Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Aix HIGH 7.2
CVE-2008-0588

Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors.

Patch available
Fix from $1,950 2008-02-05
Comment Upload Module MEDIUM 6.4
CVE-2008-0569

The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows…

Mitigation only
Fix from $1,600 2008-02-05
Ipsecdrv.sys HIGH 7.2
CVE-2008-0573

IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL reques…

No fix yet
Fix from $1,950 2008-02-05
Project Issue Tracking Module MEDIUM 6.4
CVE-2008-0577

The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier…

Mitigation only
Fix from $1,600 2008-02-05
Frimousse MEDIUM 5.0
CVE-2008-0425

Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary direct…

No fix yet
Fix from $1,600 2008-01-23
Websphere Business Modeler MEDIUM 6.0
CVE-2008-0402

Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to byp…

Patch available
Fix from $1,600 2008-01-23
R3000 Internet Filter MEDIUM 5.0
CVE-2008-0372

8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP …

Fix: after 2.0.10
Fix from $1,600 2008-01-22
C5510 Mfp Printer HIGH 10.0
CVE-2008-0375

Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the passwo…

Mitigation only
Fix from $1,950 2008-01-22
Evilsentinel HIGH 7.5
CVE-2008-0350

admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain admini…

Fix: after 1.0.9
Fix from $1,950 2008-01-18
Lulieblog MEDIUM 5.0
CVE-2008-0329

LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which a…

No fix yet
Fix from $1,600 2008-01-17
Gallery Publish Xp Module HIGH 10.0
CVE-2007-6685

Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vector…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Gallery HIGH 10.0
CVE-2007-6690

The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack…

Fix: after 2.2.3
Fix from $1,950 2008-01-17
Freeseat MEDIUM 6.8
CVE-2008-0293

Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authent…

Fix: after 1.1.5c
Fix from $1,600 2008-01-16
FreeBSD MEDIUM 6.9
CVE-2008-0217

The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable perm…

Patch available
Fix from $1,600 2008-01-16
Atom Module MEDIUM 5.0
CVE-2008-0275

The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3)…

Fix: after 5.0
Fix from $1,600 2008-01-15
Uploadimage HIGH 7.5
CVE-2008-0245

admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain…

No fix yet
Fix from $1,950 2008-01-12
Uploadimage HIGH 10.0
CVE-2008-0246

admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gai…

No fix yet
Fix from $1,950 2008-01-12
Framework MEDIUM 5.8
CVE-2007-6018

IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w…

Patch available
Fix from $1,600 2008-01-11
Zero Cms HIGH 7.5
CVE-2008-0233

Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload an…

No fix yet
Fix from $1,950 2008-01-11
Helpbox MEDIUM 6.5
CVE-2007-5401

Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary…

Mitigation only
Fix from $1,600 2008-01-09
PostgreSQL MEDIUM 6.5
CVE-2007-6600

PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of tabl…

Patch available
Fix from $1,600 2008-01-09
Zenworks Endpoint Security Management HIGH 7.2
CVE-2007-5665

STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts …

Fix: after 3.5
Fix from $1,950 2008-01-09
Netoctopus HIGH 7.2
CVE-2007-5761

The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which a…

Patch available
Fix from $1,950 2008-01-09
Tutos HIGH 10.0
CVE-2008-0148EPSS 6%

TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a…

No fix yet
Fix from $1,950 2008-01-09
Windows 2000 HIGH 7.2
CVE-2007-5352

Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 al…

Patch available
Fix from $1,950 2008-01-08
Xoops MEDIUM 5.0
CVE-2007-6675

The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows…

Fix: after 2.0.17_1
Fix from $1,600 2008-01-08
Snitz Forums 2000 MEDIUM 5.0
CVE-2008-0135

Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers …

Fix: after 3.4.06
Fix from $1,600 2008-01-08
Myspace Content Zone HIGH 7.5
CVE-2007-6668EPSS 6%

admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestri…

Fix: after 3.60
Fix from $1,950 2008-01-08
R2 Cms HIGH 7.5
CVE-2007-6650

Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image…

No fix yet
Fix from $1,950 2008-01-04
Dovecot MEDIUM 6.8
CVE-2007-6598

Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might al…

Fix: after 1.0.9
Fix from $1,600 2008-01-04