Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2007-5644 Lussumo Vanilla 1.1.3 and earlier does not require admin privileges for (1) ajax/sortcategories.php and (2) ajax/sortroles.php, which allows remote a… Vanilla after 1.1.3 Fix from $1,9502007-10-23 HIGH 9.3 CVE-2007-5338 Mozilla Firefox before 2.0.0.8 and SeaMonkey before 1.1.5 allow remote attackers to execute arbitrary Javascript with user privileges by using the Sc… Firefox after 2.0.0.7 Fix from $1,9502007-10-21 MEDIUM 6.9 CVE-2007-5587 Buffer overflow in Macrovision SafeDisc secdrv.sys before 4.3.86.0, as shipped in Microsoft Windows XP SP2, XP Professional x64 and x64 SP2, Server 2… Safedisc No fix yet Fix from $1,6002007-10-19 MEDIUM 6.8 CVE-2007-5571 Cisco Firewall Services Module (FWSM) 3.1(6), and 3.2(2) and earlier, does not properly enforce edited ACLs, which might allow remote attackers to by… Firewall Services Module after 3.2 Fix from $1,6002007-10-18 MEDIUM 6.4 CVE-2007-5486 dotProject before 2.1 does not properly check privileges when invoking the Companies module, which allows remote attackers to access this module via … Dotproject after 2.0.4 Fix from $1,6002007-10-16 MEDIUM 5.0 CVE-2007-5468 Cisco CallManager 5.1.1.3000-5 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote atta… Call Manager Mitigation only Fix from $1,6002007-10-16 MEDIUM 5.0 CVE-2007-5469 OpenSER 1.2.2 does not verify the Digest authentication header URI against the Request URI in SIP messages, which allows remote attackers to use snif… Openser Mitigation only Fix from $1,6002007-10-16 MEDIUM 6.5 CVE-2007-5441 CMS Made Simple 1.1.3.1 does not check the permissions assigned to users in some situations, which allows remote authenticated users to perform some … Cms Made Simple Mitigation only Fix from $1,6002007-10-14 MEDIUM 5.0 CVE-2007-5439 CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows… Etrust Integrated Threat Management Mitigation only Fix from $1,6002007-10-13 HIGH 10.0 CVE-2007-5328EPSS 7% The Message Engine RPC service in CA BrightStor ARCServe BackUp v9.01 through R11.5, and Enterprise Backup r10.5, allows attackers to execute arbitra… Brightstor Arcserve Backup Patch available Fix from $1,9502007-10-13 HIGH 10.0 CVE-2007-5382 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine (WLSE) 4.1.91.0 and earlier to Cisco Wireless Control System (WCS) crea… Wireless Lan Solution Engine after 4.1.91.0 Fix from $1,9502007-10-12 HIGH 7.2 CVE-2007-5254 VirusBlokAda Vba32 AntiVirus 3.12.2 uses weak permissions (Everyone:Write) for its installation directory, which allows local users to gain privilege… Vba32 Antivirus Patch available Fix from $1,9502007-10-06 MEDIUM 5.0 CVE-2007-5260 ASP-CMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database co… Asp Cms Mitigation only Fix from $1,6002007-10-06 MEDIUM 5.4 CVE-2007-5236 Java Web Start in Sun JDK and JRE 5.0 Update 12 and earlier, and SDK and JRE 1.4.2_15 and earlier, on Windows does not properly enforce access restri… Jdk Patch available Fix from $1,6002007-10-06 HIGH 7.5 CVE-2007-5230 admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote attackers to perform administr… Zomplog Patch available Fix from $1,9502007-10-05 MEDIUM 6.8 CVE-2007-5223 Multiple unspecified vulnerabilities in AlstraSoft Affiliate Network Pro allow remote attackers to include local files and have other unspecified imp… Affiliate Network Pro Mitigation only Fix from $1,6002007-10-05 MEDIUM 6.0 CVE-2007-5210 Arbor Networks Peakflow SP before 3.5.1 patch 14, and 3.6.x before 3.6.1 patch 5, allows remote authenticated users to bypass access restrictions and… Peakflow Sp Patch available Fix from $1,6002007-10-04 MEDIUM 6.9 CVE-2007-5194 The Chroot server in rMake 1.0.11 creates a /dev/zero device file with read/write permissions for the rMake user and the same minor device number as … Rmake Mitigation only Fix from $1,6002007-10-04 MEDIUM 5.0 CVE-2007-5170 Unspecified vulnerability in the embedded service processor (SP) before 3.09 in Sun Fire X2100 M2 and X2200 M2 Embedded Lights Out Manager (ELOM) all… Embedded Lights Out Manager Patch available Fix from $1,6002007-10-01 MEDIUM 5.0 CVE-2007-5171 Unspecified vulnerability in Quicksilver Forums before 1.4.1 allows remote attackers to delete arbitrary PMs via unspecified vectors. Quicksilver Forums after 1.4.0 Fix from $1,6002007-10-01 MEDIUM 5.0 CVE-2007-4873 SimpNews 2.41.03 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download arbitrar… Simplenews Mitigation only Fix from $1,6002007-09-27 MEDIUM 5.0 CVE-2007-5134 Cisco Catalyst 6500 and Cisco 7600 series devices use 127/8 IP addresses for Ethernet Out-of-Band Channel (EOBC) internal communication, which might … Catalyst 6500 Patch available Fix from $1,6002007-09-27 HIGH 7.2 CVE-2007-5101 ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local us… Chironfs after 1.0_rc6 Fix from $1,9502007-09-26 HIGH 7.5 CVE-2007-5090 Unspecified vulnerability in IBM Rational ClearQuest (CQ), when a Microsoft SQL Server or an IBM DB2 database is used, allows attackers to corrupt da… Rational Clearquest No fix yet Fix from $1,9502007-09-26 HIGH 7.2 CVE-2007-4573 The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero … Linux Kernel after 2.6.22.6 Fix from $1,9502007-09-24 HIGH 7.5 CVE-2007-5062 account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un parameter in a register acti… Flip after 3.0 Fix from $1,9502007-09-24 HIGH 7.5 CVE-2007-5038 The offer_account_by_email function in User.pm in the WebService for Bugzilla before 3.0.2, and 3.1.x before 3.1.2, does not check the value of the c… Bugzilla Patch available Fix from $1,9502007-09-24 MEDIUM 6.9 CVE-2007-5044 ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows loc… Zonealarm Mitigation only Fix from $1,6002007-09-24 MEDIUM 5.5 CVE-2007-4497 Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Pl… Ace after 6.0.1 Fix from $1,6002007-09-21 MEDIUM 6.8 CVE-2007-4569 backend/session.c in KDM in KDE 3.3.0 through 3.5.7, when autologin is configured and "shutdown with password" is enabled, allows remote attackers to… Kde Patch available Fix from $1,6002007-09-21