Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2009-2669 A certain debugging component in IBM AIX 5.3 and 6.1 does not properly handle the (1) _LIB_INIT_DBG and (2) _LIB_INIT_DBG_FILE environment variables,… Aix Patch available Fix from $1,9502009-08-05 MEDIUM 5.0 CVE-2008-6886 RSA EnVision 3.5.0, 3.5.1, 3.5.2, and 3.7.0 does not properly restrict access to unspecified user profile functionality, which allows remote attacker… Envision Patch available Fix from $1,6002009-08-03 HIGH 9.3 CVE-2009-1863EPSS 6% Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a … Air after 10.0.22.87 Fix from $1,9502009-07-31 MEDIUM 5.0 CVE-2009-2648 FlashDen Guestbook allows remote attackers to obtain configuration information via a direct request to amfphp/phpinfo.php, which calls the phpinfo fu… Guestbook No fix yet Fix from $1,6002009-07-30 HIGH 8.8 CVE-2009-2493EPSS 38% The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and… Visual C\+\+ Patch available Fix from $1,9502009-07-29 MEDIUM 5.0 CVE-2009-2602 R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, which allows remote attackers to… R2 Newsletter Lite No fix yet Fix from $1,6002009-07-27 MEDIUM 5.0 CVE-2009-2606 ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Asp Football Pool No fix yet Fix from $1,6002009-07-27 MEDIUM 5.0 CVE-2008-6870 Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information via a direct request to (1) c… Educate Server No fix yet Fix from $1,6002009-07-23 MEDIUM 5.0 CVE-2008-6871 Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers to obtain unspecified sensitiv… Educate Server No fix yet Fix from $1,6002009-07-23 MEDIUM 5.0 CVE-2008-6869EPSS 6% Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote at… Oramon No fix yet Fix from $1,6002009-07-23 MEDIUM 6.5 CVE-2009-2574 index.php in MiniTwitter 0.2 beta allows remote authenticated users to modify certain options of arbitrary accounts via an opt action. Minitwitter No fix yet Fix from $1,6002009-07-22 HIGH 7.5 CVE-2009-2558 system/message.php in Admin News Tools 2.5 does not properly restrict access, which allows remote attackers to post news messages via a direct reques… Admin News Tools No fix yet Fix from $1,9502009-07-21 HIGH 7.2 CVE-2009-2564EPSS 6% NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.… Getplus Download Manager No fix yet Fix from $1,9502009-07-21 MEDIUM 6.9 CVE-2009-2482 The pam_unix module in OpenPAM in NetBSD 4.0 before 4.0.2 and 5.0 before 5.0.1 allows local users to change the current root password if it is alread… Netbsd Mitigation only Fix from $1,6002009-07-16 HIGH 9.0 CVE-2009-1135EPSS 26% Microsoft Internet Security and Acceleration (ISA) Server 2006 Gold and SP1, when Radius OTP is enabled, uses the HTTP-Basic authentication method, w… Isa Server Mitigation only Fix from $1,9502009-07-15 HIGH 9.0 CVE-2009-1542EPSS 8% The Virtual Machine Monitor (VMM) in Microsoft Virtual PC 2004 SP1, 2007, and 2007 SP1, and Microsoft Virtual Server 2005 R2 SP1, does not enforce CP… Virtual Pc Mitigation only Fix from $1,9502009-07-15 HIGH 7.2 CVE-2009-2461 mathtex.cgi in mathTeX, when downloaded before 20090713, does not securely create temporary files, which has unspecified impact and local attack vect… Mathtex after 1.02 Fix from $1,9502009-07-14 HIGH 7.5 CVE-2009-2453 Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Adva… Presentation Server Patch available Fix from $1,9502009-07-14 MEDIUM 5.0 CVE-2009-2443 Siteframe 3.2.3, and other 3.2.x versions, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which cal… Siteframe Cms Patch available Fix from $1,6002009-07-13 MEDIUM 5.0 CVE-2009-2432 WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals… WordPress after 2.7.1 Fix from $1,6002009-07-10 MEDIUM 6.5 CVE-2009-2393 admin/index.php in Virtuenetz Virtue Online Test Generator does not require administrative privileges, which allows remote authenticated users to hav… Virtue Online Test Generator No fix yet Fix from $1,6002009-07-09 MEDIUM 6.5 CVE-2009-2371 Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has… Advanced Forum Patch available Fix from $1,6002009-07-08 HIGH 9.0 CVE-2009-2344EPSS 9% The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges … 3d Sensor after 4.8.1 Fix from $1,9502009-07-07 MEDIUM 6.4 CVE-2009-0904 The IBM Stax XMLStreamWriter in the Web Services component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.25 does not properly process XM… Websphere Application Server Mitigation only Fix from $1,6002009-07-05 HIGH 7.5 CVE-2008-6844 The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1, and 4.0.1, allows remote at… Ez Publish after 3.5.6 Fix from $1,9502009-07-02 HIGH 7.5 CVE-2009-2306 The ARD-9808 DVR card security camera stores sensitive information under the web root with insufficient access control, which allows remote attackers… Ard 9808 Software No fix yet Fix from $1,9502009-07-02 MEDIUM 6.8 CVE-2009-2291 Unspecified vulnerability in LoginToboggan 6.x-1.x before 6.x-1.5, a module for Drupal, when "Allow users to login using their e-mail address" is ena… Logintoboggan Patch available Fix from $1,6002009-07-01 HIGH 7.5 CVE-2009-2293 Optimum Web Design Tutorial Share 3.5.0 and earlier allows remote attackers to bypass authentication and obtain administrative access by setting the … Tutorial Share after 3.5.0 Fix from $1,9502009-07-01 MEDIUM 5.8 CVE-2009-1888 The acl_group_override function in smbd/posix_acls.c in smbd in Samba 3.0.x before 3.0.35, 3.1.x and 3.2.x before 3.2.13, and 3.3.x before 3.3.6, whe… Debian Linux 3.2.13 / 3.3.6+ Fix from $1,6002009-06-25 MEDIUM 5.0 CVE-2009-2160 TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpinfo.php, which calls the phpin… Torrenttrader Classic No fix yet Fix from $1,6002009-06-22