Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Irix HIGH 7.5
CVE-2005-0139

Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, whic…

Patch available
Fix from $1,950 2005-09-21
Downfile HIGH 7.5
CVE-2005-2819

DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.

Mitigation only
Fix from $1,950 2005-09-07
Solaris HIGH 7.2
CVE-2005-2072

The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to…

No fix yet
Fix from $1,950 2005-06-29
Firefox HIGH 7.5
CVE-2005-1532EPSS 9%

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh…

Mitigation only
Fix from $1,950 2005-05-12
Uguestbook MEDIUM 5.0
CVE-2005-1425

Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…

No fix yet
Fix from $1,600 2005-05-03
Unclassified MEDIUM 5.0
CVE-2005-1426

Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…

No fix yet
Fix from $1,600 2005-05-03
PostgreSQL MEDIUM 6.5
CVE-2005-0244

PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.

Patch available
Fix from $1,600 2005-05-02
Newsscript HIGH 10.0
CVE-2005-0735EPSS 8%

newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.

No fix yet
Fix from $1,950 2005-05-02
Mac Os X HIGH 7.6
CVE-2005-0970

Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta…

Mitigation only
Fix from $1,950 2005-05-02
Linux HIGH 9.3
CVE-2004-1029EPSS 17%

The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict acce…

Patch available
Fix from $1,950 2005-03-01
Prevx Home MEDIUM 6.6
CVE-2004-1193

Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalme…

Mitigation only
Fix from $1,600 2005-01-10
Solaris HIGH 7.2
CVE-2004-1767

The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving t…

Patch available
Fix from $1,950 2004-12-31
Smart Guest Book MEDIUM 5.0
CVE-2004-2608

SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which a…

No fix yet
Fix from $1,600 2004-12-31
Newsphp HIGH 10.0
CVE-2004-2689

NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.

Mitigation only
Fix from $1,950 2004-12-31
Php Exec Dir HIGH 9.3
CVE-2004-2692

The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrar…

Patch available
Fix from $1,950 2004-12-31
Hp Ux HIGH 7.2
CVE-2004-2693

HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privile…

Mitigation only
Fix from $1,950 2004-12-31
Outlook Express MEDIUM 5.8
CVE-2004-2694EPSS 9%

Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook co…

Mitigation only
Fix from $1,600 2004-12-31
Aspdotnetstorefront HIGH 9.0
CVE-2004-2700

Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executabl…

Mitigation only
Fix from $1,950 2004-12-31
Web Wiz Forums MEDIUM 5.8
CVE-2004-2733

Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_…

Mitigation only
Fix from $1,600 2004-12-31
Phprojekt HIGH 7.5
CVE-2004-2739

The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors.

Patch available
Fix from $1,950 2004-12-31
Mega Upload Progress Bar MEDIUM 6.4
CVE-2004-2743

upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to…

Patch available
Fix from $1,600 2004-12-31
Firefox HIGH 7.5
CVE-2004-0867EPSS 17%

Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…

Mitigation only
Fix from $1,950 2004-12-23
Database Server MEDIUM 6.5
CVE-2004-1338

The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or …

Patch available
Fix from $1,600 2004-12-23
Bsdmainutils HIGH 7.2
CVE-2004-0793

The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu…

Patch available
Fix from $1,950 2004-10-20
Mod Auth Shadow HIGH 7.5
CVE-2004-0041

The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenti…

Patch available
Fix from $1,950 2004-02-03
Ie HIGH 9.3
CVE-2003-1026EPSS 39%

Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added…

Mitigation only
Fix from $1,950 2004-01-20
Dwl 900ap\+ HIGH 10.0
CVE-2003-1346

D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware u…

Mitigation only
Fix from $1,950 2003-12-31
Hp Ux HIGH 7.2
CVE-2003-1356

The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a de…

Patch available
Fix from $1,950 2003-12-31
Hp Ux HIGH 7.2
CVE-2003-1358

rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges,…

No fix yet
Fix from $1,950 2003-12-31
Outlook HIGH 8.8
CVE-2003-1378EPSS 16%

Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…

No fix yet
Fix from $1,950 2003-12-31