Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2010-0752 The week_post_page function in the Weekly Archive by Node Type module 6.x before 6.x-2.7 for Drupal does not properly implement node access restricti… Week Patch available Fix from $1,6002010-02-27 HIGH 7.5 CVE-2010-0011 The eval_js function in uzbl-core.c in Uzbl before 2010.01.05 exposes the run method of the Uzbl object, which allows remote attackers to execute arb… Uzbl after 2009.12.22 Fix from $1,9502010-02-25 MEDIUM 6.9 CVE-2010-0426 sudo 1.6.x before 1.6.9p21 and 1.7.x before 1.7.2p4, when a pseudo-command is enabled, permits a match between the name of the pseudo-command and the… Sudo Patch available Fix from $1,6002010-02-24 MEDIUM 5.0 CVE-2010-0681 ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive infor… Zeuscms No fix yet Fix from $1,6002010-02-22 MEDIUM 5.0 CVE-2010-0674 StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a databas… Statcountex No fix yet Fix from $1,6002010-02-22 MEDIUM 5.0 CVE-2009-3988 Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly restrict read access to object properties i… Firefox after 3.0.17 Fix from $1,6002010-02-22 MEDIUM 5.0 CVE-2010-0665 JAG (Just Another Guestbook) 1.14 stores sensitive information under the web root with insufficient access control, which allows remote attackers to … Jag No fix yet Fix from $1,6002010-02-19 HIGH 7.2 CVE-2009-4648 Accellion Secure File Transfer Appliance before 8_0_105 does not properly restrict access to sensitive commands and arguments that run with extra sud… Secure File Transfer Appliance No fix yet Fix from $1,9502010-02-19 MEDIUM 6.8 CVE-2010-0661 WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypa… Chrome after 4.0.249.0 Fix from $1,6002010-02-18 HIGH 7.5 CVE-2010-0288EPSS 11% A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers … Dokuwiki No fix yet Fix from $1,9502010-02-15 MEDIUM 6.5 CVE-2010-0298 The x86 emulator in KVM 83 does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) in determining the memory access available t… Linux Kernel after 2.6.33 Fix from $1,6002010-02-12 MEDIUM 6.9 CVE-2010-0023 The Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly kill processes afte… Windows 2000 Mitigation only Fix from $1,6002010-02-10 HIGH 10.0 CVE-2010-0231EPSS 41% The SMB implementation in the Server service in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1,… Windows 2000 Mitigation only Fix from $1,9502010-02-10 MEDIUM 6.8 CVE-2010-0443 Unspecified vulnerability in Record Management Services (RMS) before VMS83A_RMS-V1100 for HP OpenVMS on the Alpha platform allows local users to gain… Openvms Rms Patch available Fix from $1,6002010-02-04 MEDIUM 6.9 CVE-2010-0301 main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's hom… Maildrop after 2.3.0 Fix from $1,6002010-02-04 MEDIUM 5.0 CVE-2009-3387 Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a differen… Bugzilla Patch available Fix from $1,6002010-02-03 MEDIUM 5.0 CVE-2010-0185 The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows re… Coldfusion Mitigation only Fix from $1,6002010-02-03 HIGH 7.5 CVE-2010-0005 query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might … Viewvc after 1.1.2 Fix from $1,9502010-01-29 HIGH 8.5 CVE-2010-0142 MeetingTime in Cisco Unified MeetingPlace 6 before MR5, and possibly 5, allows remote authenticated users to gain privileges via a modified authentic… Unified Meetingplace Patch available Fix from $1,9502010-01-28 MEDIUM 5.0 CVE-2010-0380 install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictions and modify application set… Php Calendars Script No fix yet Fix from $1,6002010-01-22 HIGH 7.5 CVE-2010-0230 SUSE Linux Enterprise 10 SP3 (SLE10-SP3) and openSUSE 11.2 configures postfix to listen on all network interfaces, which might allow remote attackers… Opensuse Mitigation only Fix from $1,9502010-01-22 HIGH 10.0 CVE-2008-7251 libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack… phpMyAdmin Mitigation only Fix from $1,9502010-01-19 MEDIUM 6.9 CVE-2010-0318 The replay functionality for ZFS Intent Log (ZIL) in FreeBSD 7.1, 7.2, and 8.0, when creating files during replay of a setattr transaction, uses 7777… FreeBSD Patch available Fix from $1,6002010-01-15 HIGH 7.2 CVE-2010-0184 The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveM… Runtime Agent after 5.6.1 Fix from $1,9502010-01-14 MEDIUM 6.8 CVE-2010-0310 Trusted Extensions in Sun Solaris 10 allows local users to gain privileges via vectors related to omission of unspecified libraries from software upd… Solaris Patch available Fix from $1,6002010-01-14 HIGH 7.2 CVE-2009-4606 South River Technologies WebDrive 9.02 build 2232 installs the WebDrive Service without a security descriptor, which allows local users to (1) stop t… Webdrive Mitigation only Fix from $1,9502010-01-13 HIGH 7.2 CVE-2009-4607 The command line interface in Overland Storage Snap Server 410 with GuardianOS 5.1.041 runs the "less" utility with a higher-privileged uid than the … Snap Server 410 Mitigation only Fix from $1,9502010-01-13 MEDIUM 5.0 CVE-2009-4585 UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… Uranyumsoft Listing Service No fix yet Fix from $1,6002010-01-06 HIGH 7.2 CVE-2009-4556 Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product f… Antivirus Plus 2009 Mitigation only Fix from $1,9502010-01-04 MEDIUM 5.0 CVE-2009-4558 The Image Assist module 5.x-1.x before 5.x-1.8, 5.x-2.x before 2.0-alpha4, 6.x-1.x before 6.x-1.1, 6.x-2.x before 2.0-alpha4, and 6.x-3.x-dev before … Img Assist Patch available Fix from $1,6002010-01-04