Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Esx MEDIUM 6.3
CVE-2011-2145

mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.…

Patch available
Fix from $1,600 2011-06-06
Rampart\/c MEDIUM 6.5
CVE-2011-2329

The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration …

Patch available
Fix from $1,600 2011-06-02
Tivoli Management Framework HIGH 9.0
CVE-2011-2330

Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, w…

No fix yet
Fix from $1,950 2011-06-02
Unified Ip Phone 7906 MEDIUM 6.6
CVE-2011-1602

The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif…

Mitigation only
Fix from $1,600 2011-06-02
Unified Ip Phone 7906 MEDIUM 6.6
CVE-2011-1603

Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bu…

Mitigation only
Fix from $1,600 2011-06-02
Anyconnect Secure Mobility Client HIGH 7.2
CVE-2011-2041

The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and…

Fix: after 2.3.2016
Fix from $1,950 2011-06-02
Walrack MEDIUM 6.8
CVE-2011-1329

WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code vi…

Patch available
Fix from $1,600 2011-05-31
Chrome Os HIGH 7.2
CVE-2011-2169

Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing comm…

Fix: after 0.12.433.35
Fix from $1,950 2011-05-24
Cyrus Imap Server MEDIUM 5.1
CVE-2011-1926

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to i…

Fix: after 2.4.6
Fix from $1,600 2011-05-23
Xcs MEDIUM 6.8
CVE-2011-2165EPSS 5%

The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to inser…

Mitigation only
Fix from $1,600 2011-05-23
Smarterstats MEDIUM 5.0
CVE-2011-2157

The (1) Admin/frmEmailReportSettings.aspx and (2) Admin/frmGeneralSettings.aspx components in the SmarterTools SmarterStats 6.0 web server generate w…

Mitigation only
Fix from $1,600 2011-05-20
Datacap Taskmaster Capture MEDIUM 6.8
CVE-2011-2143

IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an i…

Mitigation only
Fix from $1,600 2011-05-16
Mahara MEDIUM 6.5
CVE-2011-1402

Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, …

Fix: after 1.3.5
Fix from $1,600 2011-05-13
Palm Webos HIGH 7.2
CVE-2011-1738

HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by…

Mitigation only
Fix from $1,950 2011-05-13
.net Framework HIGH 7.7
CVE-2011-1271EPSS 20%

The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle express…

No fix yet
Fix from $1,950 2011-05-10
Db2 MEDIUM 6.5
CVE-2011-1846

IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authe…

Fix: after 9.7
Fix from $1,600 2011-05-03
Language Selector HIGH 7.2
CVE-2011-0729

dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result…

Fix: after 0.6.6
Fix from $1,950 2011-04-29
Forms MEDIUM 6.4
CVE-2010-3260

oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly rest…

Fix: after 3.8.1
Fix from $1,600 2011-04-27
Networker MEDIUM 6.9
CVE-2011-1421

EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, …

Mitigation only
Fix from $1,600 2011-04-22
Android HIGH 7.2
CVE-2011-1149

Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox …

Fix: after 2.2.2
Fix from $1,950 2011-04-21
Satellite MEDIUM 5.5
CVE-2010-1171

Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi…

Mitigation only
Fix from $1,600 2011-04-18
Mono MEDIUM 5.8
CVE-2011-0989

The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properl…

Patch available
Fix from $1,600 2011-04-13
Websphere Application Server MEDIUM 6.8
CVE-2011-1683

IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registr…

Mitigation only
Fix from $1,600 2011-04-13
Perl MEDIUM 5.0
CVE-2011-1487EPSS 9%

The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not appl…

Patch available
Fix from $1,600 2011-04-11
Glibc MEDIUM 6.2
CVE-2011-1095

locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to …

Fix: after 2.12.2
Fix from $1,600 2011-04-10
Opensuse Build Service MEDIUM 6.4
CVE-2011-0466

The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions …

Mitigation only
Fix from $1,600 2011-04-10
Node Quick Find MEDIUM 5.0
CVE-2011-1661

The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intend…

Patch available
Fix from $1,600 2011-04-10
Phpboost MEDIUM 5.0
CVE-2011-1665

PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL fil…

No fix yet
Fix from $1,600 2011-04-10
Xml Security Library MEDIUM 5.1
CVE-2011-1425EPSS 8%

xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to cre…

Fix: after 1.2.16
Fix from $1,600 2011-04-04
Vix Api MEDIUM 6.9
CVE-2011-1126

VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users t…

Mitigation only
Fix from $1,600 2011-04-04