Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Ptk MEDIUM 5.0
CVE-2012-5901

DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers…

Mitigation only
Fix from $1,600 2012-11-17
Cms MEDIUM 5.0
CVE-2012-5892

Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow…

Fix: after 1.1.0
Fix from $1,600 2012-11-17
Tomcat MEDIUM 5.0
CVE-2012-5885EPSS 9%

The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.…

Mitigation only
Fix from $1,600 2012-11-17
Mantisbt MEDIUM 5.5
CVE-2012-5522

MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remo…

Fix: after 1.2.11
Fix from $1,600 2012-11-16
Mantisbt MEDIUM 5.5
CVE-2012-5523

core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow re…

Fix: after 1.2.11
Fix from $1,600 2012-11-16
Player HIGH 8.3
CVE-2012-5458

VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows …

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-1895EPSS 23%

The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which…

Mitigation only
Fix from $1,950 2012-11-14
.net Framework HIGH 9.3
CVE-2012-4777EPSS 25%

The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, wh…

Mitigation only
Fix from $1,950 2012-11-14
Eoscada MEDIUM 5.0
CVE-2012-1810

EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP por…

Fix: after 11.0.19.1
Fix from $1,600 2012-11-13
Rt MEDIUM 5.0
CVE-2012-4734

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn…

Mitigation only
Fix from $1,600 2012-11-11
Essex MEDIUM 5.5
CVE-2012-5482

The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…

Patch available
Fix from $1,600 2012-11-11
Essex MEDIUM 5.5
CVE-2012-4573

The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image…

Patch available
Fix from $1,600 2012-11-11
Drupal MEDIUM 6.8
CVE-2012-4553

Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an e…

Patch available
Fix from $1,600 2012-11-11
Drupal MEDIUM 5.0
CVE-2012-4554EPSS 16%

The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file.

Patch available
Fix from $1,600 2012-11-11
Inn MEDIUM 6.8
CVE-2012-3523

The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert…

Fix: after 2.5.2
Fix from $1,600 2012-11-11
Dte Axiom MEDIUM 6.4
CVE-2012-2455

Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication …

Fix: after 12.3.2
Fix from $1,600 2012-11-10
Pebble MEDIUM 6.4
CVE-2012-4022

Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment.

Fix: after 2.6.3
Fix from $1,600 2012-11-08
Chrome HIGH 7.5
CVE-2012-5117

Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecifie…

Fix: after 23.0.1271.62
Fix from $1,950 2012-11-07
Flash Player HIGH 10.0
CVE-2012-5278EPSS 9%

Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux,…

Fix: 3.5.0.600 / 10.3.183.43+
Fix from $1,950 2012-11-07
Activism HIGH 7.5
CVE-2012-4498

The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote atta…

Patch available
Fix from $1,950 2012-11-02
Prime Data Center Network Manager HIGH 10.0
CVE-2012-5417

Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which all…

Mitigation only
Fix from $1,950 2012-11-02
Location MEDIUM 5.0
CVE-2012-4488

The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows…

Patch available
Fix from $1,600 2012-10-31
Monthly Archive By Node Type MEDIUM 5.8
CVE-2012-4491

The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attack…

Mitigation only
Fix from $1,600 2012-10-31
Email MEDIUM 5.0
CVE-2012-4499

The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email th…

Patch available
Fix from $1,600 2012-10-31
Commons MEDIUM 5.0
CVE-2012-4483

The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons…

Patch available
Fix from $1,600 2012-10-31
Cloudstack HIGH 10.0
CVE-2012-4501EPSS 8%

Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc…

Mitigation only
Fix from $1,950 2012-10-26
Formvine HIGH 7.5
CVE-2012-5302

The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensiti…

Mitigation only
Fix from $1,950 2012-10-24
Acontent HIGH 7.5
CVE-2012-5168

ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inli…

Fix: after 1.2
Fix from $1,950 2012-10-22
Acontent MEDIUM 6.5
CVE-2012-5454

user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arb…

No fix yet
Fix from $1,600 2012-10-22
Vios MEDIUM 6.8
CVE-2012-4845

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke…

Mitigation only
Fix from $1,600 2012-10-20