Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Creammonkey MEDIUM 6.4
CVE-2007-6640

Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to r…

Mitigation only
Fix from $1,600 2008-01-04
Joomla MEDIUM 6.5
CVE-2007-6644

Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended…

Mitigation only
Fix from $1,600 2008-01-04
Joomla HIGH 7.5
CVE-2007-6645

Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered use…

Mitigation only
Fix from $1,950 2008-01-04
Bitflu MEDIUM 5.8
CVE-2007-6636

Unspecified vulnerability in the StorageFarabDb module in Bitflu before 0.42 allows user-assisted remote attackers to create or append data to arbitr…

Fix: after 0.41
Fix from $1,600 2008-01-04
3204 Dvr HIGH 10.0
CVE-2007-6638EPSS 13%

March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain use…

No fix yet
Fix from $1,950 2008-01-04
Jira HIGH 7.5
CVE-2007-6619

The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows r…

Fix: after 3.12
Fix from $1,950 2008-01-03
Hot Or Not Clone MEDIUM 5.0
CVE-2007-6603

Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrato…

No fix yet
Fix from $1,600 2007-12-31
Lotus Notes MEDIUM 6.9
CVE-2007-6594

IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0…

Fix: after 8.0.1
Fix from $1,600 2007-12-28
Tomcat MEDIUM 6.4
CVE-2007-5342EPSS 5%

The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe…

Patch available
Fix from $1,600 2007-12-27
Mysql Banner Exchange MEDIUM 5.0
CVE-2007-6512

PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob…

Mitigation only
Fix from $1,600 2007-12-21
Ingres MEDIUM 5.0
CVE-2007-6334

Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the sa…

Patch available
Fix from $1,600 2007-12-20
Serverprotect HIGH 10.0
CVE-2007-6507EPSS 37%

SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.…

Mitigation only
Fix from $1,950 2007-12-20
Hosting Controller MEDIUM 6.5
CVE-2007-6495

inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1…

No fix yet
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 6.8
CVE-2007-6496

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the l…

No fix yet
Fix from $1,600 2007-12-20
Hosting Controller HIGH 7.5
CVE-2007-6497

Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp…

Fix: after 6.1_hotfix_3.3
Fix from $1,950 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6499

Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions o…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6501

Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a r…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6503

Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pl…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6504

Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Phprpg MEDIUM 6.4
CVE-2007-6470

phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values …

No fix yet
Fix from $1,600 2007-12-20
Mac Os X HIGH 9.4
CVE-2007-5856

Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote atta…

Mitigation only
Fix from $1,950 2007-12-19
Mac Os X MEDIUM 6.4
CVE-2007-5857

Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which mig…

Mitigation only
Fix from $1,600 2007-12-19
Solaris HIGH 9.3
CVE-2007-6413

Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup …

Patch available
Fix from $1,950 2007-12-17
Board MEDIUM 5.0
CVE-2007-6395EPSS 6%

Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt…

Fix: after 1.2
Fix from $1,600 2007-12-17
Chandler Server MEDIUM 5.5
CVE-2007-6383

The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to c…

Fix: after 0.10
Fix from $1,600 2007-12-15
Gekko MEDIUM 5.0
CVE-2007-6361

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers…

Fix: after 0.8.2
Fix from $1,600 2007-12-15
Scponly HIGH 8.5
CVE-2007-6350

scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands includin…

Fix: after 4.6
Fix from $1,950 2007-12-14
Mysql Server HIGH 7.1
CVE-2007-5969EPSS 14%

MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a …

Fix: after 5.0.50
Fix from $1,950 2007-12-10
Libflac HIGH 9.3
CVE-2007-6278

Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIM…

Fix: after 1.2
Fix from $1,950 2007-12-07
Interleave MEDIUM 6.5
CVE-2007-6222

The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, whi…

Fix: after 4.2.0
Fix from $1,600 2007-12-04