Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Excel HIGH 9.3
CVE-2011-0980EPSS 26%

Microsoft Excel 2002 SP3 and 2003 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly parse Office Art obje…

Mitigation only
Fix from $1,950 2011-02-10
Openssh HIGH 7.5
CVE-2011-0539

The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-key…

Patch available
Fix from $1,950 2011-02-10
Acrobat Reader HIGH 9.3
CVE-2011-0564

Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows use weak permissions for unspecified files, which allo…

Patch available
Fix from $1,950 2011-02-10
Chrome HIGH 7.5
CVE-2011-0778

Google Chrome before 9.0.597.84 does not properly restrict drag and drop operations, which might allow remote attackers to bypass the Same Origin Pol…

Fix: after 9.0.597.83
Fix from $1,950 2011-02-04
Smarty HIGH 7.5
CVE-2009-5054

Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended ac…

Fix: after 2.6.26
Fix from $1,950 2011-02-03
Smarty HIGH 9.3
CVE-2010-4723

Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which…

Fix: after 3.0.0
Fix from $1,950 2011-02-03
Db2 MEDIUM 6.5
CVE-2011-0757

IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP2 on Linux, UNIX, and Windows does not properly revoke the DBADM authority, which allows r…

Fix: after 9.7
Fix from $1,600 2011-02-02
Networker MEDIUM 6.4
CVE-2011-0321

librpc.dll in nsrexecd in EMC NetWorker before 7.5 SP4, 7.5.3.x before 7.5.3.5, and 7.6.x before 7.6.1.2 does not properly mitigate the possibility o…

Fix: after 7.5
Fix from $1,600 2011-02-01
iOS MEDIUM 6.4
CVE-2011-0348

Cisco IOS 12.4(11)MD, 12.4(15)MD, 12.4(22)MD, 12.4(24)MD before 12.4(24)MD3, 12.4(22)MDA before 12.4(22)MDA5, and 12.4(24)MDA before 12.4(24)MDA3 on …

Mitigation only
Fix from $1,600 2011-01-28
Syslog Ng MEDIUM 6.9
CVE-2011-0343

Balabit syslog-ng 2.0, 3.0, 3.1, 3.2 OSE and PE, when running on FreeBSD or HP-UX, does not properly perform cast operations, which causes syslog-ng …

Patch available
Fix from $1,600 2011-01-28
Bugzilla HIGH 7.5
CVE-2010-4568

Bugzilla 2.14 through 2.22.7; 3.0.x, 3.1.x, and 3.2.x before 3.2.10; 3.4.x before 3.4.10; 3.6.x before 3.6.4; and 4.0.x before 4.0rc2 does not proper…

Mitigation only
Fix from $1,950 2011-01-28
Xen MEDIUM 5.5
CVE-2010-4238

The vbd_create function in Xen 3.1.2, when the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 is used, allows guest OS users to cause a den…

No fix yet
Fix from $1,600 2011-01-22
Icedtea MEDIUM 6.8
CVE-2010-4351

The JNLP SecurityManager in IcedTea (IcedTea.so) 1.7 before 1.7.7, 1.8 before 1.8.4, and 1.9 before 1.9.4 for Java OpenJDK returns from the checkPerm…

Patch available
Fix from $1,600 2011-01-20
Websphere Application Server MEDIUM 5.0
CVE-2011-0316

The Administrative Console component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.35 and 7.0 before 7.0.0.15 does not properly restrict…

Mitigation only
Fix from $1,600 2011-01-12
Matomo MEDIUM 6.4
CVE-2011-0398

The Piwik_Common::getIP function in Piwik before 1.1 does not properly determine the client IP address, which allows remote attackers to bypass inten…

Fix: after 1.0
Fix from $1,600 2011-01-10
Matomo MEDIUM 5.0
CVE-2011-0401

Piwik before 1.1 does not properly limit the number of files stored under tmp/sessions/, which might allow remote attackers to cause a denial of serv…

Fix: after 1.0
Fix from $1,600 2011-01-10
Adaptive Security Appliance Software HIGH 7.8
CVE-2010-4689

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.3(2) do not properly preserve ACL behavior after a migration, whi…

Fix: after 8.3
Fix from $1,950 2011-01-07
Activecollab MEDIUM 6.0
CVE-2010-0215

ActiveCollab before 2.3.2 allows remote authenticated users to bypass intended access restrictions, and (1) delete an attachment or (2) subscribe to …

Fix: after 2.3.1
Fix from $1,600 2011-01-07
Glibc HIGH 7.2
CVE-2010-3856EPSS 11%

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment v…

Fix: after 2.11.2
Fix from $1,950 2011-01-07
Adaptive Security Appliance Software HIGH 9.0
CVE-2010-4675

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not properly determine the interfaces for which TELNET co…

Fix: after 8.2
Fix from $1,950 2011-01-07
Adaptive Security Appliance Software HIGH 7.5
CVE-2010-4678

Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permit packets to pass before the configuration has been loa…

Fix: after 8.2
Fix from $1,950 2011-01-07
Adaptive Security Appliance Software HIGH 9.0
CVE-2010-4680

The WebVPN implementation on Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) permits the viewing of CIFS sha…

Fix: after 8.2
Fix from $1,950 2011-01-07
Mybb MEDIUM 5.0
CVE-2010-4629

MyBB (aka MyBulletinBoard) before 1.4.12 does not properly restrict uid values for group join requests, which allows remote attackers to cause a deni…

Fix: after 1.4.11
Fix from $1,600 2010-12-30
Lotus Mobile Connect MEDIUM 5.0
CVE-2010-4595

The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (…

Fix: after 6.1.3
Fix from $1,600 2010-12-22
Websphere Service Registry And Repository MEDIUM 5.0
CVE-2010-2644

IBM WebSphere Service Registry and Repository (WSRR) 7.0.0 before FP1 does not properly implement access control, which allows remote attackers to pe…

Mitigation only
Fix from $1,600 2010-12-22
Opera Browser MEDIUM 5.0
CVE-2010-4582

Opera before 11.00 does not properly handle security policies during updates to extensions, which might allow remote attackers to bypass intended acc…

Fix: after 11.00
Fix from $1,600 2010-12-22
Windows 2003 Server HIGH 7.2
CVE-2010-3943

win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Go…

Mitigation only
Fix from $1,950 2010-12-16
Realplayer HIGH 10.0
CVE-2010-0125

RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, and Mac RealPlayer 11.0 through 12.0.0.1444 …

Mitigation only
Fix from $1,950 2010-12-14
Sleipnir MEDIUM 5.8
CVE-2010-3918

Fenrir Sleipnir 2.9.6 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify …

Fix: after 2.9.6
Fix from $1,600 2010-12-10
Grani MEDIUM 5.8
CVE-2010-3919

Fenrir Grani 4.5 and earlier does not prevent interaction between web script and the clipboard, which allows remote attackers to read or modify the c…

Fix: after 4.5
Fix from $1,600 2010-12-10