Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2008-4195 Opera before 9.52 does not properly restrict the ability of a framed web page to change the address associated with a different frame, which allows r… Opera Browser after 9.51 Fix from $1,6002008-09-27 HIGH 7.2 CVE-2008-4294 IBM Tivoli Netcool/Webtop 2.1 before 2.1.0.5 preserves cached user privileges after logout, which allows physically proximate attackers to hijack a s… Tivoli Netcool Webtop Patch available Fix from $1,9502008-09-27 MEDIUM 5.0 CVE-2008-4297 Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbit… Mercurial after 1.0.1 Fix from $1,6002008-09-27 MEDIUM 6.5 CVE-2008-4245 The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authenticated users to (1) change a … Rianxosencabos Cms No fix yet Fix from $1,6002008-09-25 HIGH 7.5 CVE-2008-3835 The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows rem… Firefox after 2.0.0.16 Fix from $1,9502008-09-24 HIGH 7.5 CVE-2008-3836 feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview a… Firefox after 2.0.0.16 Fix from $1,9502008-09-24 HIGH 7.5 CVE-2008-4058EPSS 5% The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remo… Firefox 1.1.12 / 2.0.0.17+ Fix from $1,9502008-09-24 HIGH 7.5 CVE-2008-4059 The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chr… Firefox after 2.0.0.17 Fix from $1,9502008-09-24 HIGH 7.5 CVE-2008-4060 Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create docum… Firefox after 2.0.0.16 Fix from $1,9502008-09-24 MEDIUM 5.0 CVE-2008-4153 The Talk module 5.x before 5.x-1.3 and 6.x before 6.x-1.5, a module for Drupal, does not perform access checks for a node before displaying comments,… Talk after 6.x-1.4 Fix from $1,6002008-09-24 HIGH 7.2 CVE-2008-4131 Multiple unspecified vulnerabilities in Sun Solaris 8 through 10 allow local users to gain privileges via vectors related to handling of tags with (1… Solaris Patch available Fix from $1,9502008-09-19 MEDIUM 5.0 CVE-2008-4109EPSS 29% A certain Debian patch for OpenSSH before 4.3p2-9etch3 on etch; before 4.6p1-1 on sid and lenny; and on other distributions such as SUSE uses functio… Openssh after 4.3p2 Fix from $1,6002008-09-18 MEDIUM 5.0 CVE-2008-2331 Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sha… Mac Os X Patch available Fix from $1,6002008-09-16 HIGH 7.2 CVE-2008-3609 The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might al… Mac Os X Patch available Fix from $1,9502008-09-16 HIGH 9.0 CVE-2008-3618 The File Sharing pane in the Sharing preference pane in Apple Mac OS X 10.5 through 10.5.4 does not inform users that the complete contents of their … Mac Os X Patch available Fix from $1,9502008-09-16 HIGH 7.2 CVE-2008-4018 swcons in bos.rte.console in IBM AIX 5.2.0 through 6.1.1 allows local users in the system group to create or overwrite an arbitrary file, and establi… Aix Mitigation only Fix from $1,9502008-09-11 HIGH 7.5 CVE-2008-3967 moderation.php in MyBB (aka MyBulletinBoard) before 1.4.1 does not properly check for moderator privileges, which has unknown impact and remote attac… Mybb after 1.4.0 Fix from $1,9502008-09-11 MEDIUM 6.9 CVE-2008-3970 pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which … Pam Mount Mitigation only Fix from $1,6002008-09-11 MEDIUM 6.6 CVE-2008-3972 pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card's label matches the "OpenSC" string, which might … Opensc after 0.11.5 Fix from $1,6002008-09-11 HIGH 7.1 CVE-2008-3631 Application Sandbox in Apple iPod touch 2.0 through 2.0.2, and iPhone 2.0 through 2.0.2, does not properly isolate third-party applications, which al… Ipod Touch Mitigation only Fix from $1,9502008-09-11 HIGH 7.2 CVE-2008-3890 The kernel in FreeBSD 6.3 through 7.0 on amd64 platforms can make an extra swapgs call after a General Protection Fault (GPF), which allows local use… FreeBSD Mitigation only Fix from $1,9502008-09-05 HIGH 7.5 CVE-2008-3920 Unspecified vulnerability in BitlBee before 1.2.2 allows remote attackers to "recreate" and "hijack" existing accounts via unspecified vectors. Bitlbee after 1.2.1 Fix from $1,9502008-09-04 HIGH 7.2 CVE-2008-3525 The sbni_ioctl function in drivers/net/wan/sbni.c in the wan subsystem in the Linux kernel 2.6.26.3 does not check for the CAP_NET_ADMIN capability b… Linux Kernel Mitigation only Fix from $1,9502008-09-03 HIGH 7.2 CVE-2008-3698 Unspecified vulnerability in the OpenProcess function in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 bu… Ace 1.0.7 / 1.0.8+ Fix from $1,9502008-09-03 HIGH 7.2 CVE-2008-3875 The kernel in Sun Solaris 8 through 10 and OpenSolaris before snv_90 allows local users to bypass chroot, zones, and the Solaris Trusted Extensions m… Opensolaris Patch available Fix from $1,9502008-09-02 MEDIUM 6.5 CVE-2008-3852 Unspecified vulnerability in the CLR stored procedure deployment from IBM Database Add-Ins for Visual Studio in the Visual Studio Net component in IB… Db2 Universal Database after 9.5 Fix from $1,6002008-08-28 HIGH 7.5 CVE-2008-3856 The routine infrastructure component in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP1 on Unix and Linux does not change the ownership of … Db2 Universal Database after 9.1 Fix from $1,9502008-08-28 MEDIUM 6.5 CVE-2008-3742 Unrestricted file upload vulnerability in the BlogAPI module in Drupal 5.x before 5.10 and 6.x before 6.4 allows remote authenticated users to execut… Drupal Mitigation only Fix from $1,6002008-08-27 MEDIUM 5.5 CVE-2008-3745 The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via u… Drupal Patch available Fix from $1,6002008-08-27 HIGH 7.5 CVE-2008-3747 The (1) get_edit_post_link and (2) get_edit_comment_link functions in wp-includes/link-template.php in WordPress before 2.6.1 do not force SSL commun… WordPress Patch available Fix from $1,9502008-08-27