Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
Iphone Os MEDIUM 6.4
CVE-2010-1757

WebKit in Apple iOS before 4 on the iPhone and iPod touch does not enforce the expected boundary restrictions on content display by an IFRAME element…

Fix: 4.0+
Fix from $1,600 2010-06-22
Horde MEDIUM 5.0
CVE-2010-1638

The IMP plugin in Horde allows remote attackers to bypass firewall restrictions and use Horde as a proxy to scan internal networks via a crafted requ…

Mitigation only
Fix from $1,600 2010-06-22
Cck MEDIUM 5.0
CVE-2010-2353

The Node Reference module in Content Construction Kit (CCK) module 6.x before 6.x-2.7 for Drupal does not perform access checks for the source field …

Patch available
Fix from $1,600 2010-06-21
Cups MEDIUM 6.8
CVE-2010-0542

The _WriteProlog function in texttops.c in texttops in the Text Filter subsystem in CUPS before 1.4.4 does not check the return values of certain cal…

Fix: after 1.4.3
Fix from $1,600 2010-06-21
Safe HIGH 7.5
CVE-2010-1168

The Safe (aka Safe.pm) module before 2.25 for Perl allows context-dependent attackers to bypass intended (1) Safe::reval and (2) Safe::rdo access res…

Mitigation only
Fix from $1,950 2010-06-21
Chrome HIGH 9.3
CVE-2010-2296

The implementation of unspecified DOM methods in Google Chrome before 5.0.375.70 allows remote attackers to bypass the Same Origin Policy via unknown…

Fix: 5.0.375.70+
Fix from $1,950 2010-06-15
Open Xml File Format Converter MEDIUM 6.9
CVE-2010-1254

The installation for Microsoft Open XML File Format Converter for Mac sets insecure ACLs for the /Applications folder, which allows local users to ex…

Mitigation only
Fix from $1,600 2010-06-08
Rpm HIGH 7.2
CVE-2010-2059

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file dur…

Fix: after 4.4.2.3
Fix from $1,950 2010-06-08
Rpm MEDIUM 5.8
CVE-2010-2197

rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home direct…

Mitigation only
Fix from $1,600 2010-06-08
Rpm HIGH 7.2
CVE-2010-2198

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrad…

Mitigation only
Fix from $1,950 2010-06-08
Rpm HIGH 7.2
CVE-2010-2199

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrad…

Mitigation only
Fix from $1,950 2010-06-08
Rpm HIGH 7.2
CVE-2005-4889

lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which…

Fix: after 4.4.2.3
Fix from $1,950 2010-06-08
Dpkg HIGH 7.2
CVE-2004-2768

dpkg 1.9.21 does not properly reset the metadata of a file during replacement of the file in a package upgrade, which might allow local users to gain…

No fix yet
Fix from $1,950 2010-06-08
Sudo MEDIUM 6.2
CVE-2010-1646

The secure path feature in env.c in sudo 1.3.1 through 1.6.9p22 and 1.7.0 through 1.7.2p6 does not properly handle an environment that contains multi…

Patch available
Fix from $1,600 2010-06-07
E107 HIGH 7.5
CVE-2010-2099

bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows re…

Fix: after 0.7.20
Fix from $1,950 2010-05-27
Mediator Framework HIGH 10.0
CVE-2010-0600

Cisco Mediator Framework 1.5.1 before 1.5.1.build.14-eng, 2.2 before 2.2.1.dev.1, and 3.0 before 3.0.9.release.1 on the Cisco Network Building Mediat…

Patch available
Fix from $1,950 2010-05-27
Talkback MEDIUM 6.4
CVE-2009-4874

TalkBack 2.3.14 does not properly restrict access to the edit comment feature (comments.php), which allows remote attackers to modify comments.

No fix yet
Fix from $1,600 2010-05-26
Netrix Cms MEDIUM 5.0
CVE-2009-4876

admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.

No fix yet
Fix from $1,600 2010-05-26
Cybozu Office MEDIUM 5.8
CVE-2010-2029

Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtai…

Mitigation only
Fix from $1,600 2010-05-24
PostgreSQL MEDIUM 6.0
CVE-2010-1170

The PL/Tcl implementation in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, 8.4 before 8.4…

Patch available
Fix from $1,600 2010-05-19
PostgreSQL HIGH 8.5
CVE-2010-1447

The Safe (aka Safe.pm) module 2.26, and certain earlier versions, for Perl, as used in PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.…

Patch available
Fix from $1,950 2010-05-19
PostgreSQL MEDIUM 5.5
CVE-2010-1975

PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly chec…

Mitigation only
Fix from $1,600 2010-05-19
Kget MEDIUM 6.4
CVE-2010-1511

KGet 2.4.2 in KDE SC 4.0.0 through 4.4.3 does not properly request download confirmation from the user, which makes it easier for remote attackers to…

Mitigation only
Fix from $1,600 2010-05-17
MySQL MEDIUM 5.0
CVE-2010-1621

The mysql_uninstall_plugin function in sql/sql_plugin.cc in MySQL 5.1 before 5.1.46 does not check privileges before uninstalling a plugin, which all…

Fix: after 5.1.45
Fix from $1,600 2010-05-14
Wysiwyg Editor HIGH 7.5
CVE-2010-1916

The dynamic configuration feature in Xinha WYSIWYG editor 0.96 Beta 2 and earlier, as used in Serendipity 1.5.2 and earlier, allows remote attackers …

No fix yet
Fix from $1,950 2010-05-12
Consona Dynamic Agent HIGH 9.3
CVE-2010-1908

The SdcUser.TgConCtl ActiveX control in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance does not properly restrict a…

Patch available
Fix from $1,950 2010-05-12
Consona Dynamic Agent HIGH 9.3
CVE-2010-1912EPSS 5%

The SdcWebSecureBase interface in tgctlcm.dll in Consona Live Assistance, Dynamic Agent, and Subscriber Assistance allows remote attackers to bypass …

Patch available
Fix from $1,950 2010-05-12
Xoops MEDIUM 5.0
CVE-2009-4851

The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, whic…

Fix: after 2.4.0
Fix from $1,600 2010-05-07
Krm Haber MEDIUM 5.0
CVE-2010-1736

KrM Haber 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database …

No fix yet
Fix from $1,600 2010-05-06
Openttd MEDIUM 6.5
CVE-2010-0401

OpenTTD before 1.0.1 accepts a company password for authentication in response to a request for the server password, which allows remote authenticate…

Fix: after 1.0.0
Fix from $1,600 2010-05-05