Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Airdroid MEDIUM 5.0
CVE-2012-3888

The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value wit…

No fix yet
Fix from $1,600 2012-07-26
Xcode MEDIUM 5.0
CVE-2012-3698

Apple Xcode before 4.4 does not properly compose a designated requirement (DR) during signing of programs that lack bundle identifiers, which allows …

Fix: after 4.3.3
Fix from $1,600 2012-07-26
Safari HIGH 7.1
CVE-2012-3697

WebKit in Apple Safari before 6.0 does not properly handle file: URLs, which allows remote attackers to bypass intended sandbox restrictions and read…

Fix: after 5.1.7
Fix from $1,950 2012-07-25
Safari MEDIUM 5.0
CVE-2012-0680

Apple Safari before 6.0 does not properly handle the autocomplete attribute of a password input element, which allows remote attackers to bypass auth…

Fix: after 5.1.7
Fix from $1,600 2012-07-25
Web Gateway HIGH 7.2
CVE-2012-2957EPSS 59%

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows local users to gain privileges by modifying files, related to a "file inc…

Mitigation only
Fix from $1,950 2012-07-23
Web Gateway MEDIUM 5.0
CVE-2012-2977

The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to change arbitrary passwords via crafted input to an ap…

Mitigation only
Fix from $1,600 2012-07-23
WordPress MEDIUM 5.0
CVE-2012-3385

WordPress before 3.4.1 does not properly restrict access to post contents such as private or draft posts, which allows remote authors or contributors…

Fix: after 3.4.0
Fix from $1,600 2012-07-22
Diablo MEDIUM 5.5
CVE-2012-3361

virt/disk/api.py in OpenStack Compute (Nova) Folsom (2012.2), Essex (2012.1), and Diablo (2011.3) allows remote authenticated users to overwrite arbi…

Patch available
Fix from $1,600 2012-07-22
Moodle MEDIUM 6.5
CVE-2012-2359

admin/roles/override.php in Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to gain privilege…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.5
CVE-2012-2358

Moodle 2.0.x before 2.0.9, 2.1.x before 2.1.6, and 2.2.x before 2.2.3 allows remote authenticated users to bypass an activity's read-only state and m…

Mitigation only
Fix from $1,600 2012-07-21
Moodle MEDIUM 5.0
CVE-2011-4588

The ip_in_range function in mnet/lib.php in MNET in Moodle 1.9.x before 1.9.15 uses an incorrect data type, which allows remote attackers to bypass i…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.5
CVE-2011-4589

backup/moodle2/restore_stepslib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not check for the moodle/course:changeidnumber privilege…

Patch available
Fix from $1,600 2012-07-20
Moodle MEDIUM 5.0
CVE-2011-4592

The command-line cron implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly interact with IP blocking, which might all…

Mitigation only
Fix from $1,600 2012-07-20
Moodle MEDIUM 6.5
CVE-2011-4583

Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have a…

Patch available
Fix from $1,600 2012-07-20
PostgreSQL MEDIUM 6.5
CVE-2012-0866

CREATE TRIGGER in PostgreSQL 8.3.x before 8.3.18, 8.4.x before 8.4.11, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 does not properly check the execute…

Mitigation only
Fix from $1,600 2012-07-18
Spaces HIGH 7.5
CVE-2012-2303

The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensiti…

Patch available
Fix from $1,950 2012-07-18
Firefox MEDIUM 5.0
CVE-2012-1959

Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey bef…

Fix: after 2.10
Fix from $1,600 2012-07-18
Eucalyptus HIGH 7.5
CVE-2012-3240

The Walrus service in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 allows remote attackers to gain administrator privileges via a crafted REST request.

Mitigation only
Fix from $1,950 2012-07-17
Eucalyptus HIGH 7.5
CVE-2012-3241

The VMware Broker in Eucalyptus 2.0.3 and 3.0.x before 3.0.2 does not properly authenticate SOAP requests, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2012-07-17
Moodle MEDIUM 5.5
CVE-2012-0798

The self-enrolment functionality in Moodle 2.1.x before 2.1.4 and 2.2.x before 2.2.1 allows remote authenticated users to obtain the manager role by …

Mitigation only
Fix from $1,600 2012-07-17
Moodle MEDIUM 5.0
CVE-2012-0793

Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote attackers to view the profile images of arbi…

Mitigation only
Fix from $1,600 2012-07-17
Celerra Network Server MEDIUM 6.5
CVE-2012-2282

EMC Celerra Network Server 6.x before 6.0.61.0, VNX 7.x before 7.0.53.2, and VNXe 2.0 and 2.1 before 2.1.3.19077 (aka MR1 SP3.2) and 2.2 before 2.2.0…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4293

The theme implementation in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 triggers duplicate caching of Cascading Style Sheets (CSS) and JavaScrip…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.5
CVE-2011-4295

The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authoriz…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4296

lib/db/access.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 assigns incorrect capabilities to the course-creator role, which allows remote …

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.4
CVE-2011-4297

comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 5.5
CVE-2011-4285

The default configuration of Moodle 2.0.x before 2.0.2 has an incorrect setting of the moodle/course:delete capability, which allows remote authentic…

Mitigation only
Fix from $1,600 2012-07-16
Moodle MEDIUM 6.8
CVE-2011-4287

admin/uploaduser_form.php in Moodle 2.0.x before 2.0.3 does not force password changes for autosubscribed users, which makes it easier for remote att…

Mitigation only
Fix from $1,600 2012-07-16
Trytond MEDIUM 5.5
CVE-2012-0215

model/modelstorage.py in the Tryton application framework (trytond) before 2.4.0 for Python does not properly restrict access to the Many2Many field …

Fix: after 2.2.3
Fix from $1,600 2012-07-12
Moodle MEDIUM 5.0
CVE-2011-4309

Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 allows remote attackers to bypass intended access restrictions and perform global searches by levera…

Mitigation only
Fix from $1,600 2012-07-11