Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Tor MEDIUM 5.8
CVE-2007-4174EPSS 6%

Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify…

Fix: after 0.1.2.15
Fix from $1,600 2007-08-07
Video Driver HIGH 7.2
CVE-2007-3532

NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvid…

Fix: after 100.14.11
Fix from $1,950 2007-07-27
Dirlist Php MEDIUM 5.3
CVE-2007-3968

index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name.

Fix: after 0.1.1
Fix from $1,600 2007-07-25
Clavister Coreplus MEDIUM 5.0
CVE-2007-3804

The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files.

Fix: after 8.81.00
Fix from $1,600 2007-07-16
Xeforum HIGH 10.0
CVE-2007-3500

Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie.

No fix yet
Fix from $1,950 2007-06-29
Officescan HIGH 10.0
CVE-2007-3455

cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and g…

Patch available
Fix from $1,950 2007-06-27
Firefox MEDIUM 6.8
CVE-2007-3285

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:…

Fix: after 2.0.0.4
Fix from $1,600 2007-06-20
PostgreSQL MEDIUM 6.9
CVE-2007-3278

PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows re…

Fix: 7.3.21 / 7.4.19+
Fix from $1,600 2007-06-19
Webapp HIGH 7.5
CVE-2007-3242

The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote a…

Mitigation only
Fix from $1,950 2007-06-15
Safari HIGH 9.3
CVE-2007-3186

Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, …

Mitigation only
Fix from $1,950 2007-06-12
Veritas Storage Foundation HIGH 9.3
CVE-2007-2279EPSS 6%

The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execut…

Patch available
Fix from $1,950 2007-06-04
Pheap HIGH 10.0
CVE-2007-2985

Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used t…

No fix yet
Fix from $1,950 2007-06-01
Openfire HIGH 7.5
CVE-2007-2975

The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allo…

Fix: after 3.3.0
Fix from $1,950 2007-06-01
Wabcms MEDIUM 5.0
CVE-2007-2944

WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via…

Mitigation only
Fix from $1,600 2007-05-31
Internet Information Services HIGH 10.0
CVE-2007-2815EPSS 73%

The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configur…

Mitigation only
Fix from $1,950 2007-05-22
Java Enterprise System HIGH 10.0
CVE-2007-2435

Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perfo…

Fix: after 5.0
Fix from $1,950 2007-05-02
PostgreSQL MEDIUM 6.0
CVE-2007-2138

Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4…

Fix: 7.3.19 / 7.4.17+
Fix from $1,600 2007-04-24
Mac Os X HIGH 7.2
CVE-2007-0729

Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which all…

Patch available
Fix from $1,950 2007-04-24
Windows MEDIUM 6.8
CVE-2007-2108EPSS 22%

Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers …

Mitigation only
Fix from $1,600 2007-04-18
Windows 2000 HIGH 7.2
CVE-2007-1206

The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows V…

Mitigation only
Fix from $1,950 2007-04-10
Access Manager HIGH 9.0
CVE-2007-1309

Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, …

Patch available
Fix from $1,950 2007-03-07
P News MEDIUM 5.0
CVE-2006-7114

P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive informa…

Fix: after 2.0
Fix from $1,600 2007-03-06
Openbiblio HIGH 7.5
CVE-2007-1261

Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors.

Fix: after 0.5.2
Fix from $1,950 2007-03-03
Apache MEDIUM 6.6
CVE-2006-7098

The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http…

Mitigation only
Fix from $1,600 2007-03-03
Virex MEDIUM 6.6
CVE-2007-1227

VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack o…

Fix: after 7.7
Fix from $1,600 2007-03-02
Shoutpro MEDIUM 5.0
CVE-2006-7047

include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate ba…

Mitigation only
Fix from $1,600 2007-02-24
Unified Ip Phone Firmware 7906g HIGH 7.2
CVE-2007-1072

The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows l…

Patch available
Fix from $1,950 2007-02-22
Workstation HIGH 7.2
CVE-2007-1056

VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restri…

Mitigation only
Fix from $1,950 2007-02-21
Malbum HIGH 10.0
CVE-2007-1045

mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privi…

No fix yet
Fix from $1,950 2007-02-21
Jboss Application Server HIGH 7.5
CVE-2007-1036EPSS 82%

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to by…

Mitigation only
Fix from $1,950 2007-02-21