Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.4 CVE-2007-6640 Creammonkey 0.9 through 1.1 and GreaseKit 1.2 through 1.3 does not properly prevent access to dangerous functions, which allows remote attackers to r… Creammonkey Mitigation only Fix from $1,6002008-01-04 MEDIUM 6.5 CVE-2007-6644 Joomla! before 1.5 RC4 allows remote authenticated administrators to promote arbitrary users to the administrator group, in violation of the intended… Joomla Mitigation only Fix from $1,6002008-01-04 HIGH 7.5 CVE-2007-6645 Unspecified vulnerability in Joomla! before 1.5 RC4 allows remote authenticated users to gain privileges via unspecified vectors, aka "registered use… Joomla Mitigation only Fix from $1,9502008-01-04 MEDIUM 5.8 CVE-2007-6636 Unspecified vulnerability in the StorageFarabDb module in Bitflu before 0.42 allows user-assisted remote attackers to create or append data to arbitr… Bitflu after 0.41 Fix from $1,6002008-01-04 HIGH 10.0 CVE-2007-6638EPSS 13% March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain use… 3204 Dvr No fix yet Fix from $1,9502008-01-04 HIGH 7.5 CVE-2007-6619 The Setup Wizard in Atlassian JIRA Enterprise Edition before 3.12.1 does not properly restrict setup attempts after setup is complete, which allows r… Jira after 3.12 Fix from $1,9502008-01-03 MEDIUM 5.0 CVE-2007-6603 Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrato… Hot Or Not Clone No fix yet Fix from $1,6002007-12-31 MEDIUM 6.9 CVE-2007-6594 IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0… Lotus Notes after 8.0.1 Fix from $1,6002007-12-28 MEDIUM 6.4 CVE-2007-5342EPSS 5% The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain pe… Tomcat Patch available Fix from $1,6002007-12-27 MEDIUM 5.0 CVE-2007-6512 PHP MySQL Banner Exchange 2.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to ob… Mysql Banner Exchange Mitigation only Fix from $1,6002007-12-21 MEDIUM 5.0 CVE-2007-6334 Ingres 2.5 and 2.6 on Windows, as used in multiple CA products and possibly other products, assigns the privileges and identity of users to be the sa… Ingres Patch available Fix from $1,6002007-12-20 HIGH 10.0 CVE-2007-6507EPSS 37% SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.… Serverprotect Mitigation only Fix from $1,9502007-12-20 MEDIUM 6.5 CVE-2007-6495 inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1… Hosting Controller No fix yet Fix from $1,6002007-12-20 MEDIUM 6.8 CVE-2007-6496 Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the l… Hosting Controller No fix yet Fix from $1,6002007-12-20 HIGH 7.5 CVE-2007-6497 Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp… Hosting Controller after 6.1_hotfix_3.3 Fix from $1,9502007-12-20 MEDIUM 5.5 CVE-2007-6499 Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions o… Hosting Controller after 6.1_hotfix_3.3 Fix from $1,6002007-12-20 MEDIUM 5.5 CVE-2007-6501 Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a r… Hosting Controller after 6.1_hotfix_3.3 Fix from $1,6002007-12-20 MEDIUM 5.5 CVE-2007-6503 Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pl… Hosting Controller after 6.1_hotfix_3.3 Fix from $1,6002007-12-20 MEDIUM 5.5 CVE-2007-6504 Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers… Hosting Controller after 6.1_hotfix_3.3 Fix from $1,6002007-12-20 MEDIUM 6.4 CVE-2007-6470 phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values … Phprpg No fix yet Fix from $1,6002007-12-20 HIGH 9.4 CVE-2007-5856 Quick Look Apple Mac OS X 10.5.1, when previewing an HTML file, does not prevent plug-ins from making network requests, which might allow remote atta… Mac Os X Mitigation only Fix from $1,9502007-12-19 MEDIUM 6.4 CVE-2007-5857 Quick Look in Apple Mac OS X 10.5.1 does not prevent a movie from accessing URLs when the movie file is previewed or if an icon is created, which mig… Mac Os X Mitigation only Fix from $1,6002007-12-19 HIGH 9.3 CVE-2007-6413 Sun Solaris 10 with the 120011-04 and 120012-04 patches, and later 120011-* and 120012-* patches, allows remote attackers to bypass certain netgroup … Solaris Patch available Fix from $1,9502007-12-17 MEDIUM 5.0 CVE-2007-6395EPSS 6% Flat PHP Board 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to obt… Board after 1.2 Fix from $1,6002007-12-17 MEDIUM 5.5 CVE-2007-6383 The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to c… Chandler Server after 0.10 Fix from $1,6002007-12-15 MEDIUM 5.0 CVE-2007-6361 Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers… Gekko after 0.8.2 Fix from $1,6002007-12-15 HIGH 8.5 CVE-2007-6350 scponly 4.6 and earlier allows remote authenticated users to bypass intended restrictions and execute code by invoking dangerous subcommands includin… Scponly after 4.6 Fix from $1,9502007-12-14 HIGH 7.1 CVE-2007-5969EPSS 14% MySQL Community Server 5.0.x before 5.0.51, Enterprise Server 5.0.x before 5.0.52, Server 5.1.x before 5.1.23, and Server 6.0.x before 6.0.4, when a … Mysql Server after 5.0.50 Fix from $1,9502007-12-10 HIGH 9.3 CVE-2007-6278 Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIM… Libflac after 1.2 Fix from $1,9502007-12-07 MEDIUM 6.5 CVE-2007-6222 The CheckCustomerAccess function in functions.php in CRM-CTT Interleave before 4.2.0 (formerly CRM-CTT) does not properly verify user privileges, whi… Interleave after 4.2.0 Fix from $1,6002007-12-04