Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2005-0139
Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, whic…
Irix
Patch available
HIGH 7.5
CVE-2005-2819
DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php.
Downfile
Mitigation only
HIGH 7.2
CVE-2005-2072
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to…
Solaris
No fix yet
HIGH 7.5
CVE-2005-1532EPSS 9%
Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh…
Firefox
Mitigation only
MEDIUM 5.0
CVE-2005-1425
Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo…
Uguestbook
No fix yet
MEDIUM 5.0
CVE-2005-1426
Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download…
No fix yet
MEDIUM 6.5
CVE-2005-0244
PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command.
PostgreSQL
Patch available
HIGH 10.0
CVE-2005-0735EPSS 8%
newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin.
Newsscript
No fix yet
HIGH 7.6
CVE-2005-0970
Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta…
Mac Os X
Mitigation only
HIGH 9.3
CVE-2004-1029EPSS 17%
The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict acce…
Linux
Patch available
MEDIUM 6.6
CVE-2004-1193
Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalme…
Prevx Home
Mitigation only
HIGH 7.2
CVE-2004-1767
The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving t…
Solaris
Patch available
MEDIUM 5.0
CVE-2004-2608
SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which a…
Smart Guest Book
No fix yet
HIGH 10.0
CVE-2004-2689
NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value.
Newsphp
Mitigation only
HIGH 9.3
CVE-2004-2692
The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrar…
Php Exec Dir
Patch available
HIGH 7.2
CVE-2004-2693
HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privile…
Hp Ux
Mitigation only
MEDIUM 5.8
CVE-2004-2694EPSS 9%
Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook co…
Outlook Express
Mitigation only
HIGH 9.0
CVE-2004-2700
Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executabl…
Aspdotnetstorefront
Mitigation only
MEDIUM 5.8
CVE-2004-2733
Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_…
Web Wiz Forums
Mitigation only
HIGH 7.5
CVE-2004-2739
The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors.
Phprojekt
Patch available
MEDIUM 6.4
CVE-2004-2743
upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to…
Mega Upload Progress Bar
Patch available
HIGH 7.5
CVE-2004-0867EPSS 17%
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo…
Firefox
Mitigation only
MEDIUM 6.5
CVE-2004-1338
The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or …
Database Server
Patch available
HIGH 7.2
CVE-2004-0793
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu…
Bsdmainutils
Patch available
HIGH 7.5
CVE-2004-0041
The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenti…
Mod Auth Shadow
Patch available
HIGH 9.3
CVE-2003-1026EPSS 39%
Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added…
Ie
Mitigation only
HIGH 10.0
CVE-2003-1346
D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware u…
Dwl 900ap\+
Mitigation only
HIGH 7.2
CVE-2003-1356
The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a de…
Hp Ux
Patch available
HIGH 7.2
CVE-2003-1358
rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges,…
Hp Ux
No fix yet
HIGH 8.8
CVE-2003-1378EPSS 16%
Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…
Outlook
No fix yet