Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Silverstripe MEDIUM 5.0
CVE-2010-5087

SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism …

Patch available
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5093

Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the…

Patch available
Fix from $1,600 2012-08-26
Silverstripe MEDIUM 5.0
CVE-2010-5094

The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows …

Mitigation only
Fix from $1,600 2012-08-26
Applicationxtender Desktop HIGH 7.5
CVE-2012-2289EPSS 5%

EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any loc…

Fix: after 6.5
Fix from $1,950 2012-08-26
Icinga HIGH 7.5
CVE-2012-3441

The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which …

Mitigation only
Fix from $1,950 2012-08-25
Websense Email Security MEDIUM 5.0
CVE-2009-5121

Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword in the SM…

Mitigation only
Fix from $1,600 2012-08-23
Websense Web Filter HIGH 7.5
CVE-2011-5102

The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 …

No fix yet
Fix from $1,950 2012-08-23
Application Control MEDIUM 5.0
CVE-2012-4593

McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attribu…

Mitigation only
Fix from $1,600 2012-08-22
Norton Antivirus MEDIUM 6.4
CVE-2010-3497

Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it…

Mitigation only
Fix from $1,600 2012-08-22
Anti Virus MEDIUM 6.4
CVE-2010-3498

AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remo…

Mitigation only
Fix from $1,600 2012-08-22
Anti Virus MEDIUM 6.4
CVE-2010-3499

F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for…

Mitigation only
Fix from $1,600 2012-08-22
Common Management Agent MEDIUM 6.5
CVE-2009-5115

McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenti…

Mitigation only
Fix from $1,600 2012-08-22
Virusscan Enterprise MEDIUM 6.4
CVE-2010-3496

McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, whi…

No fix yet
Fix from $1,600 2012-08-22
Rational Clearquest MEDIUM 5.5
CVE-2012-2164

The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res…

Mitigation only
Fix from $1,600 2012-08-17
Comos HIGH 8.5
CVE-2012-3009

Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database ad…

Fix: after 9.1
Fix from $1,950 2012-08-16
Authen\ MEDIUM 5.0
CVE-2012-2770

The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified …

Fix: after 0.08
Fix from $1,600 2012-08-15
Bundle Copy MEDIUM 6.0
CVE-2012-2073

The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which all…

Patch available
Fix from $1,600 2012-08-14
Organic Groups MEDIUM 5.0
CVE-2012-2081

The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive…

Patch available
Fix from $1,600 2012-08-14
Dir2web MEDIUM 5.0
CVE-2012-4069

Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database …

Mitigation only
Fix from $1,600 2012-08-12
Kindle Touch HIGH 9.3
CVE-2012-4248

The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote att…

Fix: after 5.1.1
Fix from $1,950 2012-08-12
Resin MEDIUM 6.4
CVE-2012-2969

Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created fil…

Fix: after 4.0.28
Fix from $1,600 2012-08-12
Pbboard HIGH 7.5
CVE-2012-4035

The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password p…

No fix yet
Fix from $1,950 2012-08-12
Chef MEDIUM 5.5
CVE-2011-5097

chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileg…

Fix: after 0.9.16
Fix from $1,600 2012-08-08
Chef MEDIUM 6.5
CVE-2011-5098

chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges…

Fix: after 0.9.18
Fix from $1,600 2012-08-08
Global Security Kit HIGH 7.5
CVE-2012-2203

IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses…

Fix: after 8.0.13
Fix from $1,950 2012-08-08
Chef MEDIUM 6.5
CVE-2010-5142

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and upda…

Fix: after 0.8.10
Fix from $1,600 2012-08-08
Power Hardware Management Console Firmware HIGH 7.2
CVE-2012-2188

IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director …

Mitigation only
Fix from $1,950 2012-08-06
Bitcoin Core HIGH 7.5
CVE-2010-5141

wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bitcoins ow…

Fix: after 0.3.4
Fix from $1,950 2012-08-06
Scale Out Network Attached Storage HIGH 9.0
CVE-2012-2163

IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t…

Mitigation only
Fix from $1,950 2012-07-30
Zenworks Configuration Management MEDIUM 6.8
CVE-2011-2658

The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscom…

Patch available
Fix from $1,600 2012-07-26