Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Phex MEDIUM 5.0
CVE-2006-2095

Phex before 2.8.6 allows remote attackers to cause a denial of service (application hang) by initiating multiple chat requests to a single user and t…

Fix: after 2.8.4
Fix from $1,600 2006-04-29
Phpgraphy MEDIUM 6.8
CVE-2006-1888

phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php wit…

Fix: after 0.9.11
Fix from $1,600 2006-04-20
Firefox HIGH 9.3
CVE-2006-1726EPSS 7%

Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueTo…

Patch available
Fix from $1,950 2006-04-14
Firefox MEDIUM 6.8
CVE-2006-1733EPSS 5%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protec…

Fix: after 1.7.12
Fix from $1,600 2006-04-14
Firefox HIGH 9.3
CVE-2006-1735EPSS 9%

Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers …

Fix: after 1.7.12
Fix from $1,950 2006-04-14
Interscan Messaging Security Suite HIGH 7.2
CVE-2006-1380

ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecu…

Patch available
Fix from $1,950 2006-03-24
Thttpd HIGH 7.2
CVE-2006-1079

htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacter…

No fix yet
Fix from $1,950 2006-03-09
Guestbox MEDIUM 5.0
CVE-2006-0859

Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modif…

Patch available
Fix from $1,600 2006-02-23
Zen Cart HIGH 10.0
CVE-2006-0697EPSS 5%

Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, p…

Fix: after 1.2.6d
Fix from $1,950 2006-02-15
Imagevue MEDIUM 5.0
CVE-2006-0700EPSS 7%

imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists …

No fix yet
Fix from $1,600 2006-02-15
Office HIGH 7.2
CVE-2006-0008

The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, an…

Patch available
Fix from $1,950 2006-02-14
PostgreSQL MEDIUM 6.5
CVE-2006-0553

PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a craf…

Patch available
Fix from $1,600 2006-02-14
Bind HIGH 7.5
CVE-2006-0527EPSS 8%

BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache…

Patch available
Fix from $1,950 2006-02-02
Joomla MEDIUM 5.0
CVE-2006-0114

The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to o…

Mitigation only
Fix from $1,600 2006-01-09
Javamail MEDIUM 5.0
CVE-2005-1753

ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments v…

Mitigation only
Fix from $1,600 2005-12-31
Zonealarm HIGH 7.2
CVE-2005-2932

Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default pe…

Fix: after 7.0.337.0
Fix from $1,950 2005-12-31
Fortios HIGH 7.5
CVE-2005-3058

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) H…

Fix: after 3_beta
Fix from $1,950 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4850

eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit d…

Fix: after 3.7
Fix from $1,600 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4852

The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (und…

Fix: 3.5.8+
Fix from $1,600 2005-12-31
Ez Publish HIGH 9.4
CVE-2005-4853

The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does no…

Mitigation only
Fix from $1,950 2005-12-31
Ez Publish MEDIUM 5.0
CVE-2005-4854

eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated user…

Mitigation only
Fix from $1,600 2005-12-31
Mac Os X Server HIGH 7.5
CVE-2005-4217

Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privil…

Mitigation only
Fix from $1,950 2005-12-14
Ie HIGH 7.1
CVE-2005-4089EPSS 22%

Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @impor…

No fix yet
Fix from $1,950 2005-12-08
Secureclient Ng MEDIUM 6.5
CVE-2005-4093

Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modi…

Mitigation only
Fix from $1,600 2005-12-08
Lynx HIGH 7.5
CVE-2005-2929

Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynx…

Patch available
Fix from $1,950 2005-11-18
Realone Player HIGH 7.2
CVE-2005-2936

Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne…

Mitigation only
Fix from $1,950 2005-11-18
Itunes HIGH 7.2
CVE-2005-2938

Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges…

Mitigation only
Fix from $1,950 2005-11-18
Tivoli Directory Server MEDIUM 5.8
CVE-2005-3567

slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and mod…

Patch available
Fix from $1,600 2005-11-16
Mac Os X HIGH 7.2
CVE-2005-2741

Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should…

Patch available
Fix from $1,950 2005-10-26
Linux Kernel MEDIUM 5.0
CVE-2005-3273

The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, doe…

Patch available
Fix from $1,600 2005-10-21