Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Pinyin Ime HIGH 7.2
CVE-2011-2010

The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office P…

Mitigation only
Fix from $1,950 2011-12-14
Restorepoint HIGH 7.2
CVE-2011-4202

The Tadasoft Restorepoint 3.2 evaluation image uses weak permissions (www write access) for unspecified scripts, which allows local users to gain pri…

Mitigation only
Fix from $1,950 2011-12-13
Firefox MEDIUM 5.0
CVE-2011-4688

Mozilla Firefox 8.0.1 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, w…

Fix: after 8.0.1
Fix from $1,600 2011-12-07
Opera Browser MEDIUM 5.0
CVE-2011-4690

Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes…

Fix: after 11.60
Fix from $1,600 2011-12-07
Chrome MEDIUM 5.0
CVE-2011-4691

Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attemp…

Fix: after 15.0.874.121
Fix from $1,600 2011-12-07
Safari MEDIUM 5.0
CVE-2011-4692

WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for imag…

Fix: after 15
Fix from $1,600 2011-12-07
Opera Browser MEDIUM 5.0
CVE-2011-4681

Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domai…

Fix: after 11.60
Fix from $1,600 2011-12-07
Opera Browser MEDIUM 6.4
CVE-2011-4682

The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Poli…

Fix: after 11.60
Fix from $1,600 2011-12-07
Firefox MEDIUM 5.0
CVE-2002-2437

The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of v…

Fix: after 3.6.24
Fix from $1,600 2011-12-07
Safari MEDIUM 5.0
CVE-2010-5070

The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle…

No fix yet
Fix from $1,600 2011-12-07
Ie MEDIUM 5.0
CVE-2010-5071EPSS 13%

The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object ret…

Fix: after 8
Fix from $1,600 2011-12-07
Opera Browser MEDIUM 5.0
CVE-2010-5072

The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returned by the getComputedStyle met…

No fix yet
Fix from $1,600 2011-12-07
Chrome MEDIUM 5.0
CVE-2010-5073

The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl…

No fix yet
Fix from $1,600 2011-12-07
Celery MEDIUM 6.9
CVE-2011-4356

Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid a…

Patch available
Fix from $1,600 2011-12-05
Color Laserjet 3000 HIGH 10.0
CVE-2011-4161EPSS 14%

The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Dig…

Mitigation only
Fix from $1,950 2011-12-01
Mac Os X HIGH 7.6
CVE-2008-7303

The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack…

No fix yet
Fix from $1,950 2011-11-15
Mac Os X HIGH 7.6
CVE-2011-1516

The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all crea…

No fix yet
Fix from $1,950 2011-11-15
Mahara MEDIUM 6.0
CVE-2011-4118

Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC…

Fix: after 1.4.0
Fix from $1,600 2011-11-15
Db2 Tools For Z\/os MEDIUM 5.0
CVE-2011-4435

The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent …

Mitigation only
Fix from $1,600 2011-11-11
Flash Player HIGH 9.3
CVE-2011-2458

Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Ado…

Fix: 3.1.0.4880 / 10.3.183.11+
Fix from $1,950 2011-11-11
Documentum Eroom HIGH 8.5
CVE-2011-2739

The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with d…

Mitigation only
Fix from $1,950 2011-11-09
Rsa Key Manager Appliance HIGH 9.3
CVE-2011-2740

EMC RSA Key Manager (RKM) Appliance 2.7 SP1 before 2.7.1.6, when Firefox 4.x or 5.0 is used, does not properly terminate a user session upon a logout…

Mitigation only
Fix from $1,950 2011-11-09
Autotagging MEDIUM 5.5
CVE-2011-3993

SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.…

Fix: after 5.251
Fix from $1,600 2011-11-03
Slimpdf Reader HIGH 9.3
CVE-2011-4216

Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application …

Mitigation only
Fix from $1,950 2011-11-01
Slimpdf Reader HIGH 9.3
CVE-2011-4217

Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial o…

Patch available
Fix from $1,950 2011-11-01
Slimpdf Reader HIGH 9.3
CVE-2011-4220EPSS 7%

Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a deni…

Patch available
Fix from $1,950 2011-11-01
App Engine Python Sdk HIGH 7.2
CVE-2011-4212

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass…

Fix: after 1.5.3
Fix from $1,950 2011-10-30
App Engine Python Sdk HIGH 7.2
CVE-2011-4213

The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to …

Fix: 1.5.4+
Fix from $1,950 2011-10-30
App Engine Python Sdk HIGH 7.2
CVE-2011-4211

The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of file…

Fix: after 1.5.3
Fix from $1,950 2011-10-30
Websphere Application Server MEDIUM 5.0
CVE-2009-2747

The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and…

Mitigation only
Fix from $1,600 2011-10-30