Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2008-0588 Buffer overflow in the utape program in devices.scsi.tape.diag in IBM AIX 5.2 and 5.3 allows local users to gain privileges via unspecified vectors. Aix Patch available Fix from $1,9502008-02-05 MEDIUM 6.4 CVE-2008-0569 The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows… Comment Upload Module Mitigation only Fix from $1,6002008-02-05 HIGH 7.2 CVE-2008-0573 IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafted IPSECDRV_IOCTL IOCTL reques… Ipsecdrv.sys No fix yet Fix from $1,9502008-02-05 MEDIUM 6.4 CVE-2008-0577 The Project Issue Tracking module 5.x-2.x-dev before 20080130 in the 5.x-2.x series, 5.x-1.2 and earlier in the 5.x-1.x series, 4.7.x-2.6 and earlier… Project Issue Tracking Module Mitigation only Fix from $1,6002008-02-05 MEDIUM 5.0 CVE-2008-0425 Absolute path traversal vulnerability in explorerdir.php in Frimousse 0.0.2 allows remote attackers to read arbitrary files and list arbitrary direct… Frimousse No fix yet Fix from $1,6002008-01-23 MEDIUM 6.0 CVE-2008-0402 Unspecified vulnerability in IBM WebSphere Business Modeler Basic and Advanced 6.0.2.1 before Interim Fix 11 allows remote authenticated users to byp… Websphere Business Modeler Patch available Fix from $1,6002008-01-23 MEDIUM 5.0 CVE-2008-0372 8e6 R3000 Internet Filter 2.0.05.33, and other versions before 2.0.11, allows remote attackers to bypass intended restrictions via a fragmented HTTP … R3000 Internet Filter after 2.0.10 Fix from $1,6002008-01-22 HIGH 10.0 CVE-2008-0375 Unspecified vulnerability in OKI C5510MFP Printer CU H2.15, PU 01.03.01, System F/W 1.01, and Web Page 1.00 allows remote attackers to set the passwo… C5510 Mfp Printer Mitigation only Fix from $1,9502008-01-22 HIGH 7.5 CVE-2008-0350 admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain admini… Evilsentinel after 1.0.9 Fix from $1,9502008-01-18 MEDIUM 5.0 CVE-2008-0329 LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_refuser.php in Admin/, which a… Lulieblog No fix yet Fix from $1,6002008-01-17 HIGH 10.0 CVE-2007-6685 Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vector… Gallery Publish Xp Module after 2.2.3 Fix from $1,9502008-01-17 HIGH 10.0 CVE-2007-6690 The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack… Gallery after 2.2.3 Fix from $1,9502008-01-17 MEDIUM 6.8 CVE-2008-0293 Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authent… Freeseat after 1.1.5c Fix from $1,6002008-01-16 MEDIUM 6.9 CVE-2008-0217 The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable perm… FreeBSD Patch available Fix from $1,6002008-01-16 MEDIUM 5.0 CVE-2008-0275 The Atom 4.7 before 4.7.x-1.0 and 5.x before 5.x-1.0 module for Drupal does not properly manage permissions for node (1) titles, (2) teasers, and (3)… Atom Module after 5.0 Fix from $1,6002008-01-15 HIGH 7.5 CVE-2008-0245 admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain… Uploadimage No fix yet Fix from $1,9502008-01-12 HIGH 10.0 CVE-2008-0246 admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gai… Uploadimage No fix yet Fix from $1,9502008-01-12 MEDIUM 5.8 CVE-2007-6018 IMP Webmail Client 4.1.5, Horde Application Framework 3.1.5, and Horde Groupware Webmail Edition 1.0.3 does not validate unspecified HTTP requests, w… Framework Patch available Fix from $1,6002008-01-11 HIGH 7.5 CVE-2008-0233 Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended access restrictions and upload an… Zero Cms No fix yet Fix from $1,9502008-01-11 MEDIUM 6.5 CVE-2007-5401 Unrestricted file upload vulnerability in uploadrequest.asp in Layton HelpBox 3.7.1 allows remote authenticated users to upload and execute arbitrary… Helpbox Mitigation only Fix from $1,6002008-01-09 MEDIUM 6.5 CVE-2007-6600 PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of tabl… PostgreSQL Patch available Fix from $1,6002008-01-09 HIGH 7.2 CVE-2007-5665 STEngine.exe 3.5.0.20 in Novell ZENworks Endpoint Security Management (ESM) 3.5, and other ESM versions before 3.5.0.82, dynamically creates scripts … Zenworks Endpoint Security Management after 3.5 Fix from $1,9502008-01-09 HIGH 7.2 CVE-2007-5761 The NantSys device 5.0.0.115 in Motorola netOctopus 5.1.2 build 1011 has weak permissions for the \\.\NantSys device interface (nantsys.sys), which a… Netoctopus Patch available Fix from $1,9502008-01-09 HIGH 10.0 CVE-2008-0148EPSS 6% TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a… Tutos No fix yet Fix from $1,9502008-01-09 HIGH 7.2 CVE-2007-5352 Unspecified vulnerability in Local Security Authority Subsystem Service (LSASS) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 SP1 and SP2 al… Windows 2000 Patch available Fix from $1,9502008-01-08 MEDIUM 5.0 CVE-2007-6675 The b_system_comments_show function in htdocs/modules/system/blocks/system_blocks.php in XOOPS before 2.0.18 does not check permissions, which allows… Xoops after 2.0.17_1 Fix from $1,6002008-01-08 MEDIUM 5.0 CVE-2008-0135 Snitz Forums 2000 3.4.06 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers … Snitz Forums 2000 after 3.4.06 Fix from $1,6002008-01-08 HIGH 7.5 CVE-2007-6668EPSS 6% admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote attackers to perform unrestri… Myspace Content Zone after 3.60 Fix from $1,9502008-01-08 HIGH 7.5 CVE-2007-6650 Unrestricted file upload vulnerability in fisheye/upload.php in Bitweaver R2 CMS allows remote attackers to upload arbitrary files by using the image… R2 Cms No fix yet Fix from $1,9502008-01-04 MEDIUM 6.8 CVE-2007-6598 Dovecot before 1.0.10, with certain configuration options including use of %variables, does not properly maintain the LDAP+auth cache, which might al… Dovecot after 1.0.9 Fix from $1,6002008-01-04