Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.8 CVE-2007-4174EPSS 6% Tor before 0.1.2.16, when ControlPort is enabled, does not properly restrict commands to localhost port 9051, which allows remote attackers to modify… Tor after 0.1.2.15 Fix from $1,6002007-08-07 HIGH 7.2 CVE-2007-3532 NVIDIA drivers (nvidia-drivers) before 1.0.7185, 1.0.9639, and 100.14.11, as used in Gentoo Linux and possibly other distributions, creates /dev/nvid… Video Driver after 100.14.11 Fix from $1,9502007-07-27 MEDIUM 5.3 CVE-2007-3968 index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded folder via a modified URL containing the folder name. Dirlist Php after 0.1.1 Fix from $1,6002007-07-25 MEDIUM 5.0 CVE-2007-3804 The AntiVirus engine in the HTTP-ALG in Clavister CorePlus before 8.81.00 and 8.80.03 might allow remote attackers to bypass scanning via small files. Clavister Coreplus after 8.81.00 Fix from $1,6002007-07-16 HIGH 10.0 CVE-2007-3500 Xeweb XEForum allows remote attackers to gain privileges via a modified xeforum cookie. Xeforum No fix yet Fix from $1,9502007-06-29 HIGH 10.0 CVE-2007-3455 cgiChkMasterPwd.exe before 8.0.0.142 in Trend Micro OfficeScan Corporate Edition 8.0 allows remote attackers to bypass the password requirement and g… Officescan Patch available Fix from $1,9502007-06-27 MEDIUM 6.8 CVE-2007-3285 Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:… Firefox after 2.0.0.4 Fix from $1,6002007-06-20 MEDIUM 6.9 CVE-2007-3278 PostgreSQL 8.1 and probably later versions, when local trust authentication is enabled and the Database Link library (dblink) is installed, allows re… PostgreSQL 7.3.21 / 7.4.19+ Fix from $1,6002007-06-19 HIGH 7.5 CVE-2007-3242 The Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote a… Webapp Mitigation only Fix from $1,9502007-06-15 HIGH 9.3 CVE-2007-3186 Apple Safari Beta 3.0.1 for Windows allows remote attackers to execute arbitrary commands via shell metacharacters in a URI in the SRC of an IFRAME, … Safari Mitigation only Fix from $1,9502007-06-12 HIGH 9.3 CVE-2007-2279EPSS 6% The Scheduler Service (VxSchedService.exe) in Symantec Storage Foundation for Windows 5.0 allows remote attackers to bypass authentication and execut… Veritas Storage Foundation Patch available Fix from $1,9502007-06-04 HIGH 10.0 CVE-2007-2985 Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's username, which can be used t… Pheap No fix yet Fix from $1,9502007-06-01 HIGH 7.5 CVE-2007-2975 The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allo… Openfire after 3.3.0 Fix from $1,9502007-06-01 MEDIUM 5.0 CVE-2007-2944 WabCMS 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via… Wabcms Mitigation only Fix from $1,6002007-05-31 HIGH 10.0 CVE-2007-2815EPSS 73% The "hit-highlighting" functionality in webhits.dll in Microsoft Internet Information Services (IIS) Web Server 5.0 only uses Windows NT ACL configur… Internet Information Services Mitigation only Fix from $1,9502007-05-22 HIGH 10.0 CVE-2007-2435 Sun Java Web Start in JDK and JRE 5.0 Update 10 and earlier, and Java Web Start in SDK and JRE 1.4.2_13 and earlier, allows remote attackers to perfo… Java Enterprise System after 5.0 Fix from $1,9502007-05-02 MEDIUM 6.0 CVE-2007-2138 Untrusted search path vulnerability in PostgreSQL before 7.3.19, 7.4.x before 7.4.17, 8.0.x before 8.0.13, 8.1.x before 8.1.9, and 8.2.x before 8.2.4… PostgreSQL 7.3.19 / 7.4.17+ Fix from $1,6002007-04-24 HIGH 7.2 CVE-2007-0729 Apple File Protocol (AFP) Client in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment before executing commands, which all… Mac Os X Patch available Fix from $1,9502007-04-24 MEDIUM 6.8 CVE-2007-2108EPSS 22% Unspecified vulnerability in the Core RDBMS component in Oracle Database 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.2 on Windows allows remote attackers … Windows Mitigation only Fix from $1,6002007-04-18 HIGH 7.2 CVE-2007-1206 The Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0; 2000 SP4; XP SP2; Server 2003, 2003 SP1, and 2003 SP2; and Windows V… Windows 2000 Mitigation only Fix from $1,9502007-04-10 HIGH 9.0 CVE-2007-1309 Novell Access Management 3 SSLVPN Server allows remote authenticated users to bypass VPN restrictions by making policy.txt read-only, disconnecting, … Access Manager Patch available Fix from $1,9502007-03-07 MEDIUM 5.0 CVE-2006-7114 P-News 2.0 stores db/user.txt under the web document root with insufficient access control, which allows remote attackers to obtain sensitive informa… P News after 2.0 Fix from $1,6002007-03-06 HIGH 7.5 CVE-2007-1261 Unspecified vulnerability in the reports system in OpenBiblio before 0.6.0 allows attackers to gain privileges via unspecified vectors. Openbiblio after 0.5.2 Fix from $1,9502007-03-03 MEDIUM 6.6 CVE-2006-7098 The Debian GNU/Linux 033_-F_NO_SETSID patch for the Apache HTTP Server 1.3.34-4 does not properly disassociate httpd from a controlling tty when http… Apache Mitigation only Fix from $1,6002007-03-03 MEDIUM 6.6 CVE-2007-1227 VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack o… Virex after 7.7 Fix from $1,6002007-03-02 MEDIUM 5.0 CVE-2006-7047 include.php in Shoutpro 1.0 might allow remote attackers to bypass IP ban restrictions via a URL in the path parameter that points to an alternate ba… Shoutpro Mitigation only Fix from $1,6002007-02-24 HIGH 7.2 CVE-2007-1072 The command line interface (CLI) in Cisco Unified IP Phone 7906G, 7911G, 7941G, 7961G, 7970G, and 7971G, with firmware 8.0(4)SR1 and earlier allows l… Unified Ip Phone Firmware 7906g Patch available Fix from $1,9502007-02-22 HIGH 7.2 CVE-2007-1056 VMware Workstation 5.5.3 build 34685 does not provide per-user restrictions on certain privileged actions, which allows local users to perform restri… Workstation Mitigation only Fix from $1,9502007-02-21 HIGH 10.0 CVE-2007-1045 mAlbum 0.3 has default accounts (1) "login"/"pass" for its administrative account and (2) "dqsfg"/"sdfg", which allows remote attackers to gain privi… Malbum No fix yet Fix from $1,9502007-02-21 HIGH 7.5 CVE-2007-1036EPSS 82% The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to by… Jboss Application Server Mitigation only Fix from $1,9502007-02-21