Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Firefox HIGH 7.5
CVE-2007-0981EPSS 12%

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the sa…

Fix: after 1.5.0.9
Fix from $1,950 2007-02-16
Omniaccess Wireless HIGH 7.5
CVE-2007-0932

The (1) Aruba Mobility Controllers 200, 600, 2400, and 6000 and (2) Alcatel-Lucent OmniAccess Wireless 43xx and 6000 do not properly implement authen…

Mitigation only
Fix from $1,950 2007-02-14
Opera Browser MEDIUM 5.0
CVE-2006-6970

Opera 9.10 Final allows remote attackers to bypass the Fraud Protection mechanism by adding certain characters to the end of a domain name, as demons…

No fix yet
Fix from $1,600 2007-02-07
WordPress MEDIUM 5.0
CVE-2007-0541

WordPress allows remote attackers to determine the existence of arbitrary files, and possibly read portions of certain files, via pingback service ca…

Fix: after 2.0
Fix from $1,600 2007-01-29
Connectra Ngx HIGH 7.5
CVE-2007-0471

sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and po…

No fix yet
Fix from $1,950 2007-01-24
Chetcpasswd HIGH 7.8
CVE-2006-6683

Pedro Lineu Orso chetcpasswd 2.4.1 and earlier verifies and updates user accounts via custom code that processes /etc/shadow and does not follow the …

Fix: after 2.4.1
Fix from $1,950 2006-12-21
Firefox MEDIUM 6.8
CVE-2006-6501

Unspecified vulnerability in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows …

Fix: 1.0.7 / 1.5.0.9+
Fix from $1,600 2006-12-20
Windows 2003 Server HIGH 7.2
CVE-2006-5585

The Client-Server Run-time Subsystem in Microsoft Windows XP SP2 and Server 2003 allows local users to gain privileges via a crafted file manifest wi…

Patch available
Fix from $1,950 2006-12-13
Stanford Conference And Research Forum MEDIUM 5.0
CVE-2006-5909

generaloptions.php in Paul Tarjan Stanford Conference And Research Forum (SCARF) before 20070227 does not require the admin privilege, which allows r…

Mitigation only
Fix from $1,600 2006-11-15
Linux Kernel HIGH 7.5
CVE-2006-4572

ip6_tables in netfilter in the Linux kernel before 2.6.16.31 allows remote attackers to (1) bypass a rule that disallows a protocol, via a packet wit…

Fix: after 2.6.16.30
Fix from $1,950 2006-11-07
Joomla HIGH 7.5
CVE-2006-4475

Joomla! before 1.0.11 does not limit access to the Admin Popups functionality, which has unknown impact and attack vectors.

Fix: after 1.0.10
Fix from $1,950 2006-08-31
Joomla HIGH 7.5
CVE-2006-4476

Multiple unspecified vulnerabilities in Joomla! before 1.0.11, related to "Injection Flaws," allow attackers to have an unknown impact via (1) global…

Fix: after 1.0.10
Fix from $1,950 2006-08-31
3000cn HIGH 7.5
CVE-2006-2112

Fuji Xerox Printing Systems (FXPS) print engine, as used in products including (1) Dell 3000cn through 5110cn and (2) Fuji Xerox DocuPrint firmware b…

Patch available
Fix from $1,950 2006-08-25
J2se MEDIUM 5.0
CVE-2006-4302

The Java Plug-in J2SE 1.3.0_02 through 5.0 Update 5, and Java Web Start 1.0 through 1.2 and J2SE 1.4.2 through 5.0 Update 5, allows remote attackers …

Patch available
Fix from $1,600 2006-08-23
Firefox HIGH 7.6
CVE-2006-4253EPSS 15%

Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Mitigation only
Fix from $1,950 2006-08-21
Websphere Application Server HIGH 7.5
CVE-2006-4136

Multiple unspecified vulnerabilities in IBM WebSphere Application Server before 6.1.0.1 have unspecified impact and attack vectors involving (1) "SOA…

Fix: after 6.1.0.0
Fix from $1,950 2006-08-14
Heimdal HIGH 7.2
CVE-2006-3084

The (1) ftpd and (2) ksu programs in (a) MIT Kerberos 5 (krb5) up to 1.5, and 1.4.x before 1.4.4, and (b) Heimdal 0.7.2 and earlier, do not check ret…

Fix: after 0.7.2
Fix from $1,950 2006-08-09
Outpost Firewall HIGH 7.2
CVE-2006-3697

Agnitum Outpost Firewall Pro 3.51.759.6511 (462), as used in (1) Lavasoft Personal Firewall 1.0.543.5722 (433) and (2) Novell BorderManager Novell Cl…

Mitigation only
Fix from $1,950 2006-07-21
Security Monitoring Analysis And Response System HIGH 7.5
CVE-2006-3733EPSS 12%

jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response Syst…

Patch available
Fix from $1,950 2006-07-21
Voyager 2091 Wireless Adsl Router MEDIUM 5.0
CVE-2006-3561EPSS 7%

BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication …

Fix: after 3.01m
Fix from $1,600 2006-07-13
Speedstream Wireless Router HIGH 7.5
CVE-2006-3344

Siemens Speedstream Wireless Router 2624 allows local users to bypass authentication and access protected files by using the Universal Plug and Play …

Mitigation only
Fix from $1,950 2006-07-03
Openoffice HIGH 7.6
CVE-2006-2198

OpenOffice.org (aka StarOffice) 1.1.x up to 1.1.5 and 2.0.x before 2.0.3 allows user-assisted attackers to conduct unauthorized activities via an Ope…

Patch available
Fix from $1,950 2006-06-30
Captcha Asp.net MEDIUM 5.0
CVE-2006-2918

The Lanap BotDetect APS.NET CAPTCHA component before 1.5.4.0 stores the UUID and hash for a CAPTCHA in the ViewState of a page, which makes it easier…

Patch available
Fix from $1,600 2006-06-23
Firefox MEDIUM 5.1
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user i…

Fix: after 1.5.0.3
Fix from $1,600 2006-06-02
Firefox HIGH 7.5
CVE-2006-2775

Mozilla Firefox and Thunderbird before 1.5.0.4 associates XUL attributes with the wrong URL under certain unspecified circumstances, which might allo…

Fix: after 1.5.0.3
Fix from $1,950 2006-06-02
Snort MEDIUM 5.0
CVE-2006-2769EPSS 11%

The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return …

Patch available
Fix from $1,600 2006-06-02
Wl 153 Router Firmware HIGH 7.5
CVE-2006-2560

Sitecom WL-153 router firmware before 1.38 allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP reque…

Fix: after 1.34
Fix from $1,950 2006-05-24
P 335wt Router HIGH 7.5
CVE-2006-2562

ZyXEL P-335WT router allows remote attackers to bypass access restrictions and conduct unauthorized operations via a UPnP request with a modified Int…

Mitigation only
Fix from $1,950 2006-05-24
Avatar Mod MEDIUM 5.0
CVE-2006-2530

avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload …

Patch available
Fix from $1,600 2006-05-22
Whatsup Professional MEDIUM 5.0
CVE-2006-2353

NmConsole/DeviceSelection.asp in Ipswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allows remote attackers to redirect users t…

Mitigation only
Fix from $1,600 2006-05-15