Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2011-2010 The Microsoft Office Input Method Editor (IME) for Simplified Chinese in Microsoft Pinyin IME 2010, Office Pinyin SimpleFast Style 2010, and Office P… Pinyin Ime Mitigation only Fix from $1,9502011-12-14 HIGH 7.2 CVE-2011-4202 The Tadasoft Restorepoint 3.2 evaluation image uses weak permissions (www write access) for unspecified scripts, which allows local users to gain pri… Restorepoint Mitigation only Fix from $1,9502011-12-13 MEDIUM 5.0 CVE-2011-4688 Mozilla Firefox 8.0.1 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, w… Firefox after 8.0.1 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2011-4690 Opera 11.60 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes… Opera Browser after 11.60 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2011-4691 Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attemp… Chrome after 15.0.874.121 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2011-4692 WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for imag… Safari after 15 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2011-4681 Opera before 11.60 does not properly consider the number of . (dot) characters that conventionally exist in domain names of different top-level domai… Opera Browser after 11.60 Fix from $1,6002011-12-07 MEDIUM 6.4 CVE-2011-4682 The JavaScript engine in Opera before 11.60 does not properly implement the in operator, which allows remote attackers to bypass the Same Origin Poli… Opera Browser after 11.60 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2002-2437 The JavaScript implementation in Mozilla Firefox before 4.0, Thunderbird before 3.3, and SeaMonkey before 2.1 does not properly restrict the set of v… Firefox after 3.6.24 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5070 The JavaScript implementation in Apple Safari 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle… Safari No fix yet Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5071EPSS 13% The JavaScript implementation in Microsoft Internet Explorer 8.0 and earlier does not properly restrict the set of values contained in the object ret… Ie after 8 Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5072 The JavaScript implementation in Opera 10.5 does not properly restrict the set of values contained in the object returned by the getComputedStyle met… Opera Browser No fix yet Fix from $1,6002011-12-07 MEDIUM 5.0 CVE-2010-5073 The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyl… Chrome No fix yet Fix from $1,6002011-12-07 MEDIUM 6.9 CVE-2011-4356 Celery 2.1 and 2.2 before 2.2.8, 2.3 before 2.3.4, and 2.4 before 2.4.4 changes the effective id but not the real id during processing of the --uid a… Celery Patch available Fix from $1,6002011-12-05 HIGH 10.0 CVE-2011-4161EPSS 14% The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Dig… Color Laserjet 3000 Mitigation only Fix from $1,9502011-12-01 HIGH 7.6 CVE-2008-7303 The nonet and nointernet sandbox profiles in Apple Mac OS X 10.5.x do not propagate restrictions to all created processes, which allows remote attack… Mac Os X No fix yet Fix from $1,9502011-11-15 HIGH 7.6 CVE-2011-1516 The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all crea… Mac Os X No fix yet Fix from $1,9502011-11-15 MEDIUM 6.0 CVE-2011-4118 Mahara before 1.4.1, when MNet (aka the Moodle network feature) is used, allows remote authenticated users to gain privileges via a jump to an XMLRPC… Mahara after 1.4.0 Fix from $1,6002011-11-15 MEDIUM 5.0 CVE-2011-4435 The web-server component in the Consolidation and Analysis Engine (CAE) Server in DB2 Query Monitor in IBM DB2 Tools 2.3.0 for z/OS does not prevent … Db2 Tools For Z\/os Mitigation only Fix from $1,6002011-11-11 HIGH 9.3 CVE-2011-2458 Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Ado… Flash Player 3.1.0.4880 / 10.3.183.11+ Fix from $1,9502011-11-11 HIGH 8.5 CVE-2011-2739 The file-blocking feature in EMC Documentum eRoom 7.3.x and 7.4.x before 7.4.3.g does not properly restrict the uploading and opening of files with d… Documentum Eroom Mitigation only Fix from $1,9502011-11-09 HIGH 9.3 CVE-2011-2740 EMC RSA Key Manager (RKM) Appliance 2.7 SP1 before 2.7.1.6, when Firefox 4.x or 5.0 is used, does not properly terminate a user session upon a logout… Rsa Key Manager Appliance Mitigation only Fix from $1,9502011-11-09 MEDIUM 5.5 CVE-2011-3993 SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.… Autotagging after 5.251 Fix from $1,6002011-11-03 HIGH 9.3 CVE-2011-4216 Investintech.com SlimPDF Reader does not properly restrict write operations, which allows remote attackers to cause a denial of service (application … Slimpdf Reader Mitigation only Fix from $1,9502011-11-01 HIGH 9.3 CVE-2011-4217 Investintech.com SlimPDF Reader does not properly restrict read operations during block data moves, which allows remote attackers to cause a denial o… Slimpdf Reader Patch available Fix from $1,9502011-11-01 HIGH 9.3 CVE-2011-4220EPSS 7% Investintech.com SlimPDF Reader does not properly restrict the arguments to unspecified function calls, which allows remote attackers to cause a deni… Slimpdf Reader Patch available Fix from $1,9502011-11-01 HIGH 7.2 CVE-2011-4212 The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent os.popen calls, which allows local users to bypass… App Engine Python Sdk after 1.5.3 Fix from $1,9502011-10-30 HIGH 7.2 CVE-2011-4213 The sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly prevent use of the os module, which allows local users to … App Engine Python Sdk 1.5.4+ Fix from $1,9502011-10-30 HIGH 7.2 CVE-2011-4211 The FakeFile implementation in the sandbox environment in the Google App Engine Python SDK before 1.5.4 does not properly control the opening of file… App Engine Python Sdk after 1.5.3 Fix from $1,9502011-10-30 MEDIUM 5.0 CVE-2009-2747 The Java Naming and Directory Interface (JNDI) implementation in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.39, 6.1 before 6.1.0.29, and… Websphere Application Server Mitigation only Fix from $1,6002011-10-30