Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2009-2075 Nodequeue 5.x before 5.x-2.7 and 6.x before 6.x-2.2, a module for Drupal, does not properly restrict access when displaying node titles, which has un… Nodequeue Patch available Fix from $1,9502009-06-16 HIGH 7.5 CVE-2009-2080 admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration in… The Ticket System No fix yet Fix from $1,9502009-06-16 MEDIUM 5.4 CVE-2009-1839EPSS 7% Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote… Firefox after 3.0.10 Fix from $1,6002009-06-12 HIGH 9.3 CVE-2009-1840 Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows … Firefox after 3.0.10 Fix from $1,9502009-06-12 HIGH 7.2 CVE-2009-2027 The Installer in Apple Safari before 4.0 on Windows allows local users to gain privileges by checking a box that specifies an immediate launch of the… Safari after 3.2.3 Fix from $1,9502009-06-10 HIGH 9.0 CVE-2009-0230EPSS 35% The Windows Print Spooler in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 allows remote… Windows 2000 Mitigation only Fix from $1,9502009-06-10 HIGH 10.0 CVE-2009-0568EPSS 32% The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 do… Windows 2000 Mitigation only Fix from $1,9502009-06-10 MEDIUM 5.0 CVE-2009-2022EPSS 5% fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the dat… Fipscms Light No fix yet Fix from $1,6002009-06-09 MEDIUM 5.0 CVE-2009-2024 Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow… Asp Vt Auth No fix yet Fix from $1,6002009-06-09 HIGH 7.5 CVE-2009-2025 admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) … Dm Filemanager No fix yet Fix from $1,9502009-06-09 MEDIUM 5.0 CVE-2009-1941 PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to down… Pad Site Scripts No fix yet Fix from $1,6002009-06-05 HIGH 10.0 CVE-2004-2764 Sun SDK and Java Runtime Environment (JRE) 1.4.2 through 1.4.2_04, 1.4.1 through 1.4.1_07, and 1.4.0 through 1.4.0_04 allows untrusted applets and un… Jre Mitigation only Fix from $1,9502009-06-02 MEDIUM 5.0 CVE-2009-1821 DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to … Registration Manager No fix yet Fix from $1,6002009-05-29 MEDIUM 5.0 CVE-2009-1767 admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrar… Template Monster Clone No fix yet Fix from $1,6002009-05-22 HIGH 7.5 CVE-2009-1771 index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to c… Flyspeck Cms No fix yet Fix from $1,9502009-05-22 HIGH 7.5 CVE-2009-1752 exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain … Office Message System No fix yet Fix from $1,9502009-05-22 HIGH 7.5 CVE-2009-1594 Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows re… Profense Web Application Firewall after 2.2.21 Fix from $1,9502009-05-21 MEDIUM 6.4 CVE-2009-1665 myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter wi… Answer And Question Script No fix yet Fix from $1,6002009-05-18 HIGH 7.5 CVE-2009-1652EPSS 6% admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and ad… Business Community Script No fix yet Fix from $1,9502009-05-16 MEDIUM 6.4 CVE-2009-1637 profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address a… Simple Customer No fix yet Fix from $1,6002009-05-15 HIGH 7.5 CVE-2009-1610EPSS 6% admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator pri… Job Script Job Board Software No fix yet Fix from $1,9502009-05-11 HIGH 9.3 CVE-2009-0194 The domain-locking implementation in the GARMINAXCONTROL.GarminAxControl_t.1 ActiveX control in npGarmin.dll in the Garmin Communicator Plug-In 2.6.4… Garmin Communicator Plugin Mitigation only Fix from $1,9502009-05-11 HIGH 9.3 CVE-2009-1597 Mozilla Firefox executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline … Firefox No fix yet Fix from $1,9502009-05-11 HIGH 9.3 CVE-2009-1599 Opera executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, … Opera Browser Mitigation only Fix from $1,9502009-05-11 HIGH 9.3 CVE-2009-1600 Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF… Safari Mitigation only Fix from $1,9502009-05-11 MEDIUM 6.8 CVE-2009-1601 The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working director… Linux Patch available Fix from $1,6002009-05-11 HIGH 7.5 CVE-2008-6799 connection.php in FlashChat 5.0.8 allows remote attackers to bypass the role filter mechanism and gain administrative privileges by setting the s par… Flashchat No fix yet Fix from $1,9502009-05-07 HIGH 7.5 CVE-2009-1582 Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote attackers to bypass intended res… Million Dollar Text Links No fix yet Fix from $1,9502009-05-07 MEDIUM 5.0 CVE-2009-1550 Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to obtain the administrator log… Abc Advertise No fix yet Fix from $1,6002009-05-06 HIGH 7.5 CVE-2009-1507 The Node Access User Reference module 5.x before 5.x-2.0-beta4 and 6.x before 6.x-2.0-beta6, a module for Drupal, interprets an empty CCK user refere… Nodeaccess Userreference Patch available Fix from $1,9502009-05-01