Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.0 CVE-2011-4961 SilverStripe 2.3.x before 2.3.12 and 2.4.x before 2.4.6 allows remote authenticated users with the EDIT_PERMISSIONS permission to gain administrator … Silverstripe Patch available Fix from $1,6002012-09-17 MEDIUM 6.5 CVE-2010-5106 The XML-RPC remote publishing interface in xmlrpc.php in WordPress before 3.0.3 does not properly check capabilities, which allows remote authenticat… WordPress after 3.0.2 Fix from $1,6002012-09-14 MEDIUM 5.0 CVE-2012-4903 Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor… Chrome after 18.0.1025306 Fix from $1,6002012-09-13 MEDIUM 5.0 CVE-2012-4906 Google Chrome before 18.0.1025308 on Android does not properly restrict access to file: URLs, which allows remote attackers to obtain sensitive infor… Chrome after 18.0.1025306 Fix from $1,6002012-09-13 HIGH 9.3 CVE-2012-4907 Google Chrome before 18.0.1025308 on Android does not properly restrict access from JavaScript code to Android APIs, which allows remote attackers to… Chrome after 18.0.1025306 Fix from $1,9502012-09-13 HIGH 7.5 CVE-2012-4908 Google Chrome before 18.0.1025308 on Android allows remote attackers to bypass the Same Origin Policy and obtain access to local files via vectors in… Chrome after 18.0.1025306 Fix from $1,9502012-09-13 MEDIUM 6.0 CVE-2012-4404 security/__init__.py in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "… Moinmoin Mitigation only Fix from $1,6002012-09-10 MEDIUM 5.0 CVE-2012-1581 MediaWiki 1.17.x before 1.17.3 and 1.18.x before 1.18.2 uses weak random numbers for password reset tokens, which makes it easier for remote attacker… Mediawiki Mitigation only Fix from $1,6002012-09-09 MEDIUM 5.0 CVE-2012-1611 Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via … Joomla\! Mitigation only Fix from $1,6002012-09-06 MEDIUM 5.0 CVE-2012-4752 appconfig.php in ownCloud before 4.0.6 does not properly restrict access, which allows remote authenticated users to edit app configurations via unsp… Owncloud after 4.0.5 Fix from $1,6002012-09-05 MEDIUM 5.0 CVE-2012-4387EPSS 8% Apache Struts 2.0.0 through 2.3.4 allows remote attackers to cause a denial of service (CPU consumption) via a long parameter name, which is processe… Struts Patch available Fix from $1,6002012-09-05 MEDIUM 5.0 CVE-2012-2063 The Slidebox module before 7.x-1.4 for Drupal does not properly check permissions, which allows remote attackers to obtain sensitive information via … Slidebox after 7.x-1.3 Fix from $1,6002012-09-05 MEDIUM 5.0 CVE-2012-4747 Bugzilla 2.x and 3.x through 3.6.11, 3.7.x and 4.0.x before 4.0.8, 4.1.x and 4.2.x before 4.2.3, and 4.3.x before 4.3.3 stores potentially sensitive … Bugzilla Patch available Fix from $1,6002012-09-04 MEDIUM 5.0 CVE-2011-5144 Open Business Management (OBM) 2.4.0-rc13 and earlier allows remote attackers to obtain configuration information via a direct request to test.php, w… Open Business Management after 2.4.0 Fix from $1,6002012-08-31 MEDIUM 5.0 CVE-2012-2704 The Advertisement module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access to debug information, which allows remote attackers to o… Advertisement Patch available Fix from $1,6002012-08-31 MEDIUM 6.0 CVE-2012-4737 channels/chan_iax2.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert7, Asterisk Di… Asterisk Mitigation only Fix from $1,6002012-08-31 HIGH 7.6 CVE-2012-3973 The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to… Firefox after 14.0 Fix from $1,9502012-08-29 MEDIUM 6.8 CVE-2012-3978 The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x befor… Firefox after 14.0 Fix from $1,6002012-08-29 HIGH 7.9 CVE-2012-3579EPSS 40% Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier for remote attackers to obtain … Messaging Gateway after 9.5.4 Fix from $1,9502012-08-29 HIGH 9.3 CVE-2012-3965 Mozilla Firefox before 15.0 does not properly restrict navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaSc… Firefox after 14.0 Fix from $1,9502012-08-29 MEDIUM 6.0 CVE-2012-1650 The ZipCart module 6.x before 6.x-1.4 for Drupal checks the "access content" permission instead of the "access ZipCart downloads" permission when bui… Zipcart Patch available Fix from $1,6002012-08-28 MEDIUM 6.0 CVE-2012-1641 The finder_import function in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote authenti… Finder Patch available Fix from $1,6002012-08-28 MEDIUM 5.0 CVE-2012-1642 includes/linkchecker.pages.inc in the Link checker module 6.x-2.x before 6.x-2.5 for Drupal does not properly enforce access permissions on broken li… Linkchecker Patch available Fix from $1,6002012-08-28 MEDIUM 5.0 CVE-2012-1643 The Faster Permissions module 7.x-2.x before 7.x-1.2 for Drupal does not check the "administer permissions" permission, which allows remote attackers… Fp Patch available Fix from $1,6002012-08-28 MEDIUM 6.4 CVE-2012-1635 The hook_node_access function in the revisioning module 7.x-1.x before 7.x-1.3 for Drupal checks the permissions of the current user even when it is … Revisioning Patch available Fix from $1,6002012-08-28 MEDIUM 6.9 CVE-2012-3486 Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon o… Tunnelblick after 3.3beta20 Fix from $1,6002012-08-26 MEDIUM 5.0 CVE-2009-5131 The Receive Service in Websense Email Security before 7.1 does not recognize domain extensions in the blacklist, which allows remote attackers to byp… Websense Email Security after 7.0 Fix from $1,6002012-08-26 HIGH 9.3 CVE-2010-5189 Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated user… Sgos after 4.3.4 Fix from $1,9502012-08-26 MEDIUM 5.0 CVE-2010-5190 The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x b… Sgos after 4.3.4 Fix from $1,6002012-08-26 HIGH 7.2 CVE-2012-3484 Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, whic… Tunnelblick after 3.3beta20 Fix from $1,9502012-08-26