Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2009-1084 Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote auth… Java System Identity Manager Patch available Fix from $1,6002009-03-25 MEDIUM 6.2 CVE-2008-6514 The Expo plugin in Compiz Fusion 0.7.8 allows local users with physical access to drag the screen saver aside and access the locked desktop by using … Compiz Fusion Patch available Fix from $1,6002009-03-24 MEDIUM 5.0 CVE-2009-1051 FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… Fubarforum after 1.6 Fix from $1,6002009-03-24 MEDIUM 5.0 CVE-2009-1052 FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a… Fireant after 1.3 Fix from $1,6002009-03-24 MEDIUM 5.0 CVE-2009-1053 chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download … Chaozzdb after 1.2 Fix from $1,6002009-03-24 MEDIUM 5.0 CVE-2008-6506 Unspecified vulnerability in phpBB before 3.0.4 allows attackers to bypass intended access restrictions and activate de-activated accounts via unknow… Phpbb after 3.0.3 Fix from $1,6002009-03-23 MEDIUM 5.0 CVE-2008-6493 Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, which allows remote attackers to… Easy Content Management Publishing No fix yet Fix from $1,6002009-03-20 MEDIUM 5.0 CVE-2008-6494 ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a dat… Asp User Engine.net No fix yet Fix from $1,6002009-03-20 HIGH 8.8 CVE-2008-6496 Insecure method vulnerability in the VSPDFEditorX.VSPDFEdit ActiveX control in VSPDFEditorX.ocx 1.0.200.0 in VISAGESOFT eXPert PDF EditorX allows rem… Expert Pdf Editorx No fix yet Fix from $1,9502009-03-20 HIGH 7.6 CVE-2009-0941 The HP Embedded Web Server (EWS) on HP LaserJet Printers, Edgeline Printers, and Digital Senders has no management password by default, which makes i… 8100c Digital Sender Mitigation only Fix from $1,9502009-03-18 MEDIUM 6.8 CVE-2009-0872 The NFS server in Sun Solaris 10, and OpenSolaris before snv_111, does not properly implement the AUTH_NONE (aka sec=none) security mode in combinati… Opensolaris Patch available Fix from $1,6002009-03-11 MEDIUM 6.8 CVE-2009-0873 The NFS daemon (aka nfsd) in Sun Solaris 10 and OpenSolaris before snv_106, when NFSv3 is used, does not properly implement combinations of security … Opensolaris Patch available Fix from $1,6002009-03-11 MEDIUM 5.0 CVE-2009-0866 pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database… Phnews No fix yet Fix from $1,6002009-03-10 MEDIUM 5.0 CVE-2009-0760 Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a … Team Board No fix yet Fix from $1,6002009-03-06 MEDIUM 5.0 CVE-2009-0767 Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file contai… Kipper No fix yet Fix from $1,6002009-03-06 MEDIUM 6.4 CVE-2008-6399 Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack … Dotnetnuke Mitigation only Fix from $1,6002009-03-05 MEDIUM 5.0 CVE-2009-0826 BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file cont… Bloghelper No fix yet Fix from $1,6002009-03-05 MEDIUM 5.0 CVE-2009-0827 PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containin… Pollhelper No fix yet Fix from $1,6002009-03-05 MEDIUM 5.0 CVE-2009-0828 QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain sensitive database informati… Quotebook No fix yet Fix from $1,6002009-03-05 HIGH 9.3 CVE-2009-0367EPSS 11% The Python AI module in Wesnoth 1.4.x and 1.5 before 1.5.11 allows remote attackers to escape the sandbox and execute arbitrary code by using a white… Wesnoth Patch available Fix from $1,9502009-03-05 MEDIUM 6.2 CVE-2009-0578 GNOME NetworkManager before 0.7.0.99 does not properly verify privileges for dbus (1) modify and (2) delete requests, which allows local users to cha… Ubuntu Linux Mitigation only Fix from $1,6002009-03-05 MEDIUM 6.5 CVE-2009-0806 Unspecified vulnerability in OpenGoo before 1.2.1 allows remote authenticated users to modify their own permissions via unknown attack vectors. Opengoo after 1.2 Fix from $1,6002009-03-04 HIGH 7.5 CVE-2009-0807 zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php. Zfeeder No fix yet Fix from $1,9502009-03-04 MEDIUM 5.4 CVE-2009-0801 Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to by… Squid Web Proxy Cache Mitigation only Fix from $1,6002009-03-04 MEDIUM 5.4 CVE-2009-0802 Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacker… Wingate Mitigation only Fix from $1,6002009-03-04 MEDIUM 5.4 CVE-2009-0803 SmoothWall SmoothGuardian, as used in SmoothWall Firewall, NetworkGuardian, and SchoolGuardian 2008, when transparent interception mode is enabled, u… Networkguardian Mitigation only Fix from $1,6002009-03-04 MEDIUM 5.4 CVE-2009-0804 Ziproxy 2.6.0, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attacke… Ziproxy Mitigation only Fix from $1,6002009-03-04 MEDIUM 5.0 CVE-2008-6374 CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access control, which allows remote a… Mailinglistpro No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6375 JBook stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file v… Jbook No fix yet Fix from $1,6002009-03-02 MEDIUM 5.0 CVE-2008-6382 ASP Portal 3.2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… Aspportal No fix yet Fix from $1,6002009-03-02