Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Ace MEDIUM 6.9
CVE-2007-5023

Unquoted Windows search path vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 B…

Fix: after 6.0.1
Fix from $1,600 2007-09-21
Dblog Cms MEDIUM 5.0
CVE-2007-5026

dBlog CMS, probably 2.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download …

Mitigation only
Fix from $1,600 2007-09-21
Cs Guestbook MEDIUM 5.0
CVE-2007-4937

CS Guestbook stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the admin name…

No fix yet
Fix from $1,600 2007-09-18
Winscp HIGH 9.3
CVE-2007-4909

Interpretation conflict in WinSCP before 4.0.4 allows remote attackers to perform arbitrary file transfers with a remote server via file-transfer com…

Patch available
Fix from $1,950 2007-09-17
Samba MEDIUM 6.9
CVE-2007-4138

The Winbind nss_info extension (nsswitch/idmap_ad.c) in idmap_ad.so in Samba 3.0.25 through 3.0.25c, when the "winbind nss info" option is set to rfc…

Patch available
Fix from $1,600 2007-09-14
Xwiki MEDIUM 6.5
CVE-2006-7223

PreviewAction in XWiki 0.9.543 through 0.9.1252 does not set the Author field to the identity of the user who last modified a document, which allows …

Mitigation only
Fix from $1,600 2007-09-14
Windows Services For Unix MEDIUM 6.9
CVE-2007-3036

Unspecified vulnerability in the (1) Windows Services for UNIX 3.0 and 3.5, and (2) Subsystem for UNIX-based Applications in Microsoft Windows 2000, …

Mitigation only
Fix from $1,600 2007-09-12
Connect Enterprise Server MEDIUM 5.0
CVE-2007-4651

Unspecified vulnerability in Adobe Connect Enterprise Server 6 allows remote attackers to read certain pages that are restricted to the administrator…

Patch available
Fix from $1,600 2007-09-12
Aix MEDIUM 6.6
CVE-2007-4798

Unspecified vulnerability in invscout in Inventory Scout in invscout.rte in IBM AIX 5.2 and 5.3 allows local users to delete system files that have n…

Patch available
Fix from $1,600 2007-09-10
Debian Goodies HIGH 7.2
CVE-2007-3912

checkrestart in debian-goodies before 0.34 allows local users to gain privileges via shell metacharacters in the name of the executable file for a ru…

Patch available
Fix from $1,950 2007-09-10
Video Surveillance Ip Gateway Encoder Decoder HIGH 9.0
CVE-2007-4746

The Cisco Video Surveillance IP Gateway Encoder/Decoder (Standalone and Module) firmware 1.8.1 and earlier, Video Surveillance SP/ISP Decoder Softwar…

Fix: after 1.23.7
Fix from $1,950 2007-09-06
Dsl 600eu Router HIGH 9.3
CVE-2007-4733

The Aztech DSL600EU router, when WAN access to the web interface is disabled, does not properly block inbound traffic on TCP port 80, which allows re…

Mitigation only
Fix from $1,950 2007-09-06
Reprepro MEDIUM 5.0
CVE-2007-4739

reprepro 1.3.0 through 2.2.3 does not properly verify signatures when updating repositories, which allows remote attackers to construct and distribut…

Patch available
Fix from $1,600 2007-09-06
Alice Messenger HIGH 9.3
CVE-2007-4740

The HPRevolutionRegistryManager ActiveX control in Hp.Revolution.RegistryManager.dll 1 in Telecom Italy Alice Messenger allows remote attackers to cr…

No fix yet
Fix from $1,950 2007-09-06
Quickbooks HIGH 9.3
CVE-2007-4471EPSS 5%

Multiple unspecified vulnerabilities in the Intuit QuickBooks Online Edition ActiveX control before 10 allow remote attackers to create or overwrite …

Patch available
Fix from $1,950 2007-09-05
Firebird MEDIUM 5.0
CVE-2007-4668

Unspecified vulnerability in the server in Firebird before 2.0.2 allows remote attackers to determine the existence of arbitrary files, and possibly …

Fix: after 2.0.1
Fix from $1,600 2007-09-04
Gallery MEDIUM 6.4
CVE-2007-4650

Multiple unspecified vulnerabilities in Gallery before 2.2.3 allow attackers to (1) rename items, (2) read and modify item properties, or (3) lock an…

Fix: after 2.2.2
Fix from $1,600 2007-09-04
Pakupaku Cms MEDIUM 6.4
CVE-2007-4640

Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload and execute arbitrary PHP files…

Fix: after 0.4
Fix from $1,600 2007-08-31
Our Space MEDIUM 5.0
CVE-2007-4647

newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via unspecified vectors, probably in…

No fix yet
Fix from $1,600 2007-08-31
Escan Anti Virus HIGH 7.2
CVE-2007-4649

MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for thei…

No fix yet
Fix from $1,950 2007-08-31
Eyeos MEDIUM 6.4
CVE-2007-4609

eyeOS uses predictable checksum values in the checknum parameter for access control, which allows remote attackers to register many accounts via doCr…

Mitigation only
Fix from $1,600 2007-08-31
Moon Gallery MEDIUM 6.8
CVE-2007-4610

Unrestricted file upload vulnerability in config/upload.php in Moonware (aka Dale Mooney Gallery) allows remote attackers to upload and execute arbit…

Mitigation only
Fix from $1,600 2007-08-31
Weblogic Server HIGH 7.5
CVE-2007-4614

BEA WebLogic Server 9.1 does not properly handle propagation of an admin server's security policy change log to temporarily unavailable managed serve…

Patch available
Fix from $1,950 2007-08-31
Ubuntu Linux MEDIUM 5.0
CVE-2007-4601

A regression error in tcp-wrappers 7.6.dbs-10 and 7.6.dbs-11 might allow remote attackers to bypass intended access restrictions when a service uses …

Patch available
Fix from $1,600 2007-08-30
Bugzilla MEDIUM 5.0
CVE-2007-4539

The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows r…

Patch available
Fix from $1,600 2007-08-27
Project MEDIUM 5.0
CVE-2007-4436

The Drupal Project module before 5.x-1.0, 4.7.x-2.3, and 4.7.x-1.3 and Project issue tracking module before 5.x-1.0, 4.7.x-2.4, and 4.7.x-1.4 do not …

Fix: after 5.0
Fix from $1,600 2007-08-20
Plug In For Winamp MEDIUM 6.8
CVE-2007-4403

The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the nam…

Mitigation only
Fix from $1,600 2007-08-18
Adonis HIGH 7.2
CVE-2007-4390

The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5.0.2.8 allows local admin use…

Mitigation only
Fix from $1,950 2007-08-17
Family Connections Cms HIGH 10.0
CVE-2007-4338EPSS 9%

index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary account by placing the account's n…

Fix: after 0.8
Fix from $1,950 2007-08-14
Catalyst Driver MEDIUM 6.9
CVE-2007-4315

The AMD ATI atidsmxx.sys 3.0.502.0 driver on Windows Vista allows local users to bypass the driver signing policy, write to arbitrary kernel memory l…

Mitigation only
Fix from $1,600 2007-08-13