Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Vanilla HIGH 7.5
CVE-2007-5644

Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote a…

Fix: after 1.1.3
Fix from $1,950 2007-10-23
Firefox HIGH 9.3
CVE-2007-5338

Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Sc…

Fix: after 2.0.0.7
Fix from $1,950 2007-10-21
Safedisc MEDIUM 6.9
CVE-2007-5587

Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2…

No fix yet
Fix from $1,600 2007-10-19
Firewall Services Module MEDIUM 6.8
CVE-2007-5571

Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to by…

Fix: after 3.2
Fix from $1,600 2007-10-18
Dotproject MEDIUM 6.4
CVE-2007-5486

dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via …

Fix: after 2.0.4
Fix from $1,600 2007-10-16
Call Manager MEDIUM 5.0
CVE-2007-5468

Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote atta…

Mitigation only
Fix from $1,600 2007-10-16
Openser MEDIUM 5.0
CVE-2007-5469

OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use snif…

Mitigation only
Fix from $1,600 2007-10-16
Cms Made Simple MEDIUM 6.5
CVE-2007-5441

CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some …

Mitigation only
Fix from $1,600 2007-10-14
Etrust Integrated Threat Management MEDIUM 5.0
CVE-2007-5439

CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows…

Mitigation only
Fix from $1,600 2007-10-13
Brightstor Arcserve Backup HIGH 10.0
CVE-2007-5328EPSS 7%

The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra…

Patch available
Fix from $1,950 2007-10-13
Wireless Lan Solution Engine HIGH 10.0
CVE-2007-5382

The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) crea…

Fix: after 4.1.91.0
Fix from $1,950 2007-10-12
Vba32 Antivirus HIGH 7.2
CVE-2007-5254

VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privilege…

Patch available
Fix from $1,950 2007-10-06
Asp Cms MEDIUM 5.0
CVE-2007-5260

ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database co…

Mitigation only
Fix from $1,600 2007-10-06
Jdk MEDIUM 5.4
CVE-2007-5236

Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restri…

Patch available
Fix from $1,600 2007-10-06
Zomplog HIGH 7.5
CVE-2007-5230

admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administr…

Patch available
Fix from $1,950 2007-10-05
Affiliate Network Pro MEDIUM 6.8
CVE-2007-5223

Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified imp…

Mitigation only
Fix from $1,600 2007-10-05
Peakflow Sp MEDIUM 6.0
CVE-2007-5210

Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x before 3.6.1 patch 5, allows remote authenticated users to bypass access restrictions and…

Patch available
Fix from $1,600 2007-10-04
Rmake MEDIUM 6.9
CVE-2007-5194

The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as …

Mitigation only
Fix from $1,600 2007-10-04
Embedded Lights Out Manager MEDIUM 5.0
CVE-2007-5170

Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) all…

Patch available
Fix from $1,600 2007-10-01
Quicksilver Forums MEDIUM 5.0
CVE-2007-5171

Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors.

Fix: after 1.4.0
Fix from $1,600 2007-10-01
Simplenews MEDIUM 5.0
CVE-2007-4873

SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrar…

Mitigation only
Fix from $1,600 2007-09-27
Catalyst 6500 MEDIUM 5.0
CVE-2007-5134

Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might …

Patch available
Fix from $1,600 2007-09-27
Chironfs HIGH 7.2
CVE-2007-5101

ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local us…

Fix: after 1.0_rc6
Fix from $1,950 2007-09-26
Rational Clearquest HIGH 7.5
CVE-2007-5090

Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt da…

No fix yet
Fix from $1,950 2007-09-26
Linux Kernel HIGH 7.2
CVE-2007-4573

The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero …

Fix: after 2.6.22.6
Fix from $1,950 2007-09-24
Flip HIGH 7.5
CVE-2007-5062

account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register acti…

Fix: after 3.0
Fix from $1,950 2007-09-24
Bugzilla HIGH 7.5
CVE-2007-5038

The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the c…

Patch available
Fix from $1,950 2007-09-24
Zonealarm MEDIUM 6.9
CVE-2007-5044

ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows loc…

Mitigation only
Fix from $1,600 2007-09-24
Ace MEDIUM 5.5
CVE-2007-4497

Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Pl…

Fix: after 6.0.1
Fix from $1,600 2007-09-21
Kde MEDIUM 6.8
CVE-2007-4569

backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to…

Patch available
Fix from $1,600 2007-09-21