Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.8 CVE-2011-2569 Cisco Nexus OS (aka NX-OS) 4.2 and 5.0 and Cisco Unified Computing System with software 1.4 and 2.0 do not properly restrict command-line options, wh… Nx Os Mitigation only Fix from $1,6002011-10-27 MEDIUM 6.2 CVE-2011-3871 Puppet 2.7.x before 2.7.5, 2.6.x before 2.6.11, and 0.25.x, when running in --edit mode, uses a predictable file name, which allows local users to ru… Puppet Patch available Fix from $1,6002011-10-27 MEDIUM 5.5 CVE-2011-2677 Cybozu Office before 8.0.0 allows remote authenticated users to bypass intended access restrictions and access sensitive information (time card and a… Office after 7 Fix from $1,6002011-10-21 MEDIUM 6.5 CVE-2011-0290 The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotu… Blackberry Enterprise Server No fix yet Fix from $1,6002011-10-21 HIGH 7.5 CVE-2011-2584 Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote attackers to access the (1) Encoders and Pull Configurations, (2) Push Co… Show And Share after 5.2 Fix from $1,9502011-10-20 MEDIUM 6.5 CVE-2011-3436 Open Directory in Apple Mac OS X 10.7 before 10.7.2 does not require a user to provide the current password before changing this password, which allo… Mac Os X Mitigation only Fix from $1,6002011-10-14 MEDIUM 5.0 CVE-2011-3225 The SMB File Server component in Apple Mac OS X 10.7 before 10.7.2 does not prevent all guest users from accessing the share point record of a guest-… Mac Os X Mitigation only Fix from $1,6002011-10-14 MEDIUM 6.8 CVE-2011-3226 Open Directory in Apple Mac OS X 10.7 before 10.7.2, when an LDAPv3 server is used with RFC 2307 or custom mappings, allows remote attackers to bypas… Mac Os X Mitigation only Fix from $1,6002011-10-14 MEDIUM 6.8 CVE-2011-3230EPSS 50% Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers to execute arbitrary code via… Safari after 5.1 Fix from $1,6002011-10-14 HIGH 7.6 CVE-2011-3213 The File Systems component in Apple Mac OS X before 10.7.2 does not properly track the specific X.509 certificate that a user manually accepted for a… Mac Os X after 10.7.1 Fix from $1,9502011-10-14 HIGH 9.3 CVE-2011-1253EPSS 13% Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which a… .net Framework Mitigation only Fix from $1,9502011-10-12 HIGH 9.3 CVE-2011-4030 The CMFEditions component 2.x in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2 does not prevent the KwAsAttributes classes from being publish… Cmfeditions Patch available Fix from $1,9502011-10-10 HIGH 8.5 CVE-2008-7300 The labeled networking implementation in Solaris Trusted Extensions in Sun Solaris 10 and OpenSolaris snv_39 through snv_67, when a labeled zone is i… Opensolaris Mitigation only Fix from $1,9502011-10-05 HIGH 7.5 CVE-2011-3645 Newgen OmniDocs allows remote attackers to bypass intended access restrictions via (1) a modified FolderRights parameter to doccab/doclist.jsp, which… Omnidocs No fix yet Fix from $1,9502011-09-27 HIGH 7.5 CVE-2011-2862 Google V8, as used in Google Chrome before 14.0.835.163, does not properly restrict access to built-in objects, which has unspecified impact and remo… Chrome 14.0.835.163+ Fix from $1,9502011-09-19 HIGH 7.7 CVE-2011-1740 EMC Avamar 4.x, 5.0.x, and 6.0.x before 6.0.0-592 allows remote authenticated users to modify client data or obtain sensitive information about produ… Avamar Mitigation only Fix from $1,9502011-09-19 HIGH 9.3 CVE-2011-2431 Adobe Reader and Acrobat 8.x before 8.3.1, 9.x before 9.4.6, and 10.x before 10.1.1 allow attackers to execute arbitrary code via unspecified vectors… Acrobat Reader Patch available Fix from $1,9502011-09-15 HIGH 7.2 CVE-2011-1984EPSS 7% WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over t… Windows 2003 Server Mitigation only Fix from $1,9502011-09-15 MEDIUM 5.0 CVE-2011-2581 The ACL implementation in Cisco NX-OS 5.0(2) and 5.0(3) before 5.0(3)N2(1) on Nexus 5000 series switches, and NX-OS before 5.0(3)U1(2a) on Nexus 3000… Nx Os after 5.0 Fix from $1,6002011-09-14 HIGH 7.5 CVE-2011-3190EPSS 15% Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other … Tomcat No fix yet Fix from $1,9502011-08-31 HIGH 9.3 CVE-2011-2993 The implementation of digital signatures for JAR files in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does n… Firefox Mitigation only Fix from $1,9502011-08-18 MEDIUM 5.0 CVE-2011-3140 IBM Web Application Firewall, as used on the G400 IPS-G400-IB-1 and GX4004 IPS-GX4004-IB-2 appliances with update 31.030, does not properly handle qu… Web Application Firewall No fix yet Fix from $1,6002011-08-15 MEDIUM 5.0 CVE-2011-2729EPSS 7% native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33,… Tomcat Patch available Fix from $1,6002011-08-15 HIGH 7.4 CVE-2011-1898 Xen 4.1 before 4.1.1 and 4.0 before 4.0.2, when using PCI passthrough on Intel VT-d chipsets that do not have interrupt remapping, allows guest OS us… Xen Patch available Fix from $1,9502011-08-12 MEDIUM 6.4 CVE-2011-2139EPSS 5% Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adobe AIR before 2.7.1 on Windows… Flash Player after 10.3.181.36 Fix from $1,6002011-08-10 HIGH 9.3 CVE-2011-3129 The file upload functionality in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2, when running "on hosts with dangerous security settings," has unkn… WordPress Patch available Fix from $1,9502011-08-10 HIGH 7.2 CVE-2011-1967 Winsrv.dll in the Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W… Windows 2003 Server Mitigation only Fix from $1,9502011-08-10 HIGH 7.2 CVE-2011-1974EPSS 7% NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Server 2003 SP2 does not properly … Windows 2003 Server No fix yet Fix from $1,9502011-08-10 MEDIUM 6.8 CVE-2011-3006 The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyAS… Saas Endpoint Protection after 5.2.1 Fix from $1,6002011-08-10 HIGH 7.2 CVE-2011-3123 IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, uses wea… Infosphere Datastage Mitigation only Fix from $1,9502011-08-10