Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.5 CVE-2012-4974 Layton Helpbox 4.4.0 allows remote authenticated users to change the login context and gain privileges via a modified (1) loggedinenduser, (2) logged… Helpbox Mitigation only Fix from $1,6002012-12-12 MEDIUM 6.9 CVE-2012-3317 IBM WebSphere Message Broker 6.1 before 6.1.0.11, 7.0 before 7.0.0.5, and 8.0 before 8.0.0.2 has incorrect ownership of certain uninstaller Java Runt… Websphere Message Broker Mitigation only Fix from $1,6002012-12-05 HIGH 7.5 CVE-2012-1598 Joomla! 1.5.x before 1.5.26 has unspecified impact and attack vectors related to "insufficient randomness" and a "password reset vulnerability." Joomla\! Mitigation only Fix from $1,9502012-12-03 MEDIUM 5.0 CVE-2012-1599 Joomla! 1.5.x before 1.5.26 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end information" via… Joomla\! Mitigation only Fix from $1,6002012-12-03 MEDIUM 5.0 CVE-2012-4475 The Security Questions module for Drupal 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.1 does not properly restrict access, which allows remote att… Security Questions Patch available Fix from $1,6002012-11-30 MEDIUM 5.0 CVE-2012-4477 Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack v… Drag \& Drop Gallery Patch available Fix from $1,6002012-11-30 HIGH 7.5 CVE-2012-4470 The Listhandler module 6.x-1.x before 6.x-1.1 for Drupal does not properly check permissions when importing emails, which allows remote comment autho… Listhandler Patch available Fix from $1,9502012-11-30 MEDIUM 5.0 CVE-2012-4471 The Search Autocomplete module 7.x-2.x before 7.x-2.4 for Drupal does not properly restrict access to the module admin page, which allows remote atta… Search Autocomplete Patch available Fix from $1,6002012-11-30 HIGH 7.5 CVE-2012-4964EPSS 8% The Samsung printer firmware before 20121031 has a hardcoded read-write SNMP community, which makes it easier for remote attackers to obtain administ… Printer Firmware after 20121030 Fix from $1,9502012-11-28 MEDIUM 5.0 CVE-2012-4522 The rb_get_path_check function in file.c in Ruby 1.9.3 before patchlevel 286 and Ruby 2.0.0 before r37163 allows context-dependent attackers to creat… Ruby Mitigation only Fix from $1,6002012-11-24 MEDIUM 6.0 CVE-2012-2244 Mahara 1.4.x before 1.4.5 and 1.5.x before 1.5.4 allows remote authenticated administrators to execute arbitrary programs by modifying the path to cl… Mahara Patch available Fix from $1,6002012-11-24 MEDIUM 6.9 CVE-2012-3516 The GNTTABOP_swap_grant_ref sub-operation in the grant table hypercall in Xen 4.2 and Citrix XenServer 6.0.2 allows local guest kernels or administra… Xenserver after 6.0.2 Fix from $1,6002012-11-23 HIGH 7.5 CVE-2011-4605 The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web P… Jboss Enterprise Application Platform after 5.2.0 Fix from $1,9502012-11-23 HIGH 9.0 CVE-2012-5759 The IBM WebSphere DataPower XC10 Appliance 2.0.0.0 through 2.0.0.3 and 2.1.0.0 through 2.1.0.2 allows remote authenticated users to bypass intended a… Websphere Datapower Xc10 Appliance Mitigation only Fix from $1,9502012-11-23 HIGH 10.0 CVE-2012-5863EPSS 25% These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges t… Sinapsi Firmware after 2.0.2870 Fix from $1,9502012-11-23 HIGH 10.0 CVE-2012-5864 These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within t… Sinapsi Firmware after 2.0.2870 Fix from $1,9502012-11-23 HIGH 7.2 CVE-2012-3512 Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to e… Munin after 2.0.5 Fix from $1,9502012-11-21 HIGH 9.3 CVE-2012-3513 munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files… Munin after 2.0.5 Fix from $1,9502012-11-21 MEDIUM 6.5 CVE-2012-5479 The Portfolio plugin in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to upload and execute… Moodle Mitigation only Fix from $1,6002012-11-21 MEDIUM 6.4 CVE-2012-5480 The Database activity module in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote attackers to bypass intended rest… Moodle Mitigation only Fix from $1,6002012-11-21 HIGH 9.3 CVE-2012-4210 The Style Inspector in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 does not properly restrict the context of HTML markup and Casc… Firefox after 16.0.2 Fix from $1,9502012-11-21 MEDIUM 6.5 CVE-2012-5471 The Dropbox Repository File Picker in Moodle 2.1.x before 2.1.9, 2.2.x before 2.2.6, and 2.3.x before 2.3.3 allows remote authenticated users to acce… Moodle Patch available Fix from $1,6002012-11-21 MEDIUM 6.8 CVE-2012-4203 The New Tab page in Mozilla Firefox before 17.0 uses a privileged context for execution of JavaScript code by bookmarklets, which allows user-assiste… Firefox after 16.0.2 Fix from $1,6002012-11-21 MEDIUM 5.8 CVE-2012-4510 cups-pk-helper before 0.2.3 does not properly wrap the (1) cupsGetFile and (2) cupsPutFile function calls, which allows user-assisted remote attacker… Cups Pk Helper after 0.2.2 Fix from $1,6002012-11-20 MEDIUM 6.4 CVE-2012-4523 radsecproxy before 1.6.1 does not properly verify certificates when there are configuration blocks with CA settings that are unrelated to the block b… Radsecproxy after 1.6 Fix from $1,6002012-11-20 MEDIUM 6.4 CVE-2012-4566 The DTLS support in radsecproxy before 1.6.2 does not properly verify certificates when there are configuration blocks with CA settings that are unre… Radsecproxy after 1.6.1 Fix from $1,6002012-11-20 HIGH 7.2 CVE-2012-5519 CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator key in /var/run/cups/certs/0… Cups No fix yet Fix from $1,9502012-11-20 HIGH 7.2 CVE-2012-4225 NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by… Unix Graphic Driver after 304.32 Fix from $1,9502012-11-19 MEDIUM 5.0 CVE-2011-2486 nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from dete… Nspluginwrapper Patch available Fix from $1,6002012-11-19 HIGH 9.3 CVE-2012-5897 The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and earlier do not properly implem… Intrust after 10.4.0.853 Fix from $1,9502012-11-17