Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2003-1383 WEB-ERP 0.1.4 and earlier allows remote attackers to obtain sensitive information via an HTTP request for the logicworks.ini file, which contains the… Web Erp after 0.1.4 Fix from $1,9502003-12-31 MEDIUM 6.4 CVE-2003-1386EPSS 8% AXIS 2400 Video Server 2.00 through 2.33 allows remote attackers to obtain sensitive information via an HTTP request to /support/messages, which disp… 2400 Video Server Mitigation only Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1423 Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensi… Petitforum No fix yet Fix from $1,6002003-12-31 HIGH 7.2 CVE-2003-1474 slashem-tty in the FreeBSD Ports Collection is installed with write permissions for the games group, which allows local users with group games privil… Slashem Tty Mitigation only Fix from $1,9502003-12-31 HIGH 10.0 CVE-2003-1495EPSS 5% Unspecified vulnerability in the non-SSL web agent in various HP Management Agent products allows local users or remote attackers to gain privileges … Insight Management Suite Patch available Fix from $1,9502003-12-31 HIGH 7.8 CVE-2003-1515 Origo ASR-8100 ADSL Router 3.21 has an administration service running on port 254 that does not require a password, which allows remote attackers to … Asr 8100 No fix yet Fix from $1,9502003-12-31 MEDIUM 6.3 CVE-2003-1524 PGPi PGPDisk 6.0.2i does not unmount a PGP partition when the switch user function in Windows XP is used, which could allow local users to access dat… Pgpdisk Mitigation only Fix from $1,6002003-12-31 MEDIUM 5.0 CVE-2003-1541 PlanetMoon Guestbook tr3.a stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain … Guestbook Mitigation only Fix from $1,6002003-12-31 MEDIUM 6.8 CVE-2003-1552 Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an … Uploader Mitigation only Fix from $1,6002003-12-31 HIGH 10.0 CVE-2003-1081 Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file. Solaris Patch available Fix from $1,9502003-09-09 HIGH 7.2 CVE-2003-0230 Microsoft SQL Server 7, 2000, and MSDE allows local users to gain privileges by hijacking a named pipe during the authentication of another user, aka… Data Engine Mitigation only Fix from $1,9502003-08-27 HIGH 7.2 CVE-2003-0497 Caché Database 5.x installs /cachesys/bin/cache with world-writable permissions, which allows local users to gain privileges by modifying cache and e… Cache Database Mitigation only Fix from $1,9502003-08-07 HIGH 7.5 CVE-2002-1877 NETGEAR FM114P allows remote attackers to bypass access restrictions for web sites via a URL that uses the IP address instead of the hostname. Fm114p Mitigation only Fix from $1,9502002-12-31 HIGH 7.5 CVE-2002-1978 IPFilter 3.1.1 through 3.4.28 allows remote attackers to bypass firewall rules by sending a PASV command string as the argument of another command to… Ipfilter Patch available Fix from $1,9502002-12-31 MEDIUM 6.4 CVE-2002-2242 The Apple Package Manager in KisMAC 0.02a and earlier modifies file permissions of sensitive files after installation, which could allow attackers to… Kismac after 0.2a Fix from $1,6002002-12-31 HIGH 7.5 CVE-2002-2261 Sendmail 8.9.0 through 8.12.6 allows remote attackers to bypass relaying restrictions enforced by the 'check_relay' function by spoofing a blank DNS … Sendmail Patch available Fix from $1,9502002-12-31 MEDIUM 6.4 CVE-2002-2265 Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F al… Open Source Internet Solutions Patch available Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2302 3D3.Com ShopFactory 5.5 through 5.8 allows remote attackers to modify the prices in their shopping carts by modifying the price in a hidden form fiel… Shopfactory Mitigation only Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2311EPSS 10% Microsoft Internet Explorer 6.0 and possibly others allows remote attackers to upload arbitrary file contents when users press a key corresponding to… Internet Explorer No fix yet Fix from $1,6002002-12-31 HIGH 7.8 CVE-2002-2320 MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3. Mysimplenews No fix yet Fix from $1,9502002-12-31 MEDIUM 5.0 CVE-2002-2344 Ensim WEBppliance 3.0 and 3.1 allows remote attackers to read mail intended for other users by defining an alias that is the target's email address. Webppliance Mitigation only Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2353EPSS 7% tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requests. Tftpd32 Patch available Fix from $1,6002002-12-31 MEDIUM 6.4 CVE-2002-2356 HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi. Hamweather Mitigation only Fix from $1,6002002-12-31 HIGH 9.3 CVE-2002-2360 The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to read and write to arbitrary f… Webmin No fix yet Fix from $1,9502002-12-31 MEDIUM 5.8 CVE-2002-2361 The installer in Yahoo! Messenger 4.0, 5.0 and 5.5 does not verify package signatures which could allow remote attackers to install trojan programs v… Messenger Mitigation only Fix from $1,6002002-12-31 HIGH 7.2 CVE-2002-2363 VJE.VJE-RUN in HP-UX 11.00 adds bin to /etc/PATH, which could allow local users to gain privileges. Hp Ux Patch available Fix from $1,9502002-12-31 MEDIUM 5.0 CVE-2002-2394 InterScan VirusWall 3.6 for Linux and 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTT… Interscan Viruswall Mitigation only Fix from $1,6002002-12-31 MEDIUM 5.0 CVE-2002-2395 InterScan VirusWall 3.52 for Windows allows remote attackers to bypass virus protection and possibly execute arbitrary code via HTTP 1.1 gzip content… Interscan Viruswall Mitigation only Fix from $1,6002002-12-31 MEDIUM 6.9 CVE-2002-2407 Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch … Rtos Mitigation only Fix from $1,6002002-12-31 HIGH 10.0 CVE-2002-2425 Sun AnswerBook2 1.2 through 1.4.2 allows remote attackers to execute administrative scripts such as (1) AdminViewError and (2) AdminAddadmin via a di… Solaris Answerbook2 Patch available Fix from $1,9502002-12-31