Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Web Erp HIGH 7.5
CVE-2003-1383

WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the…

Fix: after 0.1.4
Fix from $1,950 2003-12-31
2400 Video Server MEDIUM 6.4
CVE-2003-1386EPSS 8%

AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which disp…

Mitigation only
Fix from $1,600 2003-12-31
Petitforum MEDIUM 5.0
CVE-2003-1423

Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensi…

No fix yet
Fix from $1,600 2003-12-31
Slashem Tty HIGH 7.2
CVE-2003-1474

slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privil…

Mitigation only
Fix from $1,950 2003-12-31
Insight Management Suite HIGH 10.0
CVE-2003-1495EPSS 5%

Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges …

Patch available
Fix from $1,950 2003-12-31
Asr 8100 HIGH 7.8
CVE-2003-1515

Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to …

No fix yet
Fix from $1,950 2003-12-31
Pgpdisk MEDIUM 6.3
CVE-2003-1524

PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access dat…

Mitigation only
Fix from $1,600 2003-12-31
Guestbook MEDIUM 5.0
CVE-2003-1541

PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain …

Mitigation only
Fix from $1,600 2003-12-31
Uploader MEDIUM 6.8
CVE-2003-1552

Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an …

Mitigation only
Fix from $1,600 2003-12-31
Solaris HIGH 10.0
CVE-2003-1081

Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.

Patch available
Fix from $1,950 2003-09-09
Data Engine HIGH 7.2
CVE-2003-0230

Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka…

Mitigation only
Fix from $1,950 2003-08-27
Cache Database HIGH 7.2
CVE-2003-0497

Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and e…

Mitigation only
Fix from $1,950 2003-08-07
Fm114p HIGH 7.5
CVE-2002-1877

NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname.

Mitigation only
Fix from $1,950 2002-12-31
Ipfilter HIGH 7.5
CVE-2002-1978

IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to…

Patch available
Fix from $1,950 2002-12-31
Kismac MEDIUM 6.4
CVE-2002-2242

The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to…

Fix: after 0.2a
Fix from $1,600 2002-12-31
Sendmail HIGH 7.5
CVE-2002-2261

Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS …

Patch available
Fix from $1,950 2002-12-31
Open Source Internet Solutions MEDIUM 6.4
CVE-2002-2265

Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F al…

Patch available
Fix from $1,600 2002-12-31
Shopfactory MEDIUM 6.4
CVE-2002-2302

3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form fiel…

Mitigation only
Fix from $1,600 2002-12-31
Internet Explorer MEDIUM 6.4
CVE-2002-2311EPSS 10%

Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to…

No fix yet
Fix from $1,600 2002-12-31
Mysimplenews HIGH 7.8
CVE-2002-2320

MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3.

No fix yet
Fix from $1,950 2002-12-31
Webppliance MEDIUM 5.0
CVE-2002-2344

Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address.

Mitigation only
Fix from $1,600 2002-12-31
Tftpd32 MEDIUM 6.4
CVE-2002-2353EPSS 7%

tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests.

Patch available
Fix from $1,600 2002-12-31
Hamweather MEDIUM 6.4
CVE-2002-2356

HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.

Mitigation only
Fix from $1,600 2002-12-31
Webmin HIGH 9.3
CVE-2002-2360

The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary f…

No fix yet
Fix from $1,950 2002-12-31
Messenger MEDIUM 5.8
CVE-2002-2361

The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs v…

Mitigation only
Fix from $1,600 2002-12-31
Hp Ux HIGH 7.2
CVE-2002-2363

VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges.

Patch available
Fix from $1,950 2002-12-31
Interscan Viruswall MEDIUM 5.0
CVE-2002-2394

InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTT…

Mitigation only
Fix from $1,600 2002-12-31
Interscan Viruswall MEDIUM 5.0
CVE-2002-2395

InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content…

Mitigation only
Fix from $1,600 2002-12-31
Rtos MEDIUM 6.9
CVE-2002-2407

Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch …

Mitigation only
Fix from $1,600 2002-12-31
Solaris Answerbook2 HIGH 10.0
CVE-2002-2425

Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a di…

Patch available
Fix from $1,950 2002-12-31