Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2009-3122 The Ajax Table module 5.x for Drupal does not perform access control, which allows remote attackers to delete arbitrary users and nodes via unspecifi… Ajaxtable Mitigation only Fix from $1,6002009-09-09 MEDIUM 5.0 CVE-2008-7186 Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as t… Coppermine Photo Gallery Patch available Fix from $1,6002009-09-09 HIGH 7.5 CVE-2008-7188 ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the profile of arbitrary users via … Clipshare No fix yet Fix from $1,9502009-09-09 HIGH 7.2 CVE-2009-3108 The Aclient GUI in Symantec Altiris Deployment Solution 6.9.x before 6.9 SP3 Build 430 installs a client executable with insecure permissions (Everyo… Altiris Deployment Solution Mitigation only Fix from $1,9502009-09-08 MEDIUM 5.0 CVE-2009-3106 The Servlet Engine/Web Container component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.37 does not properly implement security const… Websphere Application Server Patch available Fix from $1,6002009-09-08 HIGH 7.5 CVE-2008-7167 Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbitrary code by uploading a file… Page Manager No fix yet Fix from $1,9502009-09-08 HIGH 10.0 CVE-2008-7170EPSS 10% GSC build 2067 and earlier relies on the client to enforce administrator privileges, which allows remote attackers to execute arbitrary administrator… Gsc No fix yet Fix from $1,9502009-09-08 HIGH 7.5 CVE-2008-7172 Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote attackers to gain administra… Lightweight News Portal No fix yet Fix from $1,9502009-09-08 HIGH 10.0 CVE-2008-7173 The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remot… Internet Connectivity Kit Mitigation only Fix from $1,9502009-09-08 HIGH 7.5 CVE-2008-7181 Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with t… Butterfly Organizer No fix yet Fix from $1,9502009-09-08 HIGH 9.3 CVE-2009-3068EPSS 78% Unrestricted file upload vulnerability in the RoboHelpServer Servlet (robohelp/server) in Adobe RoboHelp Server 8 allows remote attackers to execute … Robohelp Server No fix yet Fix from $1,9502009-09-04 HIGH 7.5 CVE-2008-7161EPSS 6% Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reque… Fortigate 1000 No fix yet Fix from $1,9502009-09-04 HIGH 7.5 CVE-2008-7155 NetRisk 1.9.7 does not properly restrict access to admin/change_submit.php, which allows remote attackers to change the password of arbitrary users v… Netrisk No fix yet Fix from $1,9502009-09-02 MEDIUM 6.8 CVE-2008-7157 Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code by uploading an avatar file w… Ekinboard after 1.1.0 Fix from $1,6002009-09-02 HIGH 7.5 CVE-2009-3041EPSS 7% SPIP 1.9 before 1.9.2i and 2.0.x through 2.0.8 does not use proper access control for (1) ecrire/exec/install.php and (2) ecrire/index.php, which all… Spip Patch available Fix from $1,9502009-09-01 HIGH 7.5 CVE-2008-7128 The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which… Xyssl after 0.8 Fix from $1,9502009-08-31 HIGH 9.3 CVE-2008-7111 The Scanner File Utility (aka listener) in Kyocera Mita (KM) 3.3.0.1 does not restrict the filenames or extensions of uploaded files, which makes it … Scanner File Utility Mitigation only Fix from $1,9502009-08-28 HIGH 10.0 CVE-2008-7115 The web interface to the Belkin Wireless G router and ADSL2 modem F5D7632-4V6 with firmware 6.01.08 allows remote attackers to bypass authentication … F5d7632 4 No fix yet Fix from $1,9502009-08-28 MEDIUM 5.0 CVE-2008-7117 eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) files via a certain request with … Webid No fix yet Fix from $1,6002009-08-28 MEDIUM 5.0 CVE-2008-7118 WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain … Webid No fix yet Fix from $1,6002009-08-28 MEDIUM 6.9 CVE-2008-7096 Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local … Bios Patch available Fix from $1,6002009-08-27 HIGH 7.8 CVE-2008-7095 The SNMP daemon in ArubaOS 3.3.2.6 in Aruba Mobility Controller does not restrict SNMP access, which allows remote attackers to (1) read all SNMP com… Aruba Mobility Controller Mitigation only Fix from $1,9502009-08-27 HIGH 10.0 CVE-2009-2935EPSS 5% Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain… Chrome after 2.0.172.37 Fix from $1,9502009-08-27 HIGH 7.5 CVE-2009-2960 CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords… Cuteflow No fix yet Fix from $1,9502009-08-25 MEDIUM 6.8 CVE-2008-7062EPSS 7% Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows remote attackers to execute a… Lovecms No fix yet Fix from $1,6002009-08-25 HIGH 7.5 CVE-2008-7066 OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct request with the update paramete… Openforum No fix yet Fix from $1,9502009-08-25 MEDIUM 6.5 CVE-2008-7076 Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows remote authenticated users to ex… Stararticles No fix yet Fix from $1,6002009-08-25 MEDIUM 5.0 CVE-2008-7080EPSS 8% Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob… Php Classifieds Script No fix yet Fix from $1,6002009-08-25 MEDIUM 5.0 CVE-2008-7056 BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a… Bandsite Cms No fix yet Fix from $1,6002009-08-24 MEDIUM 6.8 CVE-2008-7024 admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain administrator privileges by … Gemini Lite No fix yet Fix from $1,6002009-08-21