Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Autoform Pdm Archive MEDIUM 6.5
CVE-2012-1828

The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to pe…

Fix: after 7.0
Fix from $1,600 2012-06-13
Linux Kernel HIGH 7.2
CVE-2011-2211

The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allo…

Fix: after 2.6.39.3
Fix from $1,950 2012-06-13
Web Filtering MEDIUM 5.8
CVE-2012-2565

Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to…

Fix: after 5.0.13
Fix from $1,600 2012-06-09
Web Filtering MEDIUM 5.0
CVE-2012-2566

Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connecti…

Fix: after 5.0.13
Fix from $1,600 2012-06-09
Deltav MEDIUM 6.4
CVE-2012-1818

An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.…

Mitigation only
Fix from $1,600 2012-06-08
Dotcms MEDIUM 6.0
CVE-2012-1826

dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template.

Mitigation only
Fix from $1,600 2012-06-08
Scrumworks MEDIUM 6.5
CVE-2012-2603

The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modifie…

Mitigation only
Fix from $1,600 2012-06-08
Globus Toolkit HIGH 7.6
CVE-2012-3292

The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam…

Fix: after 5.2.1
Fix from $1,950 2012-06-07
Kerberos 5 MEDIUM 5.5
CVE-2012-1012

server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) …

Mitigation only
Fix from $1,600 2012-06-07
Firefox HIGH 7.2
CVE-2012-1942

The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain pri…

Mitigation only
Fix from $1,950 2012-06-05
Rt HIGH 7.5
CVE-2011-5092

Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspec…

Patch available
Fix from $1,950 2012-06-04
Rt MEDIUM 6.5
CVE-2011-5093

Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to b…

Patch available
Fix from $1,600 2012-06-04
Lan W300n\/ru2 Firmware HIGH 10.0
CVE-2012-1250EPSS 6%

Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative p…

Fix: 2.27+
Fix from $1,950 2012-06-04
Sympa HIGH 7.5
CVE-2012-2352

The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers …

Fix: after 6.1.10
Fix from $1,950 2012-05-31
Puppet MEDIUM 6.9
CVE-2012-1053

The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterpri…

Mitigation only
Fix from $1,600 2012-05-29
Score M HIGH 10.0
CVE-2012-2949

The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows …

Mitigation only
Fix from $1,950 2012-05-29
Blackarmor Nas HIGH 10.0
CVE-2012-2568

d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrato…

Mitigation only
Fix from $1,950 2012-05-25
Jira MEDIUM 6.4
CVE-2012-2928

The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-part…

Fix: after 5.0.0
Fix from $1,600 2012-05-22
Business Service Management HIGH 10.0
CVE-2012-2561EPSS 9%

HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary …

Mitigation only
Fix from $1,950 2012-05-21
Web Gateway HIGH 10.0
CVE-2012-0297EPSS 73%

The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers…

Mitigation only
Fix from $1,950 2012-05-21
Web Gateway MEDIUM 6.4
CVE-2012-0298EPSS 9%

The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitra…

Mitigation only
Fix from $1,600 2012-05-21
Web Gateway HIGH 10.0
CVE-2012-0299EPSS 64%

The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a des…

Mitigation only
Fix from $1,950 2012-05-21
Artiphp Cms MEDIUM 5.0
CVE-2012-2905

Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote …

No fix yet
Fix from $1,600 2012-05-21
Connman HIGH 7.8
CVE-2012-2320

ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrict…

Fix: after 0.84
Fix from $1,950 2012-05-18
Openvms MEDIUM 6.9
CVE-2012-2010

The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM sys…

Mitigation only
Fix from $1,600 2012-05-18
Sudo HIGH 7.2
CVE-2012-2337

sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local…

Mitigation only
Fix from $1,950 2012-05-18
Linux Kernel HIGH 7.2
CVE-2012-2123

The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities…

Fix: 3.0.29 / 3.2.16+
Fix from $1,950 2012-05-17
Linux Kernel HIGH 7.2
CVE-2012-2319

Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafte…

Fix: after 3.3.3
Fix from $1,950 2012-05-17
Linux Kernel MEDIUM 5.2
CVE-2012-1179

The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative acce…

Fix: after 3.3
Fix from $1,600 2012-05-17
Chrome HIGH 7.2
CVE-2011-3098

Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gai…

Fix: after 19.0.1084.45
Fix from $1,950 2012-05-16