Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Infosphere Datastage HIGH 7.2
CVE-2011-3124

IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns …

Mitigation only
Fix from $1,950 2011-08-10
Data Synchronizer MEDIUM 5.0
CVE-2011-3014

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which mak…

Mitigation only
Fix from $1,600 2011-08-09
Data Synchronizer MEDIUM 5.0
CVE-2011-2221

The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and ob…

Mitigation only
Fix from $1,600 2011-08-09
Firefox MEDIUM 5.8
CVE-2008-7293

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to…

Fix: after 4.0
Fix from $1,600 2011-08-09
Chrome MEDIUM 5.8
CVE-2008-7294

Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attack…

Fix: after 3.0.195.38
Fix from $1,600 2011-08-09
Safari MEDIUM 5.8
CVE-2008-7296

Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite o…

Patch available
Fix from $1,600 2011-08-09
Opera Browser MEDIUM 5.8
CVE-2008-7297

Opera cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delet…

Patch available
Fix from $1,600 2011-08-09
Android Browser MEDIUM 5.8
CVE-2008-7298

The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attack…

Patch available
Fix from $1,600 2011-08-09
Captiva Einput MEDIUM 5.8
CVE-2011-1744

EMC Captiva eInput 2.1.1 before 2.1.1.37 does not restrict the origin of calls to ActiveX functions, which allows remote attackers to read arbitrary …

Fix: 2.1.1.37+
Fix from $1,600 2011-08-01
Sa500 Software HIGH 9.0
CVE-2011-2547

The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execut…

Fix: after 2.1.18
Fix from $1,950 2011-07-28
Drupal HIGH 7.5
CVE-2011-2687

Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks…

Patch available
Fix from $1,950 2011-07-27
Chyrp MEDIUM 6.5
CVE-2011-2745

upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploa…

Fix: after 2.0
Fix from $1,600 2011-07-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-2196

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss E…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
Jboss Enterprise Application Platform MEDIUM 6.8
CVE-2011-1484

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBos…

Fix: after 2.2.2
Fix from $1,600 2011-07-27
Safari MEDIUM 5.8
CVE-2011-0219

Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a …

Fix: after 5.0.5
Fix from $1,600 2011-07-21
Iphone Os HIGH 7.2
CVE-2011-0227

The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows…

Fix: after 4.2.8
Fix from $1,950 2011-07-19
Iphonehandle MEDIUM 6.5
CVE-2011-2385

The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneH…

Patch available
Fix from $1,600 2011-07-19
Bigiron Rx Switch MEDIUM 5.0
CVE-2011-2760

Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.

Mitigation only
Fix from $1,600 2011-07-17
Libgnomesu HIGH 7.2
CVE-2011-1946

gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid functi…

Patch available
Fix from $1,950 2011-07-07
Firefox MEDIUM 5.0
CVE-2011-2362

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that d…

Fix: after 3.6.17
Fix from $1,600 2011-06-30
Firefox MEDIUM 6.4
CVE-2011-2367

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sen…

Mitigation only
Fix from $1,600 2011-06-30
Firefox HIGH 10.0
CVE-2011-2368

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute a…

Mitigation only
Fix from $1,950 2011-06-30
Firefox MEDIUM 5.0
CVE-2011-2370

Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an insta…

Fix: after 4.0.1
Fix from $1,600 2011-06-30
Mac Os X HIGH 7.1
CVE-2011-2601

The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desk…

No fix yet
Fix from $1,950 2011-06-30
Smf HIGH 10.0
CVE-2011-1127

SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers …

Fix: after 1.1.12
Fix from $1,950 2011-06-21
Windows 2003 Server HIGH 7.2
CVE-2011-1249EPSS 8%

The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Serve…

No fix yet
Fix from $1,950 2011-06-16
Gdm HIGH 7.2
CVE-2011-1709

GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows l…

Patch available
Fix from $1,950 2011-06-14
Oprofile HIGH 7.2
CVE-2011-2471

utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session…

Fix: after 0.9.6
Fix from $1,950 2011-06-09
Dotclear MEDIUM 6.5
CVE-2011-1584

The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allo…

Fix: after 2.2.2
Fix from $1,600 2011-06-08
Plone MEDIUM 5.5
CVE-2011-1950

plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exp…

Patch available
Fix from $1,600 2011-06-06