Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2006-2095 Phex before 2.8.6 allows remote attackers to cause a denial of service (application hang) by initiating multiple chat requests to a single user and t… Phex after 2.8.4 Fix from $1,6002006-04-29 MEDIUM 6.8 CVE-2006-1888 phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php wit… Phpgraphy after 0.9.11 Fix from $1,6002006-04-20 HIGH 9.3 CVE-2006-1726EPSS 7% Unspecified vulnerability in Firefox and Thunderbird 1.5 before 1.5.0.2, and SeaMonkey before 1.0.1, allows remote attackers to bypass the js_ValueTo… Firefox Patch available Fix from $1,9502006-04-14 MEDIUM 6.8 CVE-2006-1733EPSS 5% Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 does not properly protec… Firefox after 1.7.12 Fix from $1,6002006-04-14 HIGH 9.3 CVE-2006-1735EPSS 9% Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 allows remote attackers … Firefox after 1.7.12 Fix from $1,9502006-04-14 HIGH 7.2 CVE-2006-1380 ISNTSmtp directory in Trend Micro InterScan Messaging Security Suite (IMSS) 5.5 build 1183 and possibly other versions before 5.7.0.1121, uses insecu… Interscan Messaging Security Suite Patch available Fix from $1,9502006-03-24 HIGH 7.2 CVE-2006-1079 htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacter… Thttpd No fix yet Fix from $1,9502006-03-09 MEDIUM 5.0 CVE-2006-0859 Michael Salzer Guestbox 0.6, and other versions before 0.8, allows remote attackers to post an admin comment to a guestbook entry via a certain modif… Guestbox Patch available Fix from $1,6002006-02-23 HIGH 10.0 CVE-2006-0697EPSS 5% Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impact via unspecified vectors, p… Zen Cart after 1.2.6d Fix from $1,9502006-02-15 MEDIUM 5.0 CVE-2006-0700EPSS 7% imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which returns an XML document that lists … Imagevue No fix yet Fix from $1,6002006-02-15 HIGH 7.2 CVE-2006-0008 The ShellAbout API call in Korean Input Method Editor (IME) in Korean versions of Microsoft Windows XP SP1 and SP2, Windows Server 2003 up to SP1, an… Office Patch available Fix from $1,9502006-02-14 MEDIUM 6.5 CVE-2006-0553 PostgreSQL 8.1.0 through 8.1.2 allows authenticated database users to gain additional privileges via "knowledge of the backend protocol" using a craf… PostgreSQL Patch available Fix from $1,6002006-02-14 HIGH 7.5 CVE-2006-0527EPSS 8% BIND 4 (BIND4) and BIND 8 (BIND8), if used as a target forwarder, allows remote attackers to gain privileged access via a "Kashpureff-style DNS cache… Bind Patch available Fix from $1,9502006-02-02 MEDIUM 5.0 CVE-2006-0114 The vCard functions in Joomla! 1.0.5 use predictable sequential IDs for vcards and do not restrict access to them, which allows remote attackers to o… Joomla Mitigation only Fix from $1,6002006-01-09 MEDIUM 5.0 CVE-2005-1753 ReadMessage.jsp in JavaMail API 1.1.3 through 1.3, as used by Apache Tomcat 5.0.16, allows remote attackers to view other users' e-mail attachments v… Javamail Mitigation only Fix from $1,6002005-12-31 HIGH 7.2 CVE-2005-2932 Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default pe… Zonealarm after 7.0.337.0 Fix from $1,9502005-12-31 HIGH 7.5 CVE-2005-3058 Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) H… Fortios after 3_beta Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-4850 eZ publish 3.5 through 3.7 before 20050608 requires both edit and create permissions in order to submit data, which allows remote attackers to edit d… Ez Publish after 3.7 Fix from $1,6002005-12-31 MEDIUM 5.0 CVE-2005-4852 The siteaccess URIMatching implementation in eZ publish 3.5 through 3.8 before 20050812 converts all non-alphanumeric characters in a URI to '_' (und… Ez Publish 3.5.8+ Fix from $1,6002005-12-31 HIGH 9.4 CVE-2005-4853 The default configuration of the forum package in eZ publish 3.5 before 3.5.5, 3.6 before 3.6.2, 3.7 before 3.7.0rc2, and 3.8 before 20050818 does no… Ez Publish Mitigation only Fix from $1,9502005-12-31 MEDIUM 5.0 CVE-2005-4854 eZ publish 3.5 through 3.7 before 20050830 does not use a folder's read permissions to restrict notifications, which allows remote authenticated user… Ez Publish Mitigation only Fix from $1,6002005-12-31 HIGH 7.5 CVE-2005-4217 Perl in Apple Mac OS X Server 10.3.9 does not properly drop privileges when using the "$<" variable to set uid, which allows attackers to gain privil… Mac Os X Server Mitigation only Fix from $1,9502005-12-14 HIGH 7.1 CVE-2005-4089EPSS 22% Microsoft Internet Explorer allows remote attackers to bypass cross-domain security restrictions and obtain sensitive information by using the @impor… Ie No fix yet Fix from $1,9502005-12-08 MEDIUM 6.5 CVE-2005-4093 Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modi… Secureclient Ng Mitigation only Fix from $1,6002005-12-08 HIGH 7.5 CVE-2005-2929 Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynx… Lynx Patch available Fix from $1,9502005-11-18 HIGH 7.2 CVE-2005-2936 Unquoted Windows search path vulnerability in RealNetworks RealPlayer 10.5 6.0.12.1040 through 6.0.12.1348, RealPlayer 10, RealOne Player v2, RealOne… Realone Player Mitigation only Fix from $1,9502005-11-18 HIGH 7.2 CVE-2005-2938 Unquoted Windows search path vulnerability in iTunesHelper.exe in iTunes 4.7.1.30 and iTunes 5 for Windows might allow local users to gain privileges… Itunes Mitigation only Fix from $1,9502005-11-18 MEDIUM 5.8 CVE-2005-3567 slapd daemon in IBM Tivoli Directory Server (ITDS) 5.2.0 and 6.0.0 binds using SASL EXTERNAL, which allows attackers to bypass authentication and mod… Tivoli Directory Server Patch available Fix from $1,6002005-11-16 HIGH 7.2 CVE-2005-2741 Authorization Services in securityd for Apple Mac OS X 10.3.9 allows local users to gain privileges by granting themselves certain rights that should… Mac Os X Patch available Fix from $1,9502005-10-26 MEDIUM 5.0 CVE-2005-3273 The rose_rt_ioctl function in rose_route.c for Radionet Open Source Environment (ROSE) in Linux 2.6 kernels before 2.6.12, and 2.4 before 2.4.29, doe… Linux Kernel Patch available Fix from $1,6002005-10-21