Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2008-2722 Menalto Gallery before 2.2.5 allows remote attackers to bypass permissions for sub-albums via a ZIP archive. Gallery after 2.2.4 Fix from $1,9502008-06-16 MEDIUM 5.0 CVE-2008-2724 Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attack… Gallery Mitigation only Fix from $1,6002008-06-16 MEDIUM 6.5 CVE-2008-2717 TYPO3 4.0.x before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.2.1, uses an insufficiently restrictive default fileDenyPattern for Apache, which al… Apache Webserver Mitigation only Fix from $1,6002008-06-16 HIGH 7.8 CVE-2008-2707 Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (… Network Interface Controller Mitigation only Fix from $1,9502008-06-16 HIGH 7.5 CVE-2008-2682 _RealmAdmin/login.asp in Realm CMS 2.3 and earlier allows remote attackers to bypass authentication and access admin pages via certain modified cooki… Realm Cms No fix yet Fix from $1,9502008-06-12 HIGH 9.3 CVE-2008-2551EPSS 47% The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force the download and execution o… Instant Messenger No fix yet Fix from $1,9502008-06-04 HIGH 7.8 CVE-2008-2059 Cisco Adaptive Security Appliance (ASA) and Cisco PIX security appliance 8.0.x before 8.0(3)9 allows remote attackers to bypass control-plane ACLs fo… Pix Security Appliance Mitigation only Fix from $1,9502008-06-04 MEDIUM 5.0 CVE-2008-2402EPSS 11% The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access c… Java Asp Server after 4.0.2 Fix from $1,6002008-06-04 MEDIUM 6.8 CVE-2008-0169 Plugin/passwordauth.pm (aka the passwordauth plugin) in ikiwiki 1.34 through 2.47 allows remote attackers to bypass authentication, and login to any … Ikiwiki Mitigation only Fix from $1,6002008-06-03 HIGH 7.2 CVE-2008-2539 The Sun Cluster Global File System in Sun Cluster 3.1 on Sun Solaris 8 through 10, when an underlying ufs filesystem is used, might allow local users… Cluster Mitigation only Fix from $1,9502008-06-03 HIGH 9.3 CVE-2008-2540EPSS 8% Apple Safari on Mac OS X, and before 3.1.2 on Windows, does not prompt the user before downloading an object that has an unrecognized content type, w… Safari 3.1.2+ Fix from $1,9502008-06-03 HIGH 7.2 CVE-2008-2515 Unspecified vulnerability in iostat in IBM AIX 5.2, 5.3, and 6.1 allows local users to gain privileges via unknown vectors related to an "environment… Aix Patch available Fix from $1,9502008-06-02 MEDIUM 6.5 CVE-2008-2488 admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated users to create new admin acc… Roomphplanning No fix yet Fix from $1,6002008-05-28 MEDIUM 6.8 CVE-2008-2420 The OCSP functionality in stunnel before 4.24 does not properly search certificate revocation lists (CRL), which allows remote attackers to bypass in… Stunnel Patch available Fix from $1,6002008-05-23 HIGH 7.2 CVE-2008-2400 Unspecified vulnerability in stunnel before 4.23, when running as a service on Windows, allows local users to gain privileges via unknown attack vect… Stunnel Mitigation only Fix from $1,9502008-05-22 HIGH 7.5 CVE-2008-2346 AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creating an admin account via a di… Alkalinephp after 0.77.35 Fix from $1,9502008-05-20 HIGH 7.5 CVE-2008-2348 MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and exceed application quotas via … Meltingice File System No fix yet Fix from $1,9502008-05-20 HIGH 7.5 CVE-2008-2349 Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direct request to install/newuser.… Zomplog after 3.8.2 Fix from $1,9502008-05-20 HIGH 7.5 CVE-2008-2338EPSS 6% Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when accessing unspecified scripts … Activekb after 1.5 Fix from $1,9502008-05-19 HIGH 7.5 CVE-2008-2343 News Manager 2.0 allows remote attackers to bypass restrictions and obtain sensitive information via a direct request to (1) db/connect_str.php and (… News Manager No fix yet Fix from $1,9502008-05-19 HIGH 7.2 CVE-2008-2287 Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 does not properly protect the install directory, which might allow local users to… Altiris Deployment Solution Patch available Fix from $1,9502008-05-18 HIGH 7.2 CVE-2008-2289 Unspecified vulnerability in a tooltip element in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to gain priv… Altiris Deployment Solution Mitigation only Fix from $1,9502008-05-18 HIGH 7.2 CVE-2008-2290 Unspecified vulnerability in the Agent user interface in Symantec Altiris Deployment Solution 6.8.x and 6.9.x before 6.9.176 allows local users to ga… Altiris Deployment Solution Mitigation only Fix from $1,9502008-05-18 HIGH 7.5 CVE-2008-2293 admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain privileges by setting the Comment… Mpcs No fix yet Fix from $1,9502008-05-18 HIGH 7.5 CVE-2008-2294 Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with a modified user name for "ad… Pet Grooming Management System No fix yet Fix from $1,9502008-05-18 HIGH 7.5 CVE-2008-2297 The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininfo cookie to "<?php" or "?>", … Rantx No fix yet Fix from $1,9502008-05-18 MEDIUM 6.5 CVE-2008-2300 Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allo… Access Essentials after 4.5 Fix from $1,6002008-05-18 HIGH 9.0 CVE-2008-2216 Unrestricted file upload vulnerability in src/yopy_upload.php in Project-Based Calendaring System (PBCS) 0.7.1 allows remote authenticated users to u… Project Based Calendaring System No fix yet Fix from $1,9502008-05-14 MEDIUM 5.0 CVE-2008-2226 Unspecified vulnerability in the export feature in OpenKM before 2.0 allows remote attackers to export arbitrary documents via unspecified vectors. … Openkm after 1.2 Fix from $1,6002008-05-14 MEDIUM 6.5 CVE-2008-2174 Multiple unspecified vulnerabilities in Robin Rawson-Tetley Animal Shelter Manager (ASM) before 2.2.2 have unknown impact and attack vectors, related… Animal Shelter Manager after 2.2.1 Fix from $1,6002008-05-13