Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2009-4545 Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a datab… Logoshows Bbs No fix yet Fix from $1,6002010-01-04 MEDIUM 5.0 CVE-2009-4515 The Storm module 6.x before 6.x-1.25 for Drupal does not enforce privilege requirements for storminvoiceitem nodes, which allows remote attackers to … Storm Patch available Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4520 The CCK Comment Reference module 5.x before 5.x-1.2 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to bypass intended access re… Commentreference after 6.x-1.2 Fix from $1,6002009-12-31 MEDIUM 5.0 CVE-2009-4526 The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drup… Print Patch available Fix from $1,6002009-12-31 MEDIUM 6.5 CVE-2009-4528 The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restricti… Og Vocab Patch available Fix from $1,6002009-12-31 HIGH 9.3 CVE-2009-4502EPSS 22% The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRe… Zabbix after 1.6.6 Fix from $1,9502009-12-31 HIGH 7.5 CVE-2009-4465 DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user and confi… Deluxebb No fix yet Fix from $1,9502009-12-30 MEDIUM 6.5 CVE-2009-4455 The default configuration of Cisco ASA 5500 Series Adaptive Security Appliance (Cisco ASA) 7.0, 7.1, 7.2, 8.0, 8.1, and 8.2 allows portal traffic to … Adaptive Security Appliance 5500 Mitigation only Fix from $1,6002009-12-29 MEDIUM 6.8 CVE-2009-4452 Kaspersky Anti-Virus 5.0 (5.0.712); Antivirus Personal 5.0.x; Anti-Virus 6.0 (6.0.3.837), 7 (7.0.1.325), 2009 (8.0.0.x), and 2010 (9.0.0.463); and In… Kaspersky Anti Virus No fix yet Fix from $1,6002009-12-29 MEDIUM 6.5 CVE-2009-4438 The Query Compiler, Rewrite, and Optimizer component in IBM DB2 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not enforce privilege require… Db2 Patch available Fix from $1,6002009-12-28 MEDIUM 5.0 CVE-2009-4417 The shutdown function in the Zend_Log_Writer_Mail class in Zend Framework (ZF) allows context-dependent attackers to send arbitrary e-mail messages t… Framework after 1.9.6 Fix from $1,6002009-12-24 HIGH 7.2 CVE-2009-4331 The Install component in IBM DB2 9.5 before FP5 and 9.7 before FP1 configures the High Availability (HA) scripts with incorrect file-permission and a… Db2 Patch available Fix from $1,9502009-12-16 MEDIUM 5.0 CVE-2009-4299 mod/glossary/showentry.php in the Glossary module for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not properly perform access control, which a… Moodle Patch available Fix from $1,6002009-12-16 MEDIUM 6.0 CVE-2009-4301 mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remo… Moodle Patch available Fix from $1,6002009-12-16 HIGH 7.2 CVE-2009-4131 The EXT4_IOC_MOVE_EXT (aka move extents) ioctl implementation in the ext4 filesystem in the Linux kernel before 2.6.32-git6 allows local users to ove… Linux Kernel after 2.6.32 Fix from $1,9502009-12-13 HIGH 7.5 CVE-2009-4262 Harold Bakker's NewsScript (HB-NS) 1.3 allows remote attackers to obtain access to the admin control panel via a direct request to admin.php. Hb Ns No fix yet Fix from $1,9502009-12-10 MEDIUM 6.9 CVE-2009-4033 A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users t… Acpid Mitigation only Fix from $1,6002009-12-08 MEDIUM 6.9 CVE-2009-4235 acpid 1.0.4 sets an unrestrictive umask, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive informati… Acpid Patch available Fix from $1,6002009-12-08 HIGH 7.2 CVE-2009-4215 Panda Global Protection 2010, Internet Security 2010, and Antivirus Pro 2010 use weak permissions (Everyone: Full Control) for the product files, whi… Panda Antivirus Patch available Fix from $1,9502009-12-07 HIGH 7.5 CVE-2009-4222 phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote attackers to obtain access to t… Phpbazar after 2.1.1 Fix from $1,9502009-12-07 HIGH 9.3 CVE-2009-4211 The U.S. Defense Information Systems Agency (DISA) Security Readiness Review (SRR) script for the Solaris x86 platform executes files in arbitrary di… Srr For Solaris Mitigation only Fix from $1,9502009-12-04 MEDIUM 6.8 CVE-2009-2631 Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate; Cisco ASA; SonicWALL E-Class SSL VPN and SonicWALL SSL … Adaptive Security Appliance Mitigation only Fix from $1,6002009-12-04 HIGH 7.2 CVE-2009-4147 The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear the (1) LD_LIBMAP, (2) LD_LIBR… FreeBSD Patch available Fix from $1,9502009-12-02 MEDIUM 6.0 CVE-2009-4174 The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with… Cutenews No fix yet Fix from $1,6002009-12-02 HIGH 7.2 CVE-2009-4146 The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not clear the LD_PRELOAD environme… FreeBSD Patch available Fix from $1,9502009-12-02 HIGH 9.0 CVE-2009-4112EPSS 11% Cacti 0.8.7e and earlier allows remote authenticated administrators to gain privileges by modifying the "Data Input Method" for the "Linux - Get Memo… Cacti after 0.8.7e Fix from $1,9502009-11-30 MEDIUM 5.0 CVE-2009-4091EPSS 7% comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments vi… Simplog No fix yet Fix from $1,6002009-11-29 HIGH 10.0 CVE-2009-3843EPSS 79% HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to condu… Operations Manager Mitigation only Fix from $1,9502009-11-24 HIGH 7.5 CVE-2009-4044 The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API … Web Services Mitigation only Fix from $1,9502009-11-20 HIGH 7.5 CVE-2009-3949 cp/profile.php in VivaPrograms Infinity 2.0.5 and earlier does not require administrative authentication for the donewauthor action, which allows rem… Infinity Script after 2.0.5 Fix from $1,9502009-11-16