Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2008-2146 wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attacke… WordPress after 2.2.2 Fix from $1,9502008-05-12 MEDIUM 6.5 CVE-2008-2139 The rootpw plugin in rPath Appliance Platform Agent 2 and 3 does not re-validate requests from a browser with a valid administrator session, includin… Appliance Platform Agent Mitigation only Fix from $1,6002008-05-12 MEDIUM 5.0 CVE-2008-2138EPSS 16% Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/p… Application Server Portal No fix yet Fix from $1,6002008-05-12 HIGH 7.5 CVE-2008-2078 Robocode before 1.6.0 allows user-assisted remote attackers to "access the internals of the Robocode game" via unspecified vectors related to the AWT… Robocode after 1.5.4 Fix from $1,9502008-05-05 HIGH 7.5 CVE-2008-2019 Simple Machines Forum (SMF), probably 1.1.4, relies on "randomly generated static" to hinder brute-force attacks on the WAV file (aka audio) CAPTCHA,… Smf Mitigation only Fix from $1,9502008-04-30 HIGH 8.5 CVE-2008-1998 The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users … Db2 Mitigation only Fix from $1,9502008-04-28 HIGH 7.5 CVE-2008-2003 BadBlue 2.72 Personal Edition stores multiple programs in the web document root with insufficient access control, which allows remote attackers to (1… Badblue Mitigation only Fix from $1,9502008-04-28 HIGH 7.5 CVE-2008-1995 Sun Java System Directory Proxy Server 6.0, 6.1, and 6.2 classifies a connection using the "bind-dn" criteria, which can cause an incorrect applicati… Java System Directory Server Mitigation only Fix from $1,9502008-04-28 HIGH 7.5 CVE-2008-1992 Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3) default_mail_jmail.asp, whic… Acidcat Cms No fix yet Fix from $1,9502008-04-27 HIGH 7.5 CVE-2008-1993 Acidcat CMS 3.4.1 does not restrict access to the FCKEditor component, which allows remote attackers to upload arbitrary files. Acidcat Cms No fix yet Fix from $1,9502008-04-27 MEDIUM 6.8 CVE-2008-1931 Realtek HD Audio Codec Drivers RTKVHDA.sys and RTKVHDA64.sys before 6.0.1.5605 on Windows Vista allow local users to create, write, and read registry… Hd Audio Codec Drivers after 6.0.1.5604 Fix from $1,6002008-04-25 MEDIUM 6.8 CVE-2008-1937 The user form processing (userform.py) in MoinMoin before 1.6.3, when using ACLs or a non-empty superusers list, does not properly manage users, whic… Moinmoin Patch available Fix from $1,6002008-04-25 HIGH 9.0 CVE-2008-1436EPSS 37% Microsoft Windows XP Professional SP2, Vista, and Server 2003 and 2008 does not properly assign activities to the (1) NetworkService and (2) LocalSer… Windows Nt No fix yet Fix from $1,9502008-04-21 HIGH 7.5 CVE-2008-0893 Red Hat Administration Server, as used by Red Hat Directory Server 8.0 EL4 and EL5, does not properly restrict access to CGI scripts, which allows re… Directory Server Patch available Fix from $1,9502008-04-16 MEDIUM 6.5 CVE-2008-1790 Unrestricted file upload vulnerability in iScripts SocialWare allows remote authenticated administrators to upload arbitrary files via a crafted logo… Socialware No fix yet Fix from $1,6002008-04-15 MEDIUM 6.4 CVE-2008-1783 Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct request to siteadmin/DeleteUser.ph… Reviews No fix yet Fix from $1,6002008-04-15 HIGH 7.5 CVE-2008-1784 Prozilla Topsites 1.0 allows remote attackers to perform administrative actions via a direct request to (1) addu.php, (2) editu.php, and (3) uidx.php… Topsites No fix yet Fix from $1,9502008-04-15 HIGH 7.5 CVE-2008-1731 The Simple Access module for Drupal 5.x through 5.x-1.2-2 does not properly handle the privacy information for nodes, which might allow remote attack… Simple Access Patch available Fix from $1,9502008-04-11 HIGH 7.5 CVE-2008-1656 Adobe ColdFusion 8 and 8.0.1 does not properly implement the public access level for CFC methods, which allows remote attackers to invoke these metho… Coldfusion Patch available Fix from $1,9502008-04-09 HIGH 7.2 CVE-2008-1710 Untrusted search path vulnerability in chnfsmnt in IBM AIX 6.1 allows local users to gain privileges via a modified PATH environment variable. Aix Mitigation only Fix from $1,9502008-04-09 MEDIUM 6.9 CVE-2008-1692 Eterm 0.9.4 opens a terminal window on :0 if -display is not specified and the DISPLAY environment variable is not set, which might allow local users… Eterm Mitigation only Fix from $1,6002008-04-07 MEDIUM 5.5 CVE-2008-0709 Multiple unspecified vulnerabilities in HP Select Identity 4.00, 4.01, 4.11, 4.12, 4.13, and 4.20 allow remote authenticated users to access other us… Select Identity Mitigation only Fix from $1,6002008-04-07 HIGH 10.0 CVE-2008-1681 Unspecified vulnerability in IBM DB2 Content Manager before 8.3 FP8 has unknown impact and attack vectors related to the AllowedTrustedLogin privileg… Db2 Content Manager after 8.3 Fix from $1,9502008-04-04 MEDIUM 6.5 CVE-2008-1657 OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc ses… Openssh Patch available Fix from $1,6002008-04-02 MEDIUM 6.8 CVE-2008-1625 aavmker4.sys in avast! Home and Professional 4.7 for Windows does not properly validate input to IOCTL 0xb2d60030, which allows local users to gain p… Avast Antivirus Home Mitigation only Fix from $1,6002008-04-02 MEDIUM 6.8 CVE-2008-1638 Nik Sharpener Pro, possibly 2.0, uses world-writable permissions for plug-in files, which allows local users to gain privileges by replacing a plug-i… Nik Sharpener Pro Mitigation only Fix from $1,6002008-04-02 MEDIUM 6.4 CVE-2008-1515 The SOAP interface in OTRS 2.1.x before 2.1.8 and 2.2.x before 2.2.6 allows remote attackers to "read and modify objects" via SOAP requests, related … Otrs 2.1.8 / 2.2.6+ Fix from $1,6002008-04-01 HIGH 7.2 CVE-2008-1593 The checkpoint and restart feature in the kernel in IBM AIX 5.2, 5.3, and 6.1 does not properly protect kernel memory, which allows local users to re… Aix Patch available Fix from $1,9502008-03-31 HIGH 7.2 CVE-2008-1596 Trusted Execution in IBM AIX 6.1 uses an incorrect pathname argument in a call to the trustchk_block_write function, which might allow local users to… Aix Patch available Fix from $1,9502008-03-31 HIGH 7.2 CVE-2008-1599 The nddstat programs on IBM AIX 5.2, 5.3, and 6.1 do not properly handle environment variables, which allows local users to gain privileges by invoki… Aix Patch available Fix from $1,9502008-03-31