Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Cobbler HIGH 7.2
CVE-2010-4512

Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions f…

Fix: after 2.0.3.1-2
Fix from $1,950 2010-12-09
Systemtap HIGH 7.2
CVE-2010-4170EPSS 5%

The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allows local users to gain privile…

No fix yet
Fix from $1,950 2010-12-07
Enterprise Mrg HIGH 7.5
CVE-2010-4179

The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the …

Mitigation only
Fix from $1,950 2010-12-07
Bind MEDIUM 5.0
CVE-2010-3615EPSS 10%

named in ISC BIND 9.7.2-P2 does not check all intended locations for allow-query ACLs, which might allow remote attackers to make successful requests…

Mitigation only
Fix from $1,600 2010-12-06
Web Wiz Newspad MEDIUM 5.0
CVE-2009-5019

Web Wiz NewsPad stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databas…

No fix yet
Fix from $1,600 2010-12-01
Iphone Os MEDIUM 5.8
CVE-2010-3829

WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetc…

Fix: after 4.1
Fix from $1,600 2010-11-26
Iphone Os HIGH 7.2
CVE-2010-3830

Networking in Apple iOS before 4.2 accesses an invalid pointer during the processing of packet filter rules, which allows local users to gain privile…

Fix: after 4.1
Fix from $1,950 2010-11-26
Safari MEDIUM 5.8
CVE-2010-3813

The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 t…

Fix: after 5.0.2
Fix from $1,600 2010-11-22
Foswiki MEDIUM 6.5
CVE-2010-4215

UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences …

Patch available
Fix from $1,600 2010-11-17
Mac Os X Server MEDIUM 6.8
CVE-2010-3783

Password Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not properly perform replication, which allows remote authenticated users to b…

Patch available
Fix from $1,600 2010-11-16
Omnifind HIGH 7.5
CVE-2010-3893

The administrator interface in IBM OmniFind Enterprise Edition 8.x and 9.x does not restrict use of a session ID (aka SID) value to a single IP addre…

No fix yet
Fix from $1,950 2010-11-12
Omnifind HIGH 7.2
CVE-2010-3895

esRunCommand in IBM OmniFind Enterprise Edition before 9.1 allows local users to gain privileges by specifying an arbitrary command name as the first…

Fix: after 9.0
Fix from $1,950 2010-11-12
Omnifind MEDIUM 5.0
CVE-2010-3898

IBM OmniFind Enterprise Edition 8.x and 9.x does not properly restrict the cookie path of administrator (aka ESAdmin) cookies, which might allow remo…

Mitigation only
Fix from $1,600 2010-11-12
Gnome Shell MEDIUM 6.9
CVE-2010-4000

gnome-shell in GNOME Shell 2.31.5 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Troja…

Mitigation only
Fix from $1,600 2010-11-06
Kisisel Radyo Script MEDIUM 5.0
CVE-2010-4145

Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a da…

No fix yet
Fix from $1,600 2010-11-02
Springsource Spring Security MEDIUM 5.0
CVE-2010-3700

VMware SpringSource Spring Security 2.x before 2.0.6 and 3.x before 3.0.4, and Acegi Security 1.0.0 through 1.0.7, as used in IBM WebSphere Applicati…

Mitigation only
Fix from $1,600 2010-10-29
Module Activex Controls MEDIUM 5.0
CVE-2010-2584

The Upload method in the RealPage Module Upload ActiveX control in Realpage.dll 1.0.0.9 in RealPage Module ActiveX Controls does not properly restric…

Mitigation only
Fix from $1,600 2010-10-26
TYPO3 HIGH 7.1
CVE-2010-3714EPSS 25%

The jumpUrl (aka access tracking) implementation in tslib/class.tslib_fe.php in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4…

Patch available
Fix from $1,950 2010-10-25
TYPO3 MEDIUM 5.0
CVE-2010-3717

The t3lib_div::validEmail function in TYPO3 4.2.x before 4.2.15, 4.3.x before 4.3.7, and 4.4.x before 4.4.4 does not properly restrict input to filte…

Mitigation only
Fix from $1,600 2010-10-25
Opera Browser HIGH 9.3
CVE-2010-4045

Opera before 10.63 does not properly restrict web script in unspecified circumstances involving reloads and redirects, which allows remote attackers …

Fix: after 10.62
Fix from $1,950 2010-10-21
Firefox MEDIUM 5.8
CVE-2010-3178

Mozilla Firefox before 3.5.14 and 3.6.x before 3.6.11, Thunderbird before 3.0.9 and 3.1.x before 3.1.5, and SeaMonkey before 2.0.9 do not properly ha…

Fix: after 3.5.13
Fix from $1,600 2010-10-21
Pyftpdlib MEDIUM 6.5
CVE-2007-6741

The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address ma…

Fix: after 0.1.1
Fix from $1,600 2010-10-19
Businessobjects HIGH 9.0
CVE-2010-3983

CmcApp in SAP BusinessObjects Enterprise XI 3.2 allows remote authenticated users to gain privileges via vectors involving the Program Job Server and…

No fix yet
Fix from $1,950 2010-10-18
Blackberry Device Software MEDIUM 6.8
CVE-2010-3934

The browser in Research In Motion (RIM) BlackBerry Device Software 5.0.0.593 Platform 5.1.0.147 on the BlackBerry 9700 does not properly restrict cro…

No fix yet
Fix from $1,600 2010-10-14
Windows 2003 Server HIGH 7.2
CVE-2010-2741

The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 performs an incorrect integer calculation during font p…

Mitigation only
Fix from $1,950 2010-10-13
Windows 2003 Server HIGH 7.2
CVE-2010-2744

The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R…

No fix yet
Fix from $1,950 2010-10-13
Windows 2003 Server HIGH 7.2
CVE-2010-2740

The OpenType Font (OTF) format driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly perform memory allocation during font…

Mitigation only
Fix from $1,950 2010-10-13
Pl\/php MEDIUM 6.0
CVE-2010-3781

The PL/php add-on 1.4 and earlier for PostgreSQL does not properly protect script execution by a different SQL user identity within the same session,…

Fix: after 1.4
Fix from $1,600 2010-10-06
Dovecot MEDIUM 5.5
CVE-2010-3706

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission…

Mitigation only
Fix from $1,600 2010-10-06
Dovecot MEDIUM 5.5
CVE-2010-3707

plugins/acl/acl-backend-vfile.c in Dovecot 1.2.x before 1.2.15 and 2.0.x before 2.0.5 interprets an ACL entry as a directive to add to the permission…

Mitigation only
Fix from $1,600 2010-10-06