Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Webcalendar HIGH 7.5
CVE-2012-5385

install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via ve…

Mitigation only
Fix from $1,950 2012-10-11
Firefox HIGH 9.3
CVE-2012-3991

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 d…

Fix: 10.0.8 / 16.0+
Fix from $1,950 2012-10-10
Virtual War MEDIUM 5.0
CVE-2010-5065

popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid…

No fix yet
Fix from $1,600 2012-10-08
Regcode MEDIUM 5.0
CVE-2012-1623

The Registration Codes module before 6.x-2.4 for Drupal does not restrict access to the registration code list, which might allow remote attackers to…

Fix: after 6.x-2.3
Fix from $1,600 2012-10-06
Monkey MEDIUM 6.9
CVE-2012-4443

Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privil…

Mitigation only
Fix from $1,600 2012-10-05
Mavili Guestbook MEDIUM 5.0
CVE-2012-5298

Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attacke…

No fix yet
Fix from $1,600 2012-10-04
Mavili Guestbook HIGH 7.5
CVE-2012-5299

Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) e…

No fix yet
Fix from $1,950 2012-10-04
License Software HIGH 7.2
CVE-2012-0692

CA License (aka CA Licensing) before 1.90.03 allows local users to modify or create arbitrary files, and consequently gain privileges, via unspecifie…

Fix: after 1.90.02
Fix from $1,950 2012-10-02
License Software HIGH 7.2
CVE-2012-0691

CA License (aka CA Licensing) before 1.90.03 does not properly restrict system commands, which allows local users to gain privileges via unspecified …

Fix: after 1.90.02
Fix from $1,950 2012-10-02
Eucalyptus MEDIUM 5.0
CVE-2012-4063

The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows…

Fix: after 3.1.0
Fix from $1,600 2012-10-01
Eucalyptus MEDIUM 6.5
CVE-2012-4064

Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gai…

Fix: after 3.1.0
Fix from $1,600 2012-10-01
Policykit MEDIUM 6.9
CVE-2011-4945

PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentic…

Patch available
Fix from $1,600 2012-10-01
Atheme MEDIUM 6.0
CVE-2012-1576

The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly cle…

Mitigation only
Fix from $1,600 2012-10-01
389 Directory Server MEDIUM 6.0
CVE-2012-4450

389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users …

Patch available
Fix from $1,600 2012-10-01
Drupal MEDIUM 5.0
CVE-2012-1591

The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows r…

Patch available
Fix from $1,600 2012-10-01
Grails MEDIUM 5.0
CVE-2012-1833

VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass …

Fix: after 1.3.7
Fix from $1,600 2012-09-28
Enterprise Mrg MEDIUM 5.0
CVE-2012-2680

Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which a…

Fix: after 0.1.5192-4
Fix from $1,600 2012-09-28
Ubiquity Slideshow Ubuntu MEDIUM 6.8
CVE-2012-0956

ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and rea…

Fix: after 58.1
Fix from $1,600 2012-09-28
Iphone Os MEDIUM 5.0
CVE-2012-3742

Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Iphone Os MEDIUM 5.0
CVE-2012-3743

The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sen…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Iphone Os MEDIUM 6.9
CVE-2012-3728

The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain…

Fix: after 5.1.1
Fix from $1,600 2012-09-20
Fillpdf MEDIUM 5.0
CVE-2012-5007

The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the …

Patch available
Fix from $1,600 2012-09-20
Rivettracker HIGH 7.5
CVE-2012-4993

torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact.

Fix: after 1.03
Fix from $1,950 2012-09-19
Moodle MEDIUM 5.5
CVE-2012-4408

course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, …

Patch available
Fix from $1,600 2012-09-19
Spice Gtk MEDIUM 6.9
CVE-2012-4425

libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute …

Patch available
Fix from $1,600 2012-09-18
Libdbus MEDIUM 6.9
CVE-2012-3524

libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileg…

Fix: after 1.5.12
Fix from $1,600 2012-09-18
Simatic Pcs7 MEDIUM 5.0
CVE-2012-3030

WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with i…

Fix: after 7.0
Fix from $1,600 2012-09-18
Endpoint Protector Appliace 4 HIGH 7.5
CVE-2012-2994EPSS 6%

The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for r…

Mitigation only
Fix from $1,950 2012-09-18
Ubercart Payflow MEDIUM 5.0
CVE-2012-2058

The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.

Mitigation only
Fix from $1,600 2012-09-17
Silverstripe MEDIUM 5.0
CVE-2010-5078

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allow…

Mitigation only
Fix from $1,600 2012-09-17