Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2005-0139 Unknown vulnerability in rpc.mountd in SGI IRIX 6.5.25, 6.5.26, and 6.5.27 does not sufficiently restrict access rights for read-mostly exports, whic… Irix Patch available Fix from $1,9502005-09-21 HIGH 7.5 CVE-2005-2819 DownFile 1.3 allows remote attackers to gain administrator privileges via a direct request to (1) update.php, (2) del.php, and (3) add_form.php. Downfile Mitigation only Fix from $1,9502005-09-07 HIGH 7.2 CVE-2005-2072 The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to… Solaris No fix yet Fix from $1,9502005-06-29 HIGH 7.5 CVE-2005-1532EPSS 9% Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, wh… Firefox Mitigation only Fix from $1,9502005-05-12 MEDIUM 5.0 CVE-2005-1425 Uapplication Uguestbook 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to downlo… Uguestbook No fix yet Fix from $1,6002005-05-03 MEDIUM 5.0 CVE-2005-1426 Uapplication Ublog Reload stores sensitive information under the web root with insufficient access control, which allows remote attackers to download… No fix yet Fix from $1,6002005-05-03 MEDIUM 6.5 CVE-2005-0244 PostgreSQL 8.0.0 and earlier allows local users to bypass the EXECUTE permission check for functions by using the CREATE AGGREGATE command. PostgreSQL Patch available Fix from $1,6002005-05-02 HIGH 10.0 CVE-2005-0735EPSS 8% newsscript.pl for NewsScript allows remote attackers to gain privileges by setting the mode parameter to admin. Newsscript No fix yet Fix from $1,9502005-05-02 HIGH 7.6 CVE-2005-0970 Mac OS X 10.3.9 and earlier allows users to install, create, and execute setuid/setgid scripts, contrary to the intended design, which may allow atta… Mac Os X Mitigation only Fix from $1,9502005-05-02 HIGH 9.3 CVE-2004-1029EPSS 17% The Sun Java Plugin capability in Java 2 Runtime Environment (JRE) 1.4.2_01, 1.4.2_04, and possibly earlier versions, does not properly restrict acce… Linux Patch available Fix from $1,9502005-03-01 MEDIUM 6.6 CVE-2004-1193 Prevx Home 1.0 allows local users with administrator privileges to bypass the intrusion prevention features by directly writing to \device\physicalme… Prevx Home Mitigation only Fix from $1,6002005-01-10 HIGH 7.2 CVE-2004-1767 The kernel in Solaris 2.6, 7, 8, and 9 allows local users to gain privileges by loading arbitrary loadable kernel modules (LKM), possibly involving t… Solaris Patch available Fix from $1,9502004-12-31 MEDIUM 5.0 CVE-2004-2608 SmartWebby Smart Guest Book stores SmartGuestBook.mdb (aka the "news database") under the web document root with insufficient access control, which a… Smart Guest Book No fix yet Fix from $1,6002004-12-31 HIGH 10.0 CVE-2004-2689 NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. Newsphp Mitigation only Fix from $1,9502004-12-31 HIGH 9.3 CVE-2004-2692 The exec_dir PHP patch (php-exec-dir) 4.3.2 through 4.3.7 with safe mode disabled allows remote attackers to bypass restrictions and execute arbitrar… Php Exec Dir Patch available Fix from $1,9502004-12-31 HIGH 7.2 CVE-2004-2693 HP-UX B.11.00 and B.11.11 with B6848AB GTK+ Support Libraries installed uses insecure directory permissions, which allows local users to gain privile… Hp Ux Mitigation only Fix from $1,9502004-12-31 MEDIUM 5.8 CVE-2004-2694EPSS 9% Microsoft Outlook Express 6.0 allows remote attackers to bypass intended access restrictions, load content from arbitrary sources into the Outlook co… Outlook Express Mitigation only Fix from $1,6002004-12-31 HIGH 9.0 CVE-2004-2700 Unrestricted file upload vulnerability in AspDotNetStorefront 3.3 allows remote authenticated administrators to upload arbitrary files with executabl… Aspdotnetstorefront Mitigation only Fix from $1,9502004-12-31 MEDIUM 5.8 CVE-2004-2733 Web Wiz Forums 7.7a uses invalid logic to determine user privileges, which allows remote attackers to (1) block arbitrary IP addresses via pop_up_ip_… Web Wiz Forums Mitigation only Fix from $1,6002004-12-31 HIGH 7.5 CVE-2004-2739 The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors. Phprojekt Patch available Fix from $1,9502004-12-31 MEDIUM 6.4 CVE-2004-2743 upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to… Mega Upload Progress Bar Patch available Fix from $1,6002004-12-31 HIGH 7.5 CVE-2004-0867EPSS 17% Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allo… Firefox Mitigation only Fix from $1,9502004-12-23 MEDIUM 6.5 CVE-2004-1338 The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or … Database Server Patch available Fix from $1,6002004-12-23 HIGH 7.2 CVE-2004-0793 The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execu… Bsdmainutils Patch available Fix from $1,9502004-10-20 HIGH 7.5 CVE-2004-0041 The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenti… Mod Auth Shadow Patch available Fix from $1,9502004-02-03 HIGH 9.3 CVE-2003-1026EPSS 39% Internet Explorer 5.01 through 6 SP1 allows remote attackers to bypass zone restrictions via a javascript protocol URL in a sub-frame, which is added… Ie Mitigation only Fix from $1,9502004-01-20 HIGH 10.0 CVE-2003-1346 D-Link wireless access point DWL-900AP+ 2.2, 2.3 and possibly 2.5 allows remote attackers to set factory default settings by upgrading the firmware u… Dwl 900ap\+ Mitigation only Fix from $1,9502003-12-31 HIGH 7.2 CVE-2003-1356 The "file handling" in sort in HP-UX 10.01 through 10.20, and 11.00 through 11.11 is "incorrect," which allows attackers to gain access or cause a de… Hp Ux Patch available Fix from $1,9502003-12-31 HIGH 7.2 CVE-2003-1358 rs.F300 for HP-UX 10.0 through 11.22 uses the PATH environment variable to find and execute programs such as rm while operating at raised privileges,… Hp Ux No fix yet Fix from $1,9502003-12-31 HIGH 8.8 CVE-2003-1378EPSS 16% Microsoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi… Outlook No fix yet Fix from $1,9502003-12-31