Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2008-5931 The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… Aspired2blog No fix yet Fix from $1,6002009-01-21 MEDIUM 5.0 CVE-2008-5932EPSS 6% CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… Freeforum No fix yet Fix from $1,6002009-01-21 MEDIUM 5.0 CVE-2008-5935 Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file c… Factosystem Weblog Mitigation only Fix from $1,6002009-01-21 HIGH 7.5 CVE-2008-5516 The web interface in git (gitweb) 1.5.x before 1.5.5 allows remote attackers to execute arbitrary commands via shell metacharacters related to git_se… Git Mitigation only Fix from $1,9502009-01-20 HIGH 7.5 CVE-2009-0180 Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which migh… Nfs Utils after 1.1.2 Fix from $1,9502009-01-20 HIGH 9.0 CVE-2009-0169 Sun Java System Access Manager 7.1 allows remote authenticated sub-realm administrators to gain privileges, as demonstrated by creating the amadmin a… Java System Access Manager Patch available Fix from $1,9502009-01-16 MEDIUM 6.0 CVE-2009-0170 Sun Java System Access Manager 6.3 2005Q1, 7 2005Q4, and 7.1 allows remote authenticated users with console privileges to discover passwords, and obt… Java System Access Manager Patch available Fix from $1,6002009-01-16 HIGH 10.0 CVE-2009-0171 The Sun SPARC Enterprise M4000 and M5000 Server, within a certain range of serial numbers, allows remote attackers to use the manufacturing root pass… Sparc Enterprise Server Mitigation only Fix from $1,9502009-01-16 MEDIUM 6.9 CVE-2009-0122 hplip.postinst in HP Linux Imaging and Printing (HPLIP) 2.7.7 and 2.8.2 on Ubuntu allows local users to change the ownership of arbitrary files via u… Hplip Patch available Fix from $1,6002009-01-15 MEDIUM 5.0 CVE-2008-5459 Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect confidentiality via unknown ve… Bea Product Suite No fix yet Fix from $1,6002009-01-14 MEDIUM 6.8 CVE-2008-5461 Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0, and SP7 allows remot… Bea Product Suite Mitigation only Fix from $1,6002009-01-14 MEDIUM 6.8 CVE-2008-5462 Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 10.3, 10.2, 10.0 MP1, 9.2 MP3, and 8.1 SP6 allows remote attackers to… Bea Product Suite No fix yet Fix from $1,6002009-01-14 HIGH 7.2 CVE-2009-0024 The sys_remap_file_pages function in mm/fremap.c in the Linux kernel before 2.6.24.1 allows local users to cause a denial of service or gain privileg… Linux Kernel after 2.6.24 Fix from $1,9502009-01-13 MEDIUM 5.0 CVE-2008-5885EPSS 6% The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allows remote attackers to downloa… Aspired2quote No fix yet Fix from $1,6002009-01-12 MEDIUM 5.0 CVE-2008-5886 TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… Discussion Web No fix yet Fix from $1,6002009-01-12 HIGH 7.5 CVE-2008-5896 CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download … Ratemysite No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2008-5897EPSS 6% CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… Freewallpaper No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2008-5898EPSS 6% CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download t… Directory No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2008-5899EPSS 6% CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download … Freeforall No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2008-5900EPSS 6% CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download th… Articles No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2008-5901 iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the… Iyzi Forum No fix yet Fix from $1,9502009-01-12 HIGH 7.5 CVE-2009-0108 PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via modified (1) PHPAUCTION_RM_ID,… Phpauctions No fix yet Fix from $1,9502009-01-09 HIGH 10.0 CVE-2009-0043EPSS 53% The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which … Service Level Management Patch available Fix from $1,9502009-01-08 HIGH 7.5 CVE-2008-5873 Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a … Yerba after 6.3 Fix from $1,9502009-01-08 MEDIUM 5.0 CVE-2008-5852 Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the d… Emefa Guestbook No fix yet Fix from $1,6002009-01-06 MEDIUM 5.0 CVE-2008-5853 Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with insufficient access control, w… Chicomas after 2.0.4 Fix from $1,6002009-01-06 MEDIUM 5.0 CVE-2008-5855 myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to dis… Login Session No fix yet Fix from $1,6002009-01-06 HIGH 7.5 CVE-2008-5840 PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicalendar_login cookies to 1. Phpicalendar after 2.24 Fix from $1,9502009-01-05 MEDIUM 5.0 CVE-2008-5762 Simple Text-File Login Script (SiTeFiLo) 1.0.6 stores sensitive information under the web root with insufficient access control, which allows remote … Simple Text File Login Script No fix yet Fix from $1,6002008-12-30 MEDIUM 5.0 CVE-2008-5765EPSS 6% WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the data… Worksimple No fix yet Fix from $1,6002008-12-30