Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.5 CVE-2012-5385 install/index.php in Craig Knudsen WebCalendar before 1.2.5 allows remote attackers to modify settings.php and possibly execute arbitrary code via ve… Webcalendar Mitigation only Fix from $1,9502012-10-11 HIGH 9.3 CVE-2012-3991 Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 d… Firefox 10.0.8 / 16.0+ Fix from $1,9502012-10-10 MEDIUM 5.0 CVE-2010-5065 popup.php in Virtual War (aka VWar) 1.6.1 R2 allows remote attackers to bypass intended member restrictions and read news posts via a modified newsid… Virtual War No fix yet Fix from $1,6002012-10-08 MEDIUM 5.0 CVE-2012-1623 The Registration Codes module before 6.x-2.4 for Drupal does not restrict access to the registration code list, which might allow remote attackers to… Regcode after 6.x-2.3 Fix from $1,6002012-10-06 MEDIUM 6.9 CVE-2012-4443 Monkey HTTP Daemon 0.9.3 uses a real UID of root and a real GID of root during execution of CGI scripts, which might allow local users to gain privil… Monkey Mitigation only Fix from $1,6002012-10-05 MEDIUM 5.0 CVE-2012-5298 Mavili Guestbook, as released in November 2007, stores guestbook.mdb under the web root with insufficient access control, which allows remote attacke… Mavili Guestbook No fix yet Fix from $1,6002012-10-04 HIGH 7.5 CVE-2012-5299 Mavili Guestbook, as released in November 2007, allows remote attackers to edit, delete, and approve arbitrary messages via a direct request to (1) e… Mavili Guestbook No fix yet Fix from $1,9502012-10-04 HIGH 7.2 CVE-2012-0692 CA License (aka CA Licensing) before 1.90.03 allows local users to modify or create arbitrary files, and consequently gain privileges, via unspecifie… License Software after 1.90.02 Fix from $1,9502012-10-02 HIGH 7.2 CVE-2012-0691 CA License (aka CA Licensing) before 1.90.03 does not properly restrict system commands, which allows local users to gain privileges via unspecified … License Software after 1.90.02 Fix from $1,9502012-10-02 MEDIUM 5.0 CVE-2012-4063 The Apache Santuario configuration in Eucalyptus before 3.1.1 does not properly restrict applying XML Signature transforms to documents, which allows… Eucalyptus after 3.1.0 Fix from $1,6002012-10-01 MEDIUM 6.5 CVE-2012-4064 Eucalyptus before 3.1.1 does not properly restrict the binding of external SOAP web-services messages, which allows remote authenticated users to gai… Eucalyptus after 3.1.0 Fix from $1,6002012-10-01 MEDIUM 6.9 CVE-2011-4945 PolicyKit 0.103 sets the AdminIdentities to "wheel" by default, which allows local users in the wheel group to gain root privileges without authentic… Policykit Patch available Fix from $1,6002012-10-01 MEDIUM 6.0 CVE-2012-1576 The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly cle… Atheme Mitigation only Fix from $1,6002012-10-01 MEDIUM 6.0 CVE-2012-4450 389 Directory Server 1.2.10 does not properly update the ACL when a DN entry is moved by a modrdn operation, which allows remote authenticated users … 389 Directory Server Patch available Fix from $1,6002012-10-01 MEDIUM 5.0 CVE-2012-1591 The image module in Drupal 7.x before 7.14 does not properly check permissions when caching derivative image styles of private images, which allows r… Drupal Patch available Fix from $1,6002012-10-01 MEDIUM 5.0 CVE-2012-1833 VMware SpringSource Grails before 1.3.8, and 2.x before 2.0.2, does not properly restrict data binding, which might allow remote attackers to bypass … Grails after 1.3.7 Fix from $1,6002012-09-28 MEDIUM 5.0 CVE-2012-2680 Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which a… Enterprise Mrg after 0.1.5192-4 Fix from $1,6002012-09-28 MEDIUM 6.8 CVE-2012-0956 ubiquity-slideshow-ubuntu before 58.2, during installation, allows remote man-in-the-middle attackers to execute arbitrary web script or HTML and rea… Ubiquity Slideshow Ubuntu after 58.1 Fix from $1,6002012-09-28 MEDIUM 5.0 CVE-2012-3742 Safari in Apple iOS before 6 does not properly restrict use of an unspecified Unicode character that looks similar to the https lock indicator, which… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 5.0 CVE-2012-3743 The System Logs implementation in Apple iOS before 6 does not restrict /var/log access by sandboxed apps, which allows remote attackers to obtain sen… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 6.9 CVE-2012-3728 The kernel in Apple iOS before 6 dereferences invalid pointers during the handling of packet-filter data structures, which allows local users to gain… Iphone Os after 5.1.1 Fix from $1,6002012-09-20 MEDIUM 5.0 CVE-2012-5007 The Fill PDF module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to write to arbitrary PDF files via unspecified vectors related to the … Fillpdf Patch available Fix from $1,6002012-09-20 HIGH 7.5 CVE-2012-4993 torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers to have an unspecified impact. Rivettracker after 1.03 Fix from $1,9502012-09-19 MEDIUM 5.5 CVE-2012-4408 course/reset.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 checks an update capability instead of a reset capability, … Moodle Patch available Fix from $1,6002012-09-19 MEDIUM 6.9 CVE-2012-4425 libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute … Spice Gtk Patch available Fix from $1,6002012-09-18 MEDIUM 6.9 CVE-2012-3524 libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileg… Libdbus after 1.5.12 Fix from $1,6002012-09-18 MEDIUM 5.0 CVE-2012-3030 WebNavigator in Siemens WinCC 7.0 SP3 and earlier, as used in SIMATIC PCS7 and other products, stores sensitive information under the web root with i… Simatic Pcs7 after 7.0 Fix from $1,6002012-09-18 HIGH 7.5 CVE-2012-2994EPSS 6% The CoSoSys Endpoint Protector 4 appliance establishes an EPProot password based entirely on the appliance serial number, which makes it easier for r… Endpoint Protector Appliace 4 Mitigation only Fix from $1,9502012-09-18 MEDIUM 5.0 CVE-2012-2058 The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors. Ubercart Payflow Mitigation only Fix from $1,6002012-09-17 MEDIUM 5.0 CVE-2010-5078 SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 stores sensitive information under the web root with insufficient access control, which allow… Silverstripe Mitigation only Fix from $1,6002012-09-17