Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.6 CVE-2009-3889 The dbg_lvl file for the megaraid_sas driver in the Linux kernel before 2.6.27 has world-writable permissions, which allows local users to change the… Linux Kernel after 2.6.26 Fix from $1,6002009-11-16 MEDIUM 5.0 CVE-2009-2818 Adaptive Firewall in Apple Mac OS X before 10.6.2 does not properly handle invalid usernames in SSH login attempts, which makes it easier for remote … Mac Os X Server after 10.6.1 Fix from $1,6002009-11-10 MEDIUM 5.0 CVE-2009-3880 The Abstract Window Toolkit (AWT) in Java Runtime Environment (JRE) in Sun Java SE 5.0 before Update 22 and 6 before Update 17, and OpenJDK, does not… Openjdk after 1.6.0 Fix from $1,6002009-11-09 MEDIUM 5.0 CVE-2009-3920 An administration page in the NGP COO/CWP Integration (crmngp) module 6.x before 6.x-1.12 for Drupal does not perform the expected access control, wh… Crmngp Patch available Fix from $1,6002009-11-09 HIGH 7.2 CVE-2009-3725 The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (… Linux Kernel 2.6.31.5+ Fix from $1,9502009-11-06 HIGH 7.5 CVE-2009-3904EPSS 9% classes/session/cc_admin_session.php in CubeCart 4.3.4 does not properly restrict administrative access permissions, which allows remote attackers to… Cubecart Patch available Fix from $1,9502009-11-06 MEDIUM 5.8 CVE-2009-3860 Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitrary files via the (1) CreateF… Comraider No fix yet Fix from $1,6002009-11-04 MEDIUM 6.5 CVE-2009-3298 Mahara before 1.0.13, and 1.1.x before 1.1.7, allows remote authenticated institution administrators to reset a site administrator password via unspe… Mahara after 1.0.12 Fix from $1,6002009-11-03 HIGH 7.1 CVE-2009-3722 The handle_dr function in arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 2.6.31.1 does not properly verify the Current Privilege … Linux Kernel after 2.6.31 Fix from $1,9502009-10-30 HIGH 7.5 CVE-2009-3374 The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce i… Firefox Patch available Fix from $1,9502009-10-29 HIGH 9.3 CVE-2009-3461 Unspecified vulnerability in Adobe Acrobat 9.x before 9.2 allows attackers to bypass intended file-extension restrictions via unknown vectors. Acrobat Patch available Fix from $1,9502009-10-19 MEDIUM 6.5 CVE-2009-3716 Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbitrary code by uploading a file… Mcshoutbox No fix yet Fix from $1,6002009-10-16 HIGH 7.2 CVE-2009-3281 The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privi… Fusion after 2.0.5 Fix from $1,9502009-10-16 HIGH 9.3 CVE-2009-0090EPSS 21% Microsoft .NET Framework 1.0 SP3, 1.1 SP1, and 2.0 SP1 does not properly validate .NET verifiable code, which allows remote attackers to obtain unint… Windows 2000 Mitigation only Fix from $1,9502009-10-14 HIGH 7.5 CVE-2009-3596 JoxTechnology Ajox Poll does not properly restrict access to admin/managepoll.php, which allows remote attackers to bypass authentication and gain ad… Ajox Poll No fix yet Fix from $1,9502009-10-08 MEDIUM 5.0 CVE-2009-3568 Comment RSS 5.x before 5.x-2.2 and 6.x before 6.x-2.2, a module for Drupal, does not properly enforce permissions when a link is added to the RSS fee… Commentrss Patch available Fix from $1,6002009-10-06 HIGH 7.2 CVE-2009-3525 The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows… Xen Patch available Fix from $1,9502009-10-05 MEDIUM 6.5 CVE-2009-3472 IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, inser… Db2 Mitigation only Fix from $1,6002009-09-29 MEDIUM 5.0 CVE-2009-3442 The Meta tags (aka Nodewords) module before 6.x-1.1 for Drupal does not properly follow permissions during assignment of node meta tags, which allows… Meta Tags Patch available Fix from $1,6002009-09-28 HIGH 7.2 CVE-2009-2682 Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictio… Hp Ux Patch available Fix from $1,9502009-09-24 HIGH 8.5 CVE-2009-3369 CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias… Backuppc Mitigation only Fix from $1,9502009-09-24 HIGH 9.0 CVE-2009-3258 vtiger CRM before 5.1.0 allows remote authenticated users, with certain View privileges, to delete (1) attachments, (2) reports, (3) filters, (4) vie… Vtiger Crm Mitigation only Fix from $1,9502009-09-18 MEDIUM 6.5 CVE-2009-3230 The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7… PostgreSQL Mitigation only Fix from $1,6002009-09-17 MEDIUM 6.8 CVE-2009-3207 The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly … Imagecache Patch available Fix from $1,6002009-09-16 MEDIUM 6.0 CVE-2009-2813 Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Wi… Fedora Mitigation only Fix from $1,6002009-09-14 HIGH 7.5 CVE-2008-7229 GreenSQL Firewall (greensql-fw) before 0.9.2 allows remote attackers to bypass SQL injection protection via a crafted string, possibly involving an e… Greensql Firewall Patch available Fix from $1,9502009-09-14 HIGH 10.0 CVE-2008-7219 Horde Kronolith H3 2.1 before 2.1.7 and 2.2 before 2.2-RC2; Nag H3 2.1 before 2.1.4 and 2.2 before 2.2-RC2; Mnemo H3 2.1 before 2.1.2 and H3 2.2 befo… Groupware Patch available Fix from $1,9502009-09-13 MEDIUM 6.8 CVE-2009-3182 Unrestricted file upload vulnerability in admin/editor/filemanager/browser.html in Anantasoft Gazelle CMS 1.0 allows remote attackers to execute arbi… Gazelle Cms No fix yet Fix from $1,6002009-09-11 HIGH 7.5 CVE-2008-7209EPSS 6% Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arb… Onecms after 2.4 Fix from $1,9502009-09-11 MEDIUM 5.0 CVE-2008-7212 MOStlyCE before 2.4, as used in Mambo 4.6.3 and earlier, allows remote attackers to obtain sensitive information via certain requests to mambots/edit… Mambo after 4.6.3 Fix from $1,6002009-09-11