Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Webkit HIGH 10.0
CVE-2010-1386

page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has un…

Mitigation only
Fix from $1,950 2010-08-19
Opera Browser MEDIUM 5.0
CVE-2010-3020

The news-feed preview feature in Opera before 10.61 does not properly remove scripts, which allows remote attackers to force subscriptions to arbitra…

Fix: after 10.60
Fix from $1,600 2010-08-16
Windows 2003 Server MEDIUM 6.8
CVE-2010-1886

Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2, and Windows 7 allow local users…

Patch available
Fix from $1,600 2010-08-16
Bugzilla MEDIUM 5.0
CVE-2010-2756

Search.pm in Bugzilla 2.19.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 allows remote attackers to determine the …

Mitigation only
Fix from $1,600 2010-08-16
Windows 2003 Server HIGH 7.2
CVE-2010-1894

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly handle unspecified ex…

Mitigation only
Fix from $1,950 2010-08-11
Windows 2003 Server HIGH 7.2
CVE-2010-1895

The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, and Windows Server 2003 SP2, do not properly perform memory alloca…

Mitigation only
Fix from $1,950 2010-08-11
Iphone Os MEDIUM 6.9
CVE-2010-2973

Integer overflow in IOSurface in Apple iOS before 4.0.2 on the iPhone and iPod touch, and before 3.2.2 on the iPad, allows local users to gain privil…

No fix yet
Fix from $1,600 2010-08-05
Celerra Network Attached Storage HIGH 9.3
CVE-2010-2860

The EMC Celerra Network Attached Storage (NAS) appliance accepts external network traffic to IP addresses intended for an intranet network within the…

No fix yet
Fix from $1,950 2010-08-05
Vxworks HIGH 7.8
CVE-2010-2968

The FTP daemon in Wind River VxWorks does not close the TCP connection after a number of failed login attempts, which makes it easier for remote atta…

Fix: after 6.8
Fix from $1,950 2010-08-05
Mapserver HIGH 10.0
CVE-2010-2540

mapserv.c in mapserv in MapServer before 4.10.6 and 5.x before 5.6.4 does not properly restrict the use of CGI command-line arguments that were inten…

Fix: after 5.6.3
Fix from $1,950 2010-08-02
Hsolink HIGH 7.2
CVE-2010-1671

hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via shell metacharacters in command-line arguments, as demonstrated by the se…

Mitigation only
Fix from $1,950 2010-08-02
Hsolink HIGH 7.2
CVE-2010-2929

Untrusted search path vulnerability in hsolinkcontrol in hsolink 1.0.118 allows local users to gain privileges via a modified PATH environment variab…

Mitigation only
Fix from $1,950 2010-08-02
Bozohttpd MEDIUM 5.0
CVE-2010-2320

bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of …

Fix: after 20100617
Fix from $1,600 2010-08-02
Openldap MEDIUM 5.0
CVE-2010-0212EPSS 6%

OpenLDAP 2.4.22 allows remote attackers to cause a denial of service (crash) via a modrdn call with a zero-length RDN destination string, which is no…

Patch available
Fix from $1,600 2010-07-28
FreeBSD HIGH 7.2
CVE-2010-2693

FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to caus…

Patch available
Fix from $1,950 2010-07-13
Pagedirector Cms HIGH 7.5
CVE-2010-2685

siteadmin/adduser.php in Customer Paradigm PageDirector CMS does not properly restrict access, which allows remote attackers to bypass intended restr…

No fix yet
Fix from $1,950 2010-07-12
iOS HIGH 10.0
CVE-2010-1574

IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a comm…

Mitigation only
Fix from $1,950 2010-07-08
Advanced Management Module MEDIUM 5.0
CVE-2010-2656

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive…

Fix: after 2.48
Fix from $1,600 2010-07-08
Opera Browser HIGH 9.3
CVE-2010-2657

Opera before 10.60 on Windows and Mac OS X does not properly prevent certain double-click operations from running a program located on a web site, wh…

Fix: 10.60+
Fix from $1,950 2010-07-08
Opera Browser HIGH 9.3
CVE-2010-2666EPSS 5%

Opera before 10.54 on Windows and Mac OS X does not properly enforce permission requirements for widget filesystem access and directory selection, wh…

Fix: after 10.53
Fix from $1,950 2010-07-08
Content Services Switch 11500 HIGH 7.5
CVE-2010-1575

The Cisco Content Services Switch (CSS) 11500 with software 08.20.1.01 conveys authentication data through ClientCert-* headers but does not delete c…

No fix yet
Fix from $1,950 2010-07-06
P8 Content Engine HIGH 7.5
CVE-2010-2518

Unspecified vulnerability in the P8 Content Engine (P8CE) 4.5.1 before FP3 and the P8 Content Search Engine (P8CSE) before 4.5.0 FP3 and 4.5.1 before…

No fix yet
Fix from $1,950 2010-06-30
Asa 5580 HIGH 10.0
CVE-2009-4912

Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) complete an SSL handshake with an HTTPS client even if this …

Fix: after 8.1
Fix from $1,950 2010-06-29
Asa 5580 MEDIUM 5.0
CVE-2009-4913

The IPv6 implementation on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) exposes IP services on the "far s…

Fix: after 8.1
Fix from $1,600 2010-06-29
Bugzilla MEDIUM 5.0
CVE-2010-1204

Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive t…

Mitigation only
Fix from $1,600 2010-06-28
Netbox MEDIUM 5.0
CVE-2010-2465

The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the w…

No fix yet
Fix from $1,600 2010-06-25
Netbox MEDIUM 5.0
CVE-2010-2466

The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloadin…

No fix yet
Fix from $1,600 2010-06-25
Oblog MEDIUM 5.0
CVE-2009-4904

article.php in oBlog does not properly restrict comments, which allows remote attackers to cause a denial of service (blog spam) via a comment=new ac…

No fix yet
Fix from $1,600 2010-06-25
Iphone Os MEDIUM 5.0
CVE-2010-1751

Application Sandbox in Apple iOS before 4 on the iPhone and iPod touch does not prevent photo-library access, which might allow remote attackers to o…

Fix: 4.0+
Fix from $1,600 2010-06-22
Iphone Os MEDIUM 6.9
CVE-2010-1754

Passcode Lock in Apple iOS before 4 on the iPhone and iPod touch does not properly handle alert-based unlocks in conjunction with subsequent Remote L…

Fix: 4.0+
Fix from $1,600 2010-06-22