Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
PostgreSQL MEDIUM 6.0
CVE-2010-3433

The PL/perl and PL/Tcl implementations in PostgreSQL 7.4 before 7.4.30, 8.0 before 8.0.26, 8.1 before 8.1.22, 8.2 before 8.2.18, 8.3 before 8.3.12, 8…

Patch available
Fix from $1,600 2010-10-06
Bind MEDIUM 5.0
CVE-2010-0218

ISC BIND 9.7.2 through 9.7.2-P1 uses an incorrect ACL to restrict the ability of Recursion Desired (RD) queries to access the cache, which allows rem…

Patch available
Fix from $1,600 2010-10-05
Db2 HIGH 7.2
CVE-2010-3733

The Engine Utilities component in IBM DB2 UDB 9.5 before FP6a uses world-writable permissions for the sqllib/cfg/db2sprf file, which might allow loca…

Mitigation only
Fix from $1,950 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3734

The Install component in IBM DB2 UDB 9.5 before FP6a on Linux, UNIX, and Windows enforces an unintended limit on password length, which makes it easi…

Mitigation only
Fix from $1,600 2010-10-05
Db2 MEDIUM 5.0
CVE-2010-3738

The Security component in IBM DB2 UDB 9.5 before FP6a logs AUDIT events by using a USERID and an AUTHID value corresponding to the instance owner, in…

Mitigation only
Fix from $1,600 2010-10-05
Dovecot MEDIUM 6.4
CVE-2010-3304

The ACL plugin in Dovecot 1.2.x before 1.2.13 propagates INBOX ACLs to newly created mailboxes in certain configurations, which might allow remote at…

Patch available
Fix from $1,600 2010-09-24
Primitive Cms HIGH 7.5
CVE-2010-3483

cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct …

No fix yet
Fix from $1,950 2010-09-22
Drupal MEDIUM 5.5
CVE-2010-3092

The upload module in Drupal 5.x before 5.23 and 6.x before 6.18 does not properly support case-insensitive filename handling in a database configurat…

Patch available
Fix from $1,600 2010-09-21
Db2 MEDIUM 5.0
CVE-2010-3474

IBM DB2 9.7 before FP3 does not perform the expected drops or invalidations of dependent functions upon a loss of privileges by the functions' owners…

Mitigation only
Fix from $1,600 2010-09-20
Filenet P8 Application Engine MEDIUM 6.4
CVE-2009-5002

The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 4.0.2.x before 4.0.2.1-P8AE-FP001 does not record Get Content Failure Au…

Mitigation only
Fix from $1,600 2010-09-20
Cvs Suite HIGH 9.3
CVE-2010-1326EPSS 5%

perms.cpp in March Hare Software CVSNT 2.0.58, 2.5.01, 2.5.02, 2.5.03 before build 3736, 2.5.04 before build 2862; CVS Suite 2.5.03, 2008 before buil…

Mitigation only
Fix from $1,950 2010-09-15
Tortoisesvn HIGH 9.3
CVE-2010-3199

Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbi…

Fix: after 1.6.10
Fix from $1,950 2010-09-10
Safari MEDIUM 6.9
CVE-2010-1805

Untrusted search path vulnerability in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2 on Windows allows local users to gain privileges via a Troj…

Patch available
Fix from $1,600 2010-09-10
Wireless Lan Controller Software HIGH 9.0
CVE-2010-2843

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and …

Patch available
Fix from $1,950 2010-09-10
Wireless Lan Controller Software HIGH 9.0
CVE-2010-3033

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and …

Patch available
Fix from $1,950 2010-09-10
Wireless Lan Controller Software MEDIUM 5.0
CVE-2010-3034

Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller …

Patch available
Fix from $1,600 2010-09-10
Wireless Lan Controller Software MEDIUM 5.0
CVE-2010-0575

Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller …

Patch available
Fix from $1,600 2010-09-10
Wireless Lan Controller Software HIGH 9.0
CVE-2010-2842

Cisco Wireless LAN Controller (WLC) software, possibly 4.2 through 6.0, allows remote authenticated users to bypass intended access restrictions and …

Patch available
Fix from $1,950 2010-09-10
Firefox MEDIUM 6.8
CVE-2010-2762

The XPCSafeJSObjectWrapper class in the SafeJSObjectWrapper (aka SJOW) implementation in Mozilla Firefox 3.6.x before 3.6.9 and Thunderbird 3.1.x bef…

Mitigation only
Fix from $1,600 2010-09-09
Power Manager HIGH 7.2
CVE-2006-7240

gnome-power-manager 2.14.0 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or …

Mitigation only
Fix from $1,950 2010-09-07
Xfce HIGH 7.2
CVE-2009-4996

Xfce4-session 4.5.91 in Xfce does not lock the screen when the suspend or hibernate button is pressed, which might make it easier for physically prox…

Mitigation only
Fix from $1,950 2010-09-07
Power Manager HIGH 7.2
CVE-2009-4997

gnome-power-manager 2.27.92 does not properly implement the lock_on_suspend and lock_on_hibernate settings for locking the screen when the suspend or…

Mitigation only
Fix from $1,950 2010-09-07
Opensuse HIGH 7.2
CVE-2010-2532

lxsession-logout in lxsession in LXDE, as used on SUSE openSUSE 11.3 and other platforms, does not lock the screen when the Suspend or Hibernate butt…

Mitigation only
Fix from $1,950 2010-09-03
Db2 HIGH 7.5
CVE-2010-3194

The DB2DART program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 allows attackers to bypass intended file access restrictions via un…

Mitigation only
Fix from $1,950 2010-08-31
Db2 MEDIUM 5.0
CVE-2010-3197

IBM DB2 9.7 before FP2 does not perform the expected access control on the monitor administrative views in the SYSIBMADM schema, which allows remote …

Mitigation only
Fix from $1,600 2010-08-31
Seil\/x1 Firmware MEDIUM 5.8
CVE-2010-2363

The IPv6 Unicast Reverse Path Forwarding (RPF) implementation on the SEIL/X1, SEIL/X2, and SEIL/B1 routers with firmware 1.00 through 2.73, when stri…

Mitigation only
Fix from $1,600 2010-08-30
phpMyAdmin HIGH 7.5
CVE-2010-3055EPSS 15%

The configuration setup script (aka scripts/setup.php) in phpMyAdmin 2.11.x before 2.11.10.1 does not properly restrict key names in its output file,…

Patch available
Fix from $1,950 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-2784

The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor)…

Patch available
Fix from $1,600 2010-08-24
Enterprise Virtualization MEDIUM 6.6
CVE-2010-0429

libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not prop…

Patch available
Fix from $1,600 2010-08-24
Iprint HIGH 7.1
CVE-2010-3107

A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be d…

Fix: after 5.40
Fix from $1,950 2010-08-23