Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Opensuse MEDIUM 6.9
CVE-2011-0468

The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via she…

Mitigation only
Fix from $1,600 2011-04-04
Nac Guest Server MEDIUM 5.0
CVE-2011-0963

The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 a…

Fix: after 2.0.2
Fix from $1,600 2011-03-31
Logrotate MEDIUM 6.3
CVE-2011-1548

The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, wh…

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1549

The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which …

Mitigation only
Fix from $1,600 2011-03-30
Logrotate MEDIUM 6.3
CVE-2011-1550

The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write acces…

Mitigation only
Fix from $1,600 2011-03-30
Opensuse Factory MEDIUM 6.9
CVE-2011-1551

SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gai…

Mitigation only
Fix from $1,600 2011-03-30
Glibc MEDIUM 6.9
CVE-2009-5064

ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a…

Fix: after 2.1.3
Fix from $1,600 2011-03-30
Data Protection Advisor Collector HIGH 7.2
CVE-2011-1420

EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users …

No fix yet
Fix from $1,950 2011-03-28
Otrs MEDIUM 6.5
CVE-2008-7277

Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization o…

Fix: after 2.3.0
Fix from $1,600 2011-03-18
Otrs MEDIUM 6.5
CVE-2008-7279

The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restric…

Fix: after 2.2.7
Fix from $1,600 2011-03-18
Otrs MEDIUM 6.0
CVE-2008-7283

Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access r…

Fix: after 2.2.5
Fix from $1,600 2011-03-18
Otrs MEDIUM 6.5
CVE-2010-4763

The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJA…

Fix: after 2.4.10
Fix from $1,600 2011-03-18
Otrs MEDIUM 6.0
CVE-2010-4768

Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intend…

Fix: after 2.3.4
Fix from $1,600 2011-03-18
Postfix MEDIUM 6.8
CVE-2011-0411EPSS 16%

The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restric…

No fix yet
Fix from $1,600 2011-03-16
Libvirt MEDIUM 6.9
CVE-2011-1146

libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause…

Patch available
Fix from $1,600 2011-03-15
Safari MEDIUM 5.8
CVE-2011-0166

The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy a…

Fix: after 5.0.3
Fix from $1,600 2011-03-11
Websphere Application Server MEDIUM 6.5
CVE-2011-1321

The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1…

Mitigation only
Fix from $1,600 2011-03-08
Websphere Application Server MEDIUM 6.0
CVE-2011-1311

The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role m…

Fix: after 7.0.0.13
Fix from $1,600 2011-03-08
Ruby MEDIUM 5.0
CVE-2011-1005

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings vi…

Patch available
Fix from $1,600 2011-03-02
Adaptive Security Appliance HIGH 7.8
CVE-2011-0396

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 b…

Mitigation only
Fix from $1,950 2011-02-25
Telepresence Multipoint Switch Software HIGH 8.0
CVE-2011-0387

The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote au…

Mitigation only
Fix from $1,950 2011-02-25
Policycoreutils MEDIUM 6.9
CVE-2011-1011

The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterpr…

Fix: after 2.0.83
Fix from $1,600 2011-02-24
Directory Server MEDIUM 6.2
CVE-2011-0532

The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se…

Mitigation only
Fix from $1,600 2011-02-23
Metasploit Framework MEDIUM 6.2
CVE-2011-1056

The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, whi…

Mitigation only
Fix from $1,600 2011-02-21
Dellsystemlite.scanner Activex Control MEDIUM 5.0
CVE-2011-0330

The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest pr…

Mitigation only
Fix from $1,600 2011-02-21
Rails HIGH 7.5
CVE-2011-0449

actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly im…

Patch available
Fix from $1,950 2011-02-21
Filenet P8 Content Engine MEDIUM 5.0
CVE-2011-1046

IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM…

Mitigation only
Fix from $1,600 2011-02-21
Icedtea Web HIGH 7.5
CVE-2011-0706

The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u…

Patch available
Fix from $1,950 2011-02-19
Lotus Connections MEDIUM 6.8
CVE-2011-1032

IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, wh…

Mitigation only
Fix from $1,600 2011-02-15
Powerpoint HIGH 9.3
CVE-2011-0976EPSS 25%

Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pac…

Mitigation only
Fix from $1,950 2011-02-10