Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Helpbox MEDIUM 6.5
CVE-2012-4974

Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) logged…

Mitigation only
Fix from $1,600 2012-12-12
Websphere Message Broker MEDIUM 6.9
CVE-2012-3317

IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt…

Mitigation only
Fix from $1,600 2012-12-05
Joomla\! HIGH 7.5
CVE-2012-1598

Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability."

Mitigation only
Fix from $1,950 2012-12-03
Joomla\! MEDIUM 5.0
CVE-2012-1599

Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via…

Mitigation only
Fix from $1,600 2012-12-03
Security Questions MEDIUM 5.0
CVE-2012-4475

The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote att…

Patch available
Fix from $1,600 2012-11-30
Drag \& Drop Gallery MEDIUM 5.0
CVE-2012-4477

Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack v…

Patch available
Fix from $1,600 2012-11-30
Listhandler HIGH 7.5
CVE-2012-4470

The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment autho…

Patch available
Fix from $1,950 2012-11-30
Search Autocomplete MEDIUM 5.0
CVE-2012-4471

The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote atta…

Patch available
Fix from $1,600 2012-11-30
Printer Firmware HIGH 7.5
CVE-2012-4964EPSS 8%

The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administ…

Fix: after 20121030
Fix from $1,950 2012-11-28
Ruby MEDIUM 5.0
CVE-2012-4522

The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to creat…

Mitigation only
Fix from $1,600 2012-11-24
Mahara MEDIUM 6.0
CVE-2012-2244

Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to cl…

Patch available
Fix from $1,600 2012-11-24
Xenserver MEDIUM 6.9
CVE-2012-3516

The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administra…

Fix: after 6.0.2
Fix from $1,600 2012-11-23
Jboss Enterprise Application Platform HIGH 7.5
CVE-2011-4605

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web P…

Fix: after 5.2.0
Fix from $1,950 2012-11-23
Websphere Datapower Xc10 Appliance HIGH 9.0
CVE-2012-5759

The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a…

Mitigation only
Fix from $1,950 2012-11-23
Sinapsi Firmware HIGH 10.0
CVE-2012-5863EPSS 25%

These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges t…

Fix: after 2.0.2870
Fix from $1,950 2012-11-23
Sinapsi Firmware HIGH 10.0
CVE-2012-5864

These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within t…

Fix: after 2.0.2870
Fix from $1,950 2012-11-23
Munin HIGH 7.2
CVE-2012-3512

Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to e…

Fix: after 2.0.5
Fix from $1,950 2012-11-21
Munin HIGH 9.3
CVE-2012-3513

munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files…

Fix: after 2.0.5
Fix from $1,950 2012-11-21
Moodle MEDIUM 6.5
CVE-2012-5479

The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute…

Mitigation only
Fix from $1,600 2012-11-21
Moodle MEDIUM 6.4
CVE-2012-5480

The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest…

Mitigation only
Fix from $1,600 2012-11-21
Firefox HIGH 9.3
CVE-2012-4210

The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Casc…

Fix: after 16.0.2
Fix from $1,950 2012-11-21
Moodle MEDIUM 6.5
CVE-2012-5471

The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to acce…

Patch available
Fix from $1,600 2012-11-21
Firefox MEDIUM 6.8
CVE-2012-4203

The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assiste…

Fix: after 16.0.2
Fix from $1,600 2012-11-21
Cups Pk Helper MEDIUM 5.8
CVE-2012-4510

cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attacker…

Fix: after 0.2.2
Fix from $1,600 2012-11-20
Radsecproxy MEDIUM 6.4
CVE-2012-4523

radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block b…

Fix: after 1.6
Fix from $1,600 2012-11-20
Radsecproxy MEDIUM 6.4
CVE-2012-4566

The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unre…

Fix: after 1.6.1
Fix from $1,600 2012-11-20
Cups HIGH 7.2
CVE-2012-5519

CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0…

No fix yet
Fix from $1,950 2012-11-20
Unix Graphic Driver HIGH 7.2
CVE-2012-4225

NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by…

Fix: after 304.32
Fix from $1,950 2012-11-19
Nspluginwrapper MEDIUM 5.0
CVE-2011-2486

nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from dete…

Patch available
Fix from $1,600 2012-11-19
Intrust HIGH 9.3
CVE-2012-5897

The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implem…

Fix: after 10.4.0.853
Fix from $1,950 2012-11-17