Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 5.8 CVE-2011-4705 The Ming Blacklist Free (vc.software.blacklist) application 1.8.1 and 1.9.2.1 for Android does not properly protect data, which allows remote attacke… Blacklist Free Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4769 The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers t… Mobilesafe Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4770 The QIWI Wallet (ru.mw) application before 1.14.2 for Android does not properly protect data, which allows remote attackers to read or modify financi… Wallet after 1.14.2 Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4771 The Scan to PDF Free (com.scan.to.pdf.trial) application 2.0.4 for Android does not properly protect data, which allows remote attackers to read or m… Scan To Pdf Free Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4772 The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SM… Kouxin Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4773 The AnGuanJia (com.anguanjia.safe) application 2.10.343 for Android does not properly protect data, which allows remote attackers to read or modify S… Anguanjia Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4863 The Tencent QQPimSecure (com.tencent.qqpimsecure) application 3.0.2 for Android does not properly protect data, which allows remote attackers to read… Qqpimsecure Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4864 The Tencent MobileQQ (com.tencent.mobileqq) application 2.2 for Android does not properly protect data, which allows remote attackers to read or modi… Mobileqq Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4865 The Tencent WBlog (com.tencent.WBlog) 3.3.1 and MicroBlogPad 1.4.0 applications for Android do not properly protect data, which allows remote attacke… Microblogpad Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4867 The Tencent QQPhoto (com.tencent.qqphoto) application 0.97 for Android does not properly protect data, which allows remote attackers to read or modif… Qqpphoto Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4700 The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to rea… Ubersocial Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4701 The CallConfirm (jp.gr.java_conf.ofnhwx.callconfirm) application 2.0.0 for Android does not properly protect data, which allows remote attackers to r… Callconfirm Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4702 The Nimbuzz (com.nimbuzz) application 2.0.8 and 2.0.10 for Android does not properly protect data, which allows remote attackers to read or modify a … Nimbuzz Mitigation only Fix from $1,6002012-01-25 MEDIUM 5.8 CVE-2011-4703 The Limit My Call (com.limited.call.view) application 2.11 for Android does not properly protect data, which allows remote attackers to read or modif… Limit My Call Mitigation only Fix from $1,6002012-01-25 HIGH 10.0 CVE-2011-4659 Cisco TelePresence Software before TE 4.1.1 on the Cisco IP Video Phone E20 has a default password for the root account after an upgrade to TE 4.1.0,… Telepresence E20 Software Mitigation only Fix from $1,9502012-01-19 MEDIUM 5.0 CVE-2011-1184EPSS 9% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not have the… Tomcat Patch available Fix from $1,6002012-01-14 MEDIUM 5.0 CVE-2011-5062EPSS 8% The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check qo… Tomcat Patch available Fix from $1,6002012-01-14 MEDIUM 6.4 CVE-2011-5058 The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the we… Codesys No fix yet Fix from $1,6002012-01-10 MEDIUM 5.0 CVE-2011-5057EPSS 29% Apache Struts 2.3.1.2 and earlier, 2.3.19-2.3.23, provides interfaces that do not properly restrict access to collections such as the session and req… Struts 2.3.3+ Fix from $1,6002012-01-08 MEDIUM 6.4 CVE-2012-0393EPSS 37% The ParameterInterceptor component in Apache Struts before 2.3.1.1 does not prevent access to public constructors, which allows remote attackers to c… Struts 2.3.1.1+ Fix from $1,6002012-01-08 MEDIUM 6.9 CVE-2011-3337 eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows loca… Digital Security Audits Mitigation only Fix from $1,6002012-01-04 HIGH 7.5 CVE-2011-4197 etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, whi… Pfsense after 2.0 Fix from $1,9502012-01-03 HIGH 7.2 CVE-2011-5044 SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute arbitrary code by replacing D… Sopcast No fix yet Fix from $1,9502011-12-30 HIGH 10.0 CVE-2011-5010EPSS 65% apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via shell metacharacters in the PIN… Skyrouter Mitigation only Fix from $1,9502011-12-25 HIGH 7.5 CVE-2011-3839 The administration functionality in Wuzly 2.0 allows remote attackers to bypass authentication by setting the dXNlcm5hbWU cookie. Wuzly Mitigation only Fix from $1,9502011-12-24 MEDIUM 5.8 CVE-2011-2768 Tor before 0.2.2.34, when configured as a client or bridge, sends a TLS certificate chain as part of an outgoing OR connection, which allows remote r… Tor after 0.2.2.33 Fix from $1,6002011-12-23 MEDIUM 6.8 CVE-2011-3666 Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted… Firefox after 3.6.24 Fix from $1,6002011-12-21 HIGH 10.0 CVE-2011-4861 The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows re… Quantum Ethernet Module 140noe77100 after 5.0 Fix from $1,9502011-12-17 MEDIUM 6.8 CVE-2011-2741 EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly implement Device Reco… Rsa Adaptive Authentication On Premise Mitigation only Fix from $1,6002011-12-14 MEDIUM 6.8 CVE-2011-2742 EMC RSA Adaptive Authentication On-Premise (AAOP) 6.0.2.1 SP1 Patch 2, SP1 Patch 3, SP2, SP2 Patch 1, and SP3 does not properly perform forensic eval… Rsa Adaptive Authentication On Premise Mitigation only Fix from $1,6002011-12-14