Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Moodle MEDIUM 5.0
CVE-2011-4300

The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which a…

Patch available
Fix from $1,600 2012-07-11
Office MEDIUM 6.9
CVE-2012-1894

Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, …

Mitigation only
Fix from $1,600 2012-07-10
Office Web Apps MEDIUM 5.5
CVE-2012-1860EPSS 13%

Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check…

Mitigation only
Fix from $1,600 2012-07-10
Org.apache.sling.servlets.post MEDIUM 5.0
CVE-2012-2138EPSS 14%

The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co…

Fix: after 2.1.0
Fix from $1,600 2012-07-09
Nec Biglobe Yome Collection MEDIUM 5.0
CVE-2012-2640

The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafte…

Fix: after 1.8.3
Fix from $1,600 2012-07-05
Mantisbt MEDIUM 6.4
CVE-2012-1119

MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without de…

Fix: after 1.2.8
Fix from $1,600 2012-06-29
Font Uploader HIGH 7.5
CVE-2012-3814EPSS 10%

Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrar…

No fix yet
Fix from $1,950 2012-06-27
Vios HIGH 7.2
CVE-2012-2200

The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma…

Mitigation only
Fix from $1,950 2012-06-27
Protected Node HIGH 7.5
CVE-2012-2730

The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not properly "protect node access when nodes are accessed outside of the standard no…

Patch available
Fix from $1,950 2012-06-27
Hostmaster MEDIUM 5.8
CVE-2012-2707

The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which all…

Patch available
Fix from $1,600 2012-06-27
Filedepot MEDIUM 5.1
CVE-2012-2719

The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Exp…

Patch available
Fix from $1,600 2012-06-27
Tokenauth MEDIUM 5.0
CVE-2012-2720

The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attack…

Patch available
Fix from $1,600 2012-06-27
Organic Groups MEDIUM 6.8
CVE-2012-2721

The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "acce…

Patch available
Fix from $1,600 2012-06-27
Ubercart Product Keys MEDIUM 5.0
CVE-2012-2702

The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to …

Patch available
Fix from $1,600 2012-06-27
Rails MEDIUM 6.4
CVE-2012-2660

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider …

No fix yet
Fix from $1,600 2012-06-22
Aix MEDIUM 6.9
CVE-2012-2179

libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file.

Patch available
Fix from $1,600 2012-06-22
Liveupdate Administrator MEDIUM 6.9
CVE-2012-0304

Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local user…

Fix: after 2.3.0
Fix from $1,600 2012-06-22
Lotus Expeditor MEDIUM 5.0
CVE-2012-0191

The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al…

Mitigation only
Fix from $1,600 2012-06-22
Linux Kernel HIGH 7.2
CVE-2011-1477

Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corrupt…

Fix: after 2.6.38.8
Fix from $1,950 2012-06-21
Linux Kernel HIGH 7.2
CVE-2012-0028

The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local …

Fix: after 2.6.27.62
Fix from $1,950 2012-06-21
Libgssglue MEDIUM 6.2
CVE-2011-2709

libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbi…

Fix: after 0.3
Fix from $1,600 2012-06-21
Member Conversation HIGH 7.5
CVE-2012-3577EPSS 14%

Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to e…

Fix: after 1.3
Fix from $1,950 2012-06-17
Fcchat Widget MEDIUM 6.8
CVE-2012-3578EPSS 8%

Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e…

Fix: after 2.2.13.1
Fix from $1,600 2012-06-17
Mantisbt HIGH 7.5
CVE-2012-2691

The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bu…

Fix: after 1.2.10
Fix from $1,950 2012-06-17
Rbx Gallery HIGH 10.0
CVE-2012-3575EPSS 15%

Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code …

Mitigation only
Fix from $1,950 2012-06-16
Wpstorecart HIGH 10.0
CVE-2012-3576EPSS 18%

Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arb…

Fix: after 2.5.29
Fix from $1,950 2012-06-16
Gnash MEDIUM 5.0
CVE-2011-4328

plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows l…

Fix: after 0.8.9
Fix from $1,600 2012-06-16
Opera Browser MEDIUM 5.0
CVE-2012-3557

Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON reso…

Fix: after 11.62
Fix from $1,600 2012-06-14
Autoform Pdm Archive MEDIUM 6.0
CVE-2012-3347

AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users…

Fix: after 6.920
Fix from $1,600 2012-06-13
Autoform Pdm Archive MEDIUM 6.5
CVE-2012-1827

The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform datab…

Fix: after 7.0
Fix from $1,600 2012-06-13