Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Sing HIGH 7.2
CVE-2007-6211

Send ICMP Nasty Garbage (sing) on Debian GNU/Linux allows local users to append to arbitrary files and gain privileges via the -L (output log file) o…

No fix yet
Fix from $1,950 2007-12-04
Rsync HIGH 10.0
CVE-2007-6200EPSS 5%

Unspecified vulnerability in rsync before 3.0.0pre6, when running a writable rsync daemon, allows remote attackers to bypass exclude, exclude_from, a…

Patch available
Fix from $1,950 2007-12-01
Phpdevshell HIGH 8.5
CVE-2007-6174

PHPDevShell before 0.7.0 allows remote authenticated users to gain privileges via a crafted request to update a user profile. NOTE: some of these de…

Fix: after 0.6.0
Fix from $1,950 2007-11-30
Ispmanager HIGH 7.2
CVE-2007-6182

The responder program in ISPsystem ISPmanager (aka ISPmgr) 4.2.15.1 allows local users to gain privileges via shell metacharacters in command line ar…

Fix: after 4.0
Fix from $1,950 2007-11-30
Mac Os X HIGH 9.3
CVE-2007-6165EPSS 45%

Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an a…

No fix yet
Fix from $1,950 2007-11-29
Suse Linux HIGH 7.2
CVE-2007-6167

Untrusted search path vulnerability in yast2-core in SUSE Linux might allow local users to execute arbitrary code by creating a malicious yast2 modul…

Mitigation only
Fix from $1,950 2007-11-29
Eventlog Analyzer HIGH 7.5
CVE-2007-6081

AdventNet EventLog Analyzer build 4030 for Windows, and possibly other versions and platforms, installs a mysql instance with a default "root" accoun…

Mitigation only
Fix from $1,950 2007-11-21
Db2 Universal Database HIGH 10.0
CVE-2007-6047

Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance o…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6048

IBM DB2 UDB 9.1 before Fixpak 4 uses incorrect permissions on ACLs for DB2NODES.CFG, which has unknown impact and attack vectors. NOTE: the vendor d…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 7.2
CVE-2007-6049

Unspecified vulnerability in the SSL LOAD GSKIT action in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, involving a call to …

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 7.2
CVE-2007-6050

Unspecified vulnerability in DB2LICD in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors, related to creation of an "insecure di…

Fix: after 9.1
Fix from $1,950 2007-11-20
Db2 Universal Database HIGH 10.0
CVE-2007-6051

IBM DB2 UDB 9.1 before Fixpak 4 assigns incorrect privileges to the (1) DB2ADMNS and (2) DB2USERS alternative groups, which has unknown impact. NOTE…

Fix: after 9.1
Fix from $1,950 2007-11-20
Aida Web MEDIUM 5.0
CVE-2007-6056

frame.html in Aida-Web (Aida Web) allows remote attackers to bypass a protection mechanism and obtain comment and task details via modified values to…

No fix yet
Fix from $1,600 2007-11-20
Safari HIGH 7.5
CVE-2007-4699

The default configuration of Safari in Apple Mac OS X 10.4 through 10.4.10 adds a private key to the keychain with permissions that allow other appli…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.5
CVE-2007-4700

Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attack…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 7.2
CVE-2007-4685

The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, st…

Patch available
Fix from $1,950 2007-11-15
Mac Os X HIGH 10.0
CVE-2007-4691

The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions f…

Patch available
Fix from $1,950 2007-11-15
Bti Tracker MEDIUM 6.8
CVE-2007-5987

details.php in BtiTracker before 1.4.5, when torrent viewing is disabled for guests, allows remote attackers to bypass protection mechanisms via a di…

Fix: after 1.4.4
Fix from $1,600 2007-11-15
Bti Tracker HIGH 7.5
CVE-2007-5988

blocks/shoutbox_block.php in BtiTracker 1.4.4 does not verify user accounts, which allows remote attackers to post shoutbox entries as arbitrary user…

Fix: after 1.4.4
Fix from $1,950 2007-11-15
User Friendly Svn MEDIUM 5.0
CVE-2007-5945

USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors.

Fix: after 0.6.4
Fix from $1,600 2007-11-14
Orangehrm MEDIUM 5.0
CVE-2007-5931

The reDirect function in lib/controllers/RepViewController.php in OrangeHRM before 2.2.2 does not verify the privileges of a user, which allows remot…

Fix: after 2.2.1
Fix from $1,600 2007-11-10
Mywebftp MEDIUM 5.0
CVE-2007-5919

MyWebFTP, possibly 5.3.2, stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain a…

Mitigation only
Fix from $1,600 2007-11-10
Norton Antivirus MEDIUM 6.0
CVE-2007-5829

The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security f…

Mitigation only
Fix from $1,600 2007-11-05
Bosnews MEDIUM 5.0
CVE-2007-5835

Install.php in BosDev BosNews 4 and 5 does not require authentication for replacing an existing product installation or creating a new admin account,…

Mitigation only
Fix from $1,600 2007-11-05
Flatnuke3 HIGH 7.5
CVE-2007-5771EPSS 6%

Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.

No fix yet
Fix from $1,950 2007-11-01
I Gallery MEDIUM 5.0
CVE-2007-5777

Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers…

Mitigation only
Fix from $1,600 2007-11-01
Micro Login System MEDIUM 5.0
CVE-2007-5787

Micro Login System 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a …

Mitigation only
Fix from $1,600 2007-11-01
Efileman MEDIUM 5.0
CVE-2007-5735

eFileMan 7.1.0.87-88 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain unspec…

Mitigation only
Fix from $1,600 2007-10-30
Pc Cillin Internet Security 2007 MEDIUM 6.6
CVE-2007-4277

The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.50…

Fix: after 8.500
Fix from $1,600 2007-10-30
Tikiwiki Cms\/groupware HIGH 7.5
CVE-2007-5682

Incomplete blacklist vulnerability in tiki-graph_formula.php in TikiWiki before 1.9.8.2 allows remote attackers to execute arbitrary code by using va…

Fix: after 1.9.8
Fix from $1,950 2007-10-26