Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Silverstripe MEDIUM 6.0
CVE-2011-4961

SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator …

Patch available
Fix from $1,600 2012-09-17
WordPress MEDIUM 6.5
CVE-2010-5106

The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticat…

Fix: after 3.0.2
Fix from $1,600 2012-09-14
Chrome MEDIUM 5.0
CVE-2012-4903

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor…

Fix: after 18.0.1025306
Fix from $1,600 2012-09-13
Chrome MEDIUM 5.0
CVE-2012-4906

Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor…

Fix: after 18.0.1025306
Fix from $1,600 2012-09-13
Chrome HIGH 9.3
CVE-2012-4907

Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to…

Fix: after 18.0.1025306
Fix from $1,950 2012-09-13
Chrome HIGH 7.5
CVE-2012-4908

Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors in…

Fix: after 18.0.1025306
Fix from $1,950 2012-09-13
Moinmoin MEDIUM 6.0
CVE-2012-4404

security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "…

Mitigation only
Fix from $1,600 2012-09-10
Mediawiki MEDIUM 5.0
CVE-2012-1581

MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attacker…

Mitigation only
Fix from $1,600 2012-09-09
Joomla\! MEDIUM 5.0
CVE-2012-1611

Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via …

Mitigation only
Fix from $1,600 2012-09-06
Owncloud MEDIUM 5.0
CVE-2012-4752

appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unsp…

Fix: after 4.0.5
Fix from $1,600 2012-09-05
Struts MEDIUM 5.0
CVE-2012-4387EPSS 8%

Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe…

Patch available
Fix from $1,600 2012-09-05
Slidebox MEDIUM 5.0
CVE-2012-2063

The Slidebox module before 7.x-1.4 for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via …

Fix: after 7.x-1.3
Fix from $1,600 2012-09-05
Bugzilla MEDIUM 5.0
CVE-2012-4747

Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive …

Patch available
Fix from $1,600 2012-09-04
Open Business Management MEDIUM 5.0
CVE-2011-5144

Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to test.php, w…

Fix: after 2.4.0
Fix from $1,600 2012-08-31
Advertisement MEDIUM 5.0
CVE-2012-2704

The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which allows remote attackers to o…

Patch available
Fix from $1,600 2012-08-31
Asterisk MEDIUM 6.0
CVE-2012-4737

channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Di…

Mitigation only
Fix from $1,600 2012-08-31
Firefox HIGH 7.6
CVE-2012-3973

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to…

Fix: after 14.0
Fix from $1,950 2012-08-29
Firefox MEDIUM 6.8
CVE-2012-3978

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x befor…

Fix: after 14.0
Fix from $1,600 2012-08-29
Messaging Gateway HIGH 7.9
CVE-2012-3579EPSS 40%

Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain …

Fix: after 9.5.4
Fix from $1,950 2012-08-29
Firefox HIGH 9.3
CVE-2012-3965

Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaSc…

Fix: after 14.0
Fix from $1,950 2012-08-29
Zipcart MEDIUM 6.0
CVE-2012-1650

The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when bui…

Patch available
Fix from $1,600 2012-08-28
Finder MEDIUM 6.0
CVE-2012-1641

The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenti…

Patch available
Fix from $1,600 2012-08-28
Linkchecker MEDIUM 5.0
CVE-2012-1642

includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken li…

Patch available
Fix from $1,600 2012-08-28
Fp MEDIUM 5.0
CVE-2012-1643

The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers…

Patch available
Fix from $1,600 2012-08-28
Revisioning MEDIUM 6.4
CVE-2012-1635

The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is …

Patch available
Fix from $1,600 2012-08-28
Tunnelblick MEDIUM 6.9
CVE-2012-3486

Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon o…

Fix: after 3.3beta20
Fix from $1,600 2012-08-26
Websense Email Security MEDIUM 5.0
CVE-2009-5131

The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to byp…

Fix: after 7.0
Fix from $1,600 2012-08-26
Sgos HIGH 9.3
CVE-2010-5189

Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated user…

Fix: after 4.3.4
Fix from $1,950 2012-08-26
Sgos MEDIUM 5.0
CVE-2010-5190

The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x b…

Fix: after 4.3.4
Fix from $1,600 2012-08-26
Tunnelblick HIGH 7.2
CVE-2012-3484

Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, whic…

Fix: after 3.3beta20
Fix from $1,950 2012-08-26