Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2010-5087 SilverStripe 2.3.x before 2.3.10 and 2.4.x before 2.4.4 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism … Silverstripe Patch available Fix from $1,6002012-08-26 MEDIUM 5.0 CVE-2010-5093 Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the… Silverstripe Patch available Fix from $1,6002012-08-26 MEDIUM 5.0 CVE-2010-5094 The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows … Silverstripe Mitigation only Fix from $1,6002012-08-26 HIGH 7.5 CVE-2012-2289EPSS 5% EMC ApplicationXtender Desktop before 6.5 SP2 and ApplicationXtender Web Access .NET before 6.5 SP2 allow remote attackers to upload files to any loc… Applicationxtender Desktop after 6.5 Fix from $1,9502012-08-26 HIGH 7.5 CVE-2012-3441 The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which … Icinga Mitigation only Fix from $1,9502012-08-25 MEDIUM 5.0 CVE-2009-5121 Websense Email Security 7.1 before Hotfix 4 allows remote attackers to bypass the sender-based blacklist by using the 8BITMIME EHLO keyword in the SM… Websense Email Security Mitigation only Fix from $1,6002012-08-23 HIGH 7.5 CVE-2011-5102 The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 … Websense Web Filter No fix yet Fix from $1,9502012-08-23 MEDIUM 5.0 CVE-2012-4593 McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attribu… Application Control Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.4 CVE-2010-3497 Symantec Norton AntiVirus 2011 does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it… Norton Antivirus Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.4 CVE-2010-3498 AVG Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for remo… Anti Virus Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.4 CVE-2010-3499 F-Secure Anti-Virus does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, which makes it easier for… Anti Virus Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.5 CVE-2009-5115 McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenti… Common Management Agent Mitigation only Fix from $1,6002012-08-22 MEDIUM 6.4 CVE-2010-3496 McAfee VirusScan Enterprise 8.5i and 8.7i does not properly interact with the processing of hcp:// URLs by the Microsoft Help and Support Center, whi… Virusscan Enterprise No fix yet Fix from $1,6002012-08-22 MEDIUM 5.5 CVE-2012-2164 The Web client in IBM Rational ClearQuest 7.1.x before 7.1.2.7 and 8.x before 8.0.0.3 allows remote authenticated users to bypass intended access res… Rational Clearquest Mitigation only Fix from $1,6002012-08-17 HIGH 8.5 CVE-2012-3009 Siemens COMOS before 9.1 Patch 413, 9.2 before Update 03 Patch 023, and 10.0 before Patch 005 allows remote authenticated users to obtain database ad… Comos after 9.1 Fix from $1,9502012-08-16 MEDIUM 5.0 CVE-2012-2770 The Authen::ExternalAuth extension before 0.11 for Best Practical Solutions RT allows remote attackers to obtain a logged-in session via unspecified … Authen\ after 0.08 Fix from $1,6002012-08-15 MEDIUM 6.0 CVE-2012-2073 The Bundle copy module 7.x-1.x before 7.x-1.1 for Drupal does not check for the "use PHP for settings" permission while importing settings, which all… Bundle Copy Patch available Fix from $1,6002012-08-14 MEDIUM 5.0 CVE-2012-2081 The Organic Groups (OG) module 6.x-2.x before 6.x-2.3 for Drupal does not properly restrict access, which allows remote attackers to obtain sensitive… Organic Groups Patch available Fix from $1,6002012-08-14 MEDIUM 5.0 CVE-2012-4069 Dir2web 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database … Dir2web Mitigation only Fix from $1,6002012-08-12 HIGH 9.3 CVE-2012-4248 The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote att… Kindle Touch after 5.1.1 Fix from $1,9502012-08-12 MEDIUM 6.4 CVE-2012-2969 Caucho Quercus, as distributed in Resin before 4.0.29, allows remote attackers to bypass intended restrictions on filename extensions for created fil… Resin after 4.0.28 Fix from $1,6002012-08-12 HIGH 7.5 CVE-2012-4035 The new_password page in PBBoard 2.1.4 allows remote attackers to change the password of arbitrary user accounts via the member_id and new_password p… Pbboard No fix yet Fix from $1,9502012-08-12 MEDIUM 5.5 CVE-2011-5097 chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileg… Chef after 0.9.16 Fix from $1,6002012-08-08 MEDIUM 6.5 CVE-2011-5098 chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges… Chef after 0.9.18 Fix from $1,6002012-08-08 HIGH 7.5 CVE-2012-2203 IBM Global Security Kit (aka GSKit) before 8.0.14.22, as used in IBM Rational Directory Server, IBM Tivoli Directory Server, and other products, uses… Global Security Kit after 8.0.13 Fix from $1,9502012-08-08 MEDIUM 6.5 CVE-2010-5142 chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and upda… Chef after 0.8.10 Fix from $1,6002012-08-08 HIGH 7.2 CVE-2012-2188 IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director … Power Hardware Management Console Firmware Mitigation only Fix from $1,9502012-08-06 HIGH 7.5 CVE-2010-5141 wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bitcoins ow… Bitcoin Core after 0.3.4 Fix from $1,9502012-08-06 HIGH 9.0 CVE-2012-2163 IBM Scale Out Network Attached Storage (SONAS) 1.1 through 1.3.1 allows remote authenticated administrators to execute arbitrary Linux commands via t… Scale Out Network Attached Storage Mitigation only Fix from $1,9502012-07-30 MEDIUM 6.8 CVE-2011-2658 The ISList.ISAvi ActiveX control in AdminStudio in Novell ZENworks Configuration Management (ZCM) 10.2, 10.3, and 11 SP1 provides access to the mscom… Zenworks Configuration Management Patch available Fix from $1,6002012-07-26