Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.0 CVE-2008-4789 The validation functionality in the core upload module in Drupal 6.x before 6.5 allows remote authenticated users to bypass intended access restricti… Drupal after 6.4 Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4790 The core upload module in Drupal 5.x before 5.11 allows remote authenticated users to bypass intended access restrictions and read "files attached to… Drupal after 5.10 Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4791 The user module in Drupal 5.x before 5.11 and 6.x before 6.5 might allow remote authenticated users to bypass intended login access rules and success… Drupal 5.11 / 6.5+ Fix from $1,6002008-10-29 MEDIUM 6.0 CVE-2008-4792 The core BlogAPI module in Drupal 5.x before 5.11 and 6.x before 6.5 does not properly validate unspecified content fields of an internal Drupal form… Drupal 5.11 / 6.5+ Fix from $1,6002008-10-29 HIGH 7.5 CVE-2008-4793 The node module API in Drupal 5.x before 5.11 allows remote attackers to bypass node validation and have unspecified other impact via unknown vectors… Drupal after 5.10 Fix from $1,9502008-10-29 MEDIUM 5.8 CVE-2008-4698 Opera before 9.61 does not properly block scripts during preview of a news feed, which allows remote attackers to create arbitrary new feed subscript… Opera Browser after 9.60 Fix from $1,6002008-10-23 MEDIUM 6.8 CVE-2008-4676 Unspecified vulnerability in Citrix XenApp (formerly Presentation Server) 4.5 Feature Pack 1 and earlier, Presentation Server 4.0, and Access Essenti… Access Essentials after 4.5 Fix from $1,6002008-10-22 HIGH 7.5 CVE-2008-4644 hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. Mystats No fix yet Fix from $1,9502008-10-22 HIGH 7.5 CVE-2008-4600 configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain administrative access by sett… Pokermax Poker League Tournament Script No fix yet Fix from $1,9502008-10-18 HIGH 7.5 CVE-2008-4597 Shindig-Integrator 5.x, a module for Drupal, does not properly restrict generated page access, which allows remote attackers to gain privileges via u… Shindig Integrator Mitigation only Fix from $1,9502008-10-17 HIGH 7.5 CVE-2008-4585 Belong Software Site Builder 0.1 beta allows remote attackers to bypass intended access restrictions and perform administrative actions via a direct … Site Builder Mitigation only Fix from $1,9502008-10-15 MEDIUM 5.0 CVE-2008-4578 The ACL plugin in Dovecot before 1.1.4 allows attackers to bypass intended access restrictions by using the "k" right to create unauthorized "parent/… Dovecot after 1.1.3 Fix from $1,6002008-10-15 HIGH 7.2 CVE-2008-3464 afd.sys in the Ancillary Function Driver (AFD) component in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP1 and SP2 does not properly va… Windows 2003 Server Patch available Fix from $1,9502008-10-15 HIGH 7.5 CVE-2008-4552 The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of argumen… Nfs Utils after 1.1.2 Fix from $1,9502008-10-14 HIGH 7.5 CVE-2008-4215 Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that h… Mac Os X Server Patch available Fix from $1,9502008-10-10 HIGH 7.5 CVE-2008-4507 Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows editors to delete pages that were created by a different author … Lotus Quickr Mitigation only Fix from $1,9502008-10-09 MEDIUM 5.0 CVE-2008-4511 Todd Woolums ASP News Management, possibly 2.21, stores db/news.mdb under the web root with insufficient access control, which allows remote attacker… Asp News Management Mitigation only Fix from $1,6002008-10-09 MEDIUM 5.0 CVE-2008-4512 ASP/MS Access Shoutbox, probably 1.1 beta, stores db/shoutdb.mdb under the web root with insufficient access control, which allows remote attackers t… Asp\/ms Access Shoutbox Mitigation only Fix from $1,6002008-10-09 HIGH 7.5 CVE-2008-4506 Unspecified vulnerability in IBM Lotus Quickr 8.1 before Fix pack 1 (8.1.0.1) allows a place manager to "demote or delete a place superuser group" vi… Lotus Quickr Mitigation only Fix from $1,9502008-10-09 HIGH 7.2 CVE-2008-3830 Condor before 7.0.5 does not properly handle when the configuration specifies overlapping netmasks in allow or deny rules, which causes the rule to b… Condor after 7.0.4 Fix from $1,9502008-10-08 MEDIUM 6.8 CVE-2008-4484 main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name parameter to "users," as demonstr… Gallery after 1.32 Fix from $1,6002008-10-08 HIGH 9.3 CVE-2008-4472EPSS 8% The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009 SP2 and Autodesk Design Revie… Design Review No fix yet Fix from $1,9502008-10-07 HIGH 7.2 CVE-2008-4451 The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users to execute arbitrary code via … System Analyzer Tool No fix yet Fix from $1,9502008-10-06 HIGH 9.3 CVE-2008-4453EPSS 10% The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro Imaging SDK 5.7.1 GdPicturePr… Light Imaging Toolkit Patch available Fix from $1,9502008-10-06 MEDIUM 6.8 CVE-2008-4279 The CPU hardware emulation for 64-bit guest operating systems in VMware Workstation 6.0.x before 6.0.5 build 109488 and 5.x before 5.5.8 build 108000… Player 1.0.8 / 2.0.5+ Fix from $1,6002008-10-06 HIGH 7.2 CVE-2008-4405 xend in Xen 3.0.3 does not properly limit the contents of the /local/domain xenstore directory tree, and does not properly restrict a guest VM's writ… Xen No fix yet Fix from $1,9502008-10-03 HIGH 7.8 CVE-2008-3542 Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors. Insight Diagnostics 7.9.1.2402+ Fix from $1,9502008-10-02 HIGH 7.5 CVE-2008-4334 PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the infouser cookie to 1. Php Infoboard No fix yet Fix from $1,9502008-09-30 MEDIUM 6.5 CVE-2008-4339 Unspecified vulnerability in the Java Administration GUI (jnbSA) in Symantec Veritas NetBackup Server and NetBackup Enterprise Server 5.1 before MP7,… Netbackup Enterprise Server Patch available Fix from $1,6002008-09-30 HIGH 7.5 CVE-2008-4341 add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by setting a cookie with admin=ye… Myblog after 0.9.8 Fix from $1,9502008-09-30