Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.5 CVE-2012-1828 The administrative functions in AutoFORM PDM Archive before 7.1 do not have authorization requirements, which allows remote authenticated users to pe… Autoform Pdm Archive after 7.0 Fix from $1,6002012-06-13 HIGH 7.2 CVE-2011-2211 The osf_wait4 function in arch/alpha/kernel/osf_sys.c in the Linux kernel before 2.6.39.4 on the Alpha platform uses an incorrect pointer, which allo… Linux Kernel after 2.6.39.3 Fix from $1,9502012-06-13 MEDIUM 5.8 CVE-2012-2565 Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to… Web Filtering after 5.0.13 Fix from $1,6002012-06-09 MEDIUM 5.0 CVE-2012-2566 Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connecti… Web Filtering after 5.0.13 Fix from $1,6002012-06-09 MEDIUM 6.4 CVE-2012-1818 An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.… Deltav Mitigation only Fix from $1,6002012-06-08 MEDIUM 6.0 CVE-2012-1826 dotCMS 1.9 before 1.9.5.1 allows remote authenticated users to execute arbitrary Java code via a crafted (1) XSLT or (2) Velocity template. Dotcms Mitigation only Fix from $1,6002012-06-08 MEDIUM 6.5 CVE-2012-2603 The server in CollabNet ScrumWorks Pro before 6.0 allows remote authenticated users to gain privileges and obtain sensitive information via a modifie… Scrumworks Mitigation only Fix from $1,6002012-06-08 HIGH 7.6 CVE-2012-3292 The GridFTP in Globus Toolkit (GT) before 5.2.2, when certain autoconf macros are defined, does not properly check the return value from the getpwnam… Globus Toolkit after 5.2.1 Fix from $1,9502012-06-07 MEDIUM 5.5 CVE-2012-1012 server/server_stubs.c in the kadmin protocol implementation in MIT Kerberos 5 (aka krb5) 1.10 before 1.10.1 does not properly restrict access to (1) … Kerberos 5 Mitigation only Fix from $1,6002012-06-07 HIGH 7.2 CVE-2012-1942 The Mozilla Updater and Windows Updater Service in Mozilla Firefox 12.0, Thunderbird 12.0, and SeaMonkey 2.9 on Windows allow local users to gain pri… Firefox Mitigation only Fix from $1,9502012-06-05 HIGH 7.5 CVE-2011-5092 Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspec… Rt Patch available Fix from $1,9502012-06-04 MEDIUM 6.5 CVE-2011-5093 Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to b… Rt Patch available Fix from $1,6002012-06-04 HIGH 10.0 CVE-2012-1250EPSS 6% Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative p… Lan W300n\/ru2 Firmware 2.27+ Fix from $1,9502012-06-04 HIGH 7.5 CVE-2012-2352 The archive management (arc_manage) page in wwsympa/wwsympa.fcgi.in in Sympa before 6.1.11 does not check permissions, which allows remote attackers … Sympa after 6.1.10 Fix from $1,9502012-05-31 MEDIUM 6.9 CVE-2012-1053 The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterpri… Puppet Mitigation only Fix from $1,6002012-05-29 HIGH 10.0 CVE-2012-2949 The ZTE sync_agent program for Android 2.3.4 on the Score M device uses a hardcoded ztex1609523 password to control access to commands, which allows … Score M Mitigation only Fix from $1,9502012-05-29 HIGH 10.0 CVE-2012-2568 d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrato… Blackarmor Nas Mitigation only Fix from $1,9502012-05-25 MEDIUM 6.4 CVE-2012-2928 The Gliffy plugin before 3.7.1 for Atlassian JIRA, and before 4.2 for Atlassian Confluence, does not properly restrict the capabilities of third-part… Jira after 5.0.0 Fix from $1,6002012-05-22 HIGH 10.0 CVE-2012-2561EPSS 9% HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary … Business Service Management Mitigation only Fix from $1,9502012-05-21 HIGH 10.0 CVE-2012-0297EPSS 73% The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts, which allows remote attackers… Web Gateway Mitigation only Fix from $1,9502012-05-21 MEDIUM 6.4 CVE-2012-0298EPSS 9% The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to (1) read or (2) delete arbitra… Web Gateway Mitigation only Fix from $1,6002012-05-21 HIGH 10.0 CVE-2012-0299EPSS 64% The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to upload arbitrary code to a des… Web Gateway Mitigation only Fix from $1,9502012-05-21 MEDIUM 5.0 CVE-2012-2905 Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access control, which allows remote … Artiphp Cms No fix yet Fix from $1,6002012-05-21 HIGH 7.8 CVE-2012-2320 ConnMan before 0.85 does not ensure that netlink messages originate from the kernel, which allows remote attackers to bypass intended access restrict… Connman after 0.84 Fix from $1,9502012-05-18 MEDIUM 6.9 CVE-2012-2010 The ACMELOGIN implementation in HP OpenVMS 8.3 and 8.4 on the Alpha platform, and 8.3, 8.3-1H1, and 8.4 on the Itanium platform, when the SYS$ACM sys… Openvms Mitigation only Fix from $1,6002012-05-18 HIGH 7.2 CVE-2012-2337 sudo 1.6.x and 1.7.x before 1.7.9p1, and 1.8.x before 1.8.4p5, does not properly support configurations that use a netmask syntax, which allows local… Sudo Mitigation only Fix from $1,9502012-05-18 HIGH 7.2 CVE-2012-2123 The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities… Linux Kernel 3.0.29 / 3.2.16+ Fix from $1,9502012-05-17 HIGH 7.2 CVE-2012-2319 Multiple buffer overflows in the hfsplus filesystem implementation in the Linux kernel before 3.3.5 allow local users to gain privileges via a crafte… Linux Kernel after 3.3.3 Fix from $1,9502012-05-17 MEDIUM 5.2 CVE-2012-1179 The Linux kernel before 3.3.1, when KVM is used, allows guest OS users to cause a denial of service (host OS crash) by leveraging administrative acce… Linux Kernel after 3.3 Fix from $1,6002012-05-17 HIGH 7.2 CVE-2011-3098 Google Chrome before 19.0.1084.46 on Windows uses an incorrect search path for the Windows Media Player plug-in, which might allow local users to gai… Chrome after 19.0.1084.45 Fix from $1,9502012-05-16