Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.0 CVE-2011-4300 The file_browser component in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not properly restrict access to category and course data, which a… Moodle Patch available Fix from $1,6002012-07-11 MEDIUM 6.9 CVE-2012-1894 Microsoft Office for Mac 2011 uses world-writable permissions for the "Applications/Microsoft Office 2011/" directory and certain other directories, … Office Mitigation only Fix from $1,6002012-07-10 MEDIUM 5.5 CVE-2012-1860EPSS 13% Microsoft Office SharePoint Server 2007 SP2 and SP3, SharePoint Server 2010 Gold and SP1, and Office Web Apps 2010 Gold and SP1 do not properly check… Office Web Apps Mitigation only Fix from $1,6002012-07-10 MEDIUM 5.0 CVE-2012-2138EPSS 14% The @CopyFrom operation in the POST servlet in the org.apache.sling.servlets.post bundle before 2.1.2 in Apache Sling does not prevent attempts to co… Org.apache.sling.servlets.post after 2.1.0 Fix from $1,6002012-07-09 MEDIUM 5.0 CVE-2012-2640 The NEC BIGLOBE Yome Collection application 1.8.3 and earlier for Android allows remote attackers to read the IMEI value from an SD card via a crafte… Nec Biglobe Yome Collection after 1.8.3 Fix from $1,6002012-07-05 MEDIUM 6.4 CVE-2012-1119 MantisBT before 1.2.9 does not audit when users copy or clone a bug report, which makes it easier for remote attackers to copy bug reports without de… Mantisbt after 1.2.8 Fix from $1,6002012-06-29 HIGH 7.5 CVE-2012-3814EPSS 10% Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrar… Font Uploader No fix yet Fix from $1,9502012-06-27 HIGH 7.2 CVE-2012-2200 The default configuration of sendmail in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, allows local users to gain privileges by entering a comma… Vios Mitigation only Fix from $1,9502012-06-27 HIGH 7.5 CVE-2012-2730 The Protected Node module 6.x-1.x before 6.x-1.6 for Drupal does not properly "protect node access when nodes are accessed outside of the standard no… Protected Node Patch available Fix from $1,9502012-06-27 MEDIUM 5.8 CVE-2012-2707 The Hostmaster (Aegir) module 6.x-1.x before 6.x-1.9 for Drupal does not properly exit when users do not have access to package/task nodes, which all… Hostmaster Patch available Fix from $1,6002012-06-27 MEDIUM 5.1 CVE-2012-2719 The filedepot module 6.x-1.x before 6.x-1.3 for Drupal, when accessed using multiple different browsers from the same IP address, causes Internet Exp… Filedepot Patch available Fix from $1,6002012-06-27 MEDIUM 5.0 CVE-2012-2720 The Token Authentication (tokenauth) module 6.x-1.x before 6.x-1.7 for Drupal does not properly revert user sessions, which might allow remote attack… Tokenauth Patch available Fix from $1,6002012-06-27 MEDIUM 6.8 CVE-2012-2721 The default views in the Organic Groups (OG) module 6.x-2.x before 6.x-2.4 for Drupal do not properly check permissions when all users have the "acce… Organic Groups Patch available Fix from $1,6002012-06-27 MEDIUM 5.0 CVE-2012-2702 The Ubercart Product Keys module 6.x-1.x before 6.x-1.1 for Drupal does not properly check access for product keys, which allows remote attackers to … Ubercart Product Keys Patch available Fix from $1,6002012-06-27 MEDIUM 6.4 CVE-2012-2660 actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly consider … Rails No fix yet Fix from $1,6002012-06-22 MEDIUM 6.9 CVE-2012-2179 libodm.a in IBM AIX 5.3, 6.1, and 7.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file. Aix Patch available Fix from $1,6002012-06-22 MEDIUM 6.9 CVE-2012-0304 Symantec LiveUpdate Administrator before 2.3.1 uses weak permissions (Everyone: Full Control) for the installation directory, which allows local user… Liveupdate Administrator after 2.3.0 Fix from $1,6002012-06-22 MEDIUM 5.0 CVE-2012-0191 The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which al… Lotus Expeditor Mitigation only Fix from $1,6002012-06-22 HIGH 7.2 CVE-2011-1477 Multiple array index errors in sound/oss/opl3.c in the Linux kernel before 2.6.39 allow local users to cause a denial of service (heap memory corrupt… Linux Kernel after 2.6.38.8 Fix from $1,9502012-06-21 HIGH 7.2 CVE-2012-0028 The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local … Linux Kernel after 2.6.27.62 Fix from $1,9502012-06-21 MEDIUM 6.2 CVE-2011-2709 libgssapi and libgssglue before 0.4 do not properly check privileges, which allows local users to load untrusted configuration files and execute arbi… Libgssglue after 0.3 Fix from $1,6002012-06-21 HIGH 7.5 CVE-2012-3577EPSS 14% Unrestricted file upload vulnerability in doupload.php in the Nmedia Member Conversation plugin before 1.4 for WordPress allows remote attackers to e… Member Conversation after 1.3 Fix from $1,9502012-06-17 MEDIUM 6.8 CVE-2012-3578EPSS 8% Unrestricted file upload vulnerability in html/Upload.php in the FCChat Widget plugin 2.2.13.1 and earlier for WordPress allows remote attackers to e… Fcchat Widget after 2.2.13.1 Fix from $1,6002012-06-17 HIGH 7.5 CVE-2012-2691 The mc_issue_note_update function in the SOAP API in MantisBT before 1.2.11 does not properly check privileges, which allows remote attackers with bu… Mantisbt after 1.2.10 Fix from $1,9502012-06-17 HIGH 10.0 CVE-2012-3575EPSS 15% Unrestricted file upload vulnerability in uploader.php in the RBX Gallery plugin 2.1 for WordPress allows remote attackers to execute arbitrary code … Rbx Gallery Mitigation only Fix from $1,9502012-06-16 HIGH 10.0 CVE-2012-3576EPSS 18% Unrestricted file upload vulnerability in php/upload.php in the wpStoreCart plugin before 2.5.30 for WordPress allows remote attackers to execute arb… Wpstorecart after 2.5.29 Fix from $1,9502012-06-16 MEDIUM 5.0 CVE-2011-4328 plugin/npapi/plugin.cpp in Gnash before 0.8.10 uses weak permissions (world readable) for cookie files with predictable names in /tmp, which allows l… Gnash after 0.8.9 Fix from $1,6002012-06-16 MEDIUM 5.0 CVE-2012-3557 Opera before 11.65 does not properly restrict the reading of JSON strings, which allows remote attackers to perform cross-domain loading of JSON reso… Opera Browser after 11.62 Fix from $1,6002012-06-14 MEDIUM 6.0 CVE-2012-3347 AutoFORM PDM Archive before 7.0 implements user accounts in a way that allows for JMX Console authentication, which allows remote authenticated users… Autoform Pdm Archive after 6.920 Fix from $1,6002012-06-13 MEDIUM 6.5 CVE-2012-1827 The web service in AutoFORM PDM Archive before 7.1 does not have authorization requirements, which allows remote authenticated users to perform datab… Autoform Pdm Archive after 7.0 Fix from $1,6002012-06-13