Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Xwine MEDIUM 6.3
CVE-2008-0931

w_export.c in XWine 1.0.1 on Debian GNU/Linux sets insecure permissions (0666) for /etc/wine/config, which might allow local users to execute arbitra…

Mitigation only
Fix from $1,600 2008-03-04
Solaris MEDIUM 6.8
CVE-2008-1095

Unspecified vulnerability in the Internet Protocol (IP) implementation in Sun Solaris 8, 9, and 10 allows remote attackers to bypass intended firewal…

Patch available
Fix from $1,600 2008-02-29
F Secure Anti Virus HIGH 7.5
CVE-2008-0910

Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and …

Fix: after 7.00
Fix from $1,950 2008-02-22
Splitvt HIGH 7.2
CVE-2008-0162

misc.c in splitvt 1.6.6 and earlier does not drop group privileges before executing xprop, which allows local users to gain privileges.

Fix: after 1.6.6
Fix from $1,950 2008-02-22
Weblogic Server HIGH 7.9
CVE-2008-0897

Unspecified vulnerability in BEA WebLogic Server 9.0 through 10.0 allows remote authenticated users without "receive" permissions to bypass intended …

Patch available
Fix from $1,950 2008-02-22
Weblogic Server MEDIUM 5.8
CVE-2008-0898

The distributed queue feature in JMS in BEA WebLogic Server 9.0 through 10.0, in certain configurations, does not properly handle when a client canno…

Patch available
Fix from $1,600 2008-02-22
Weblogic Server MEDIUM 6.0
CVE-2008-0900EPSS 10%

Session fixation vulnerability in BEA WebLogic Server and Express 8.1 SP4 through SP6, 9.2 through MP1, and 10.0 allows remote authenticated users to…

Patch available
Fix from $1,600 2008-02-22
Weblogic Portal MEDIUM 5.0
CVE-2008-0864

Admin Tools in BEA WebLogic Portal 8.1 SP3 through SP6 can inadvertently remove entitlements for pages when an administrator edits the page definitio…

Mitigation only
Fix from $1,600 2008-02-21
Weblogic Portal MEDIUM 5.0
CVE-2008-0865

Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP port…

No fix yet
Fix from $1,600 2008-02-21
Statcountex MEDIUM 6.4
CVE-2008-0843

StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a direct request to admin.asp.

No fix yet
Fix from $1,600 2008-02-20
List Manager HIGH 10.0
CVE-2007-6319

Multiple unspecified vulnerabilities in Lyris ListManager 8.x before 8.95d, 9.2 before 9.2c, and 9.3 before 9.3b allow remote attackers to (1) gain l…

Patch available
Fix from $1,950 2008-02-19
Openca Pki HIGH 7.5
CVE-2008-0556

Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized…

Fix: after 0.9.2.5
Fix from $1,950 2008-02-19
Medias Phpizabi HIGH 9.3
CVE-2008-0805EPSS 5%

Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitrary code by uploading a file …

No fix yet
Fix from $1,950 2008-02-19
Mysql Community Server MEDIUM 6.5
CVE-2007-6313

MySQL Server 5.1.x before 5.1.23 and 6.0.x before 6.0.4 does not check the rights of the entity executing BINLOG, which allows remote authorized user…

Mitigation only
Fix from $1,600 2008-02-18
F Secure Anti Virus MEDIUM 5.8
CVE-2008-0792

Multiple F-Secure anti-virus products, including Internet Security 2006 through 2008, Anti-Virus 2006 through 2008, F-Secure Protection Service, and …

Fix: after 7.00
Fix from $1,600 2008-02-15
Forticlient Host Security HIGH 7.2
CVE-2008-0779

The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, wh…

Fix: after 3.0
Fix from $1,950 2008-02-14
Websphere Application Server HIGH 10.0
CVE-2008-0741

Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has un…

Fix: after 6.0.2.24
Fix from $1,950 2008-02-13
Db2 Universal Database MEDIUM 6.9
CVE-2007-5757

Untrusted search path vulnerability in db2pd in IBM DB2 Universal Database (UDB) 8 before FixPak 16 and 9 before Fix Pack 4 allows local users to gai…

Fix: after 8.0
Fix from $1,600 2008-02-13
Internet Information Server HIGH 7.2
CVE-2008-0074EPSS 5%

Unspecified vulnerability in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows local users to gain privileges via unknown vectors …

Mitigation only
Fix from $1,950 2008-02-12
Apparmor HIGH 7.5
CVE-2008-0731

The Linux kernel before 2.6.18.8-0.8 in SUSE openSUSE 10.2 does not properly handle failure of an AppArmor change_hat system call, which might allow …

Mitigation only
Fix from $1,950 2008-02-12
Storage Essentials Srm Enterprise HIGH 10.0
CVE-2008-0215

Multiple unspecified vulnerabilities in HP Storage Essentials Storage Resource Management (SRM) before 6.0.0 allow remote attackers to obtain unspeci…

Fix: after 5.1.3
Fix from $1,950 2008-02-12
Db2 HIGH 7.5
CVE-2008-0696

IBM DB2 UDB before 8.2 Fixpak 16 does not properly check authorization for the ALTER TABLE statement, which has unknown impact and attack vectors.

Mitigation only
Fix from $1,950 2008-02-12
Db2 HIGH 7.2
CVE-2008-0697

Unspecified vulnerability in DB2PD in IBM DB2 UDB before 8.2 Fixpak 16 allows local users to gain root privileges via unspecified vectors.

Mitigation only
Fix from $1,950 2008-02-12
Ce MEDIUM 5.0
CVE-2008-0701

ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown imp…

Mitigation only
Fix from $1,600 2008-02-12
Select Identity HIGH 7.5
CVE-2008-0214

Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to gain access via…

No fix yet
Fix from $1,950 2008-02-08
WordPress MEDIUM 6.4
CVE-2008-0664

The XML-RPC implementation (xmlrpc.php) in WordPress before 2.3.3, when registration is enabled, allows remote attackers to edit posts of other blog …

Patch available
Fix from $1,600 2008-02-08
Lightblog HIGH 9.3
CVE-2008-0632EPSS 6%

Unrestricted file upload vulnerability in cp_upload_image.php in LightBlog 9.5 allows remote attackers to execute arbitrary code by uploading a file …

No fix yet
Fix from $1,950 2008-02-06
Lsrunase HIGH 7.2
CVE-2008-0581

Geert Moernaut LSrunasE allows local users to gain privileges by obtaining the encrypted password from a batch file, and constructing a modified batc…

Mitigation only
Fix from $1,950 2008-02-05
Aix HIGH 7.2
CVE-2008-0584

Multiple buffer overflows in bos.rte.control in IBM AIX 5.2 and 5.3 allow local users to gain privileges via unspecified vectors related to the (1) s…

Mitigation only
Fix from $1,950 2008-02-05
Aix MEDIUM 6.6
CVE-2008-0585

sysmgt.websm.webaccess in IBM AIX 5.2 and 5.3 has world writable permissions for unspecified WebSM Remote Client files, which allows local users to "…

Mitigation only
Fix from $1,600 2008-02-05