Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2012-5901 DFLabs PTK 1.0.5 stores data files with predictable names under the web document root with insufficient access control, which allows remote attackers… Ptk Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5892 Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to dow… Cms after 1.1.0 Fix from $1,6002012-11-17 MEDIUM 5.0 CVE-2012-5885EPSS 9% The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.… Tomcat Mitigation only Fix from $1,6002012-11-17 MEDIUM 5.5 CVE-2012-5522 MantisBT before 1.2.12 does not use an expected default value during decisions about whether a user may modify the status of a bug, which allows remo… Mantisbt after 1.2.11 Fix from $1,6002012-11-16 MEDIUM 5.5 CVE-2012-5523 core/email_api.php in MantisBT before 1.2.12 does not properly manage the sending of e-mail notifications about restricted bugs, which might allow re… Mantisbt after 1.2.11 Fix from $1,6002012-11-16 HIGH 8.3 CVE-2012-5458 VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows use weak permissions for unspecified process threads, which allows … Player Mitigation only Fix from $1,9502012-11-14 HIGH 9.3 CVE-2012-1895EPSS 23% The reflection implementation in Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4 does not properly enforce object permissions, which… .net Framework Mitigation only Fix from $1,9502012-11-14 HIGH 9.3 CVE-2012-4777EPSS 25% The code-optimization feature in the reflection implementation in Microsoft .NET Framework 4 and 4.5 does not properly enforce object permissions, wh… .net Framework Mitigation only Fix from $1,9502012-11-14 MEDIUM 5.0 CVE-2012-1810 EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP por… Eoscada after 11.0.19.1 Fix from $1,6002012-11-13 MEDIUM 5.0 CVE-2012-4734 Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warn… Rt Mitigation only Fix from $1,6002012-11-11 MEDIUM 5.5 CVE-2012-5482 The v2 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image… Essex Patch available Fix from $1,6002012-11-11 MEDIUM 5.5 CVE-2012-4573 The v1 API in OpenStack Glance Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to delete arbitrary non-protected image… Essex Patch available Fix from $1,6002012-11-11 MEDIUM 6.8 CVE-2012-4553 Drupal 7.x before 7.16 allows remote attackers to obtain sensitive information and possibly re-install Drupal and execute arbitrary PHP code via an e… Drupal Patch available Fix from $1,6002012-11-11 MEDIUM 5.0 CVE-2012-4554EPSS 16% The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE declaration in an XRDS file. Drupal Patch available Fix from $1,6002012-11-11 MEDIUM 6.8 CVE-2012-3523 The STARTTLS implementation in nnrpd in INN before 2.5.3 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert… Inn after 2.5.2 Fix from $1,6002012-11-11 MEDIUM 6.4 CVE-2012-2455 Advanced Productivity Software DTE Axiom before 12.3.3 does not validate the registration ID, which allows remote attackers to bypass authentication … Dte Axiom after 12.3.2 Fix from $1,6002012-11-10 MEDIUM 6.4 CVE-2012-4022 Pebble before 2.6.4 allows remote attackers to trigger loss of blog-entry viewability via a crafted comment. Pebble after 2.6.3 Fix from $1,6002012-11-08 HIGH 7.5 CVE-2012-5117 Google Chrome before 23.0.1271.64 does not properly restrict the loading of an SVG subresource in the context of an IMG element, which has unspecifie… Chrome after 23.0.1271.62 Fix from $1,9502012-11-07 HIGH 10.0 CVE-2012-5278EPSS 9% Adobe Flash Player before 10.3.183.43 and 11.x before 11.5.502.110 on Windows and Mac OS X, before 10.3.183.43 and 11.x before 11.2.202.251 on Linux,… Flash Player 3.5.0.600 / 10.3.183.43+ Fix from $1,9502012-11-07 HIGH 7.5 CVE-2012-4498 The Activism module 6.x-2.x before 6.x-2.1 for Drupal does not properly restrict access to the "Campaign" content type, which might allow remote atta… Activism Patch available Fix from $1,9502012-11-02 HIGH 10.0 CVE-2012-5417 Cisco Prime Data Center Network Manager (DCNM) before 6.1(1) does not properly restrict access to certain JBoss MainDeployer functionality, which all… Prime Data Center Network Manager Mitigation only Fix from $1,9502012-11-02 MEDIUM 5.0 CVE-2012-4488 The Location module 6.x before 6.x-3.2 and 7.x before 7.x-3.0-alpha1 for Drupal does not properly check user or node access permissions, which allows… Location Patch available Fix from $1,6002012-10-31 MEDIUM 5.8 CVE-2012-4491 The Monthly Archive by Node Type module 6.x for Drupal does not properly check permissions defined by node_access modules, which allows remote attack… Monthly Archive By Node Type Mitigation only Fix from $1,6002012-10-31 MEDIUM 5.0 CVE-2012-4499 The contact formatter page in the Email Field module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to email th… Email Patch available Fix from $1,6002012-10-31 MEDIUM 5.0 CVE-2012-4483 The commons_discussion_views_default_views function in modules/features/commons_discussion/commons_discussion.views_default.inc in the Drupal Commons… Commons Patch available Fix from $1,6002012-10-31 HIGH 10.0 CVE-2012-4501EPSS 8% Citrix Cloud.com CloudStack, and Apache CloudStack pre-release, allows remote attackers to make arbitrary API calls by leveraging the system user acc… Cloudstack Mitigation only Fix from $1,9502012-10-26 HIGH 7.5 CVE-2012-5302 The server in TIBCO Formvine 3.1.x and 3.2.x before 3.2.1 does not properly implement access control, which allows remote attackers to obtain sensiti… Formvine Mitigation only Fix from $1,9502012-10-24 HIGH 7.5 CVE-2012-5168 ATutor AContent before 1.2-1 allows remote attackers to modify arbitrary user passwords or category names via a direct request to (1) user/index_inli… Acontent after 1.2 Fix from $1,9502012-10-22 MEDIUM 6.5 CVE-2012-5454 user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arb… Acontent No fix yet Fix from $1,6002012-10-22 MEDIUM 6.8 CVE-2012-4845 The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attacke… Vios Mitigation only Fix from $1,6002012-10-20