdk HIGH 9.3
CVE-2008-1190EPSS 17%

Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier al…

Mitigation only
Fix from $1,950 2008-03-06
Moinmoin MEDIUM 5.0
CVE-2008-1099

_macro_Getval in wikimacro.py in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages.

Fix: after 1.5.8
Fix from $1,600 2008-03-05
Deslock HIGH 7.2
CVE-2008-1139

DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain privileges via a certain DLMF…

Fix: after 3.2.6
Fix from $1,950 2008-03-04
Deslock HIGH 7.2
CVE-2008-1140

DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL request to \\.\DLKFDisk_Contro…

Fix: after 3.2.6
Fix from $1,950 2008-03-04