Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
HIGH 7.2 CVE-2011-3124 IBM InfoSphere Information Server 8.5 and 8.5.0.1 on Unix and Linux, as used in IBM InfoSphere DataStage 8.5 and 8.5.0.1 and other products, assigns … Infosphere Datastage Mitigation only Fix from $1,9502011-08-10 MEDIUM 5.0 CVE-2011-3014 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 does not properly restrict caching of HTTPS responses, which mak… Data Synchronizer Mitigation only Fix from $1,6002011-08-09 MEDIUM 5.0 CVE-2011-2221 The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows remote attackers to bypass WebAdmin authentication and ob… Data Synchronizer Mitigation only Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2008-7293 Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to… Firefox after 4.0 Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2008-7294 Google Chrome before 4.0.211.0 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attack… Chrome after 3.0.195.38 Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2008-7296 Apple Safari cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite o… Safari Patch available Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2008-7297 Opera cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delet… Opera Browser Patch available Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2008-7298 The Android browser in Android cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attack… Android Browser Patch available Fix from $1,6002011-08-09 MEDIUM 5.8 CVE-2011-1744 EMC Captiva eInput 2.1.1 before 2.1.1.37 does not restrict the origin of calls to ActiveX functions, which allows remote attackers to read arbitrary … Captiva Einput 2.1.1.37+ Fix from $1,6002011-08-01 HIGH 9.0 CVE-2011-2547 The web-based management interface on Cisco SA 500 series security appliances with software before 2.1.19 allows remote authenticated users to execut… Sa500 Software after 2.1.18 Fix from $1,9502011-07-28 HIGH 7.5 CVE-2011-2687 Drupal 7.x before 7.3 allows remote attackers to bypass intended node_access restrictions via vectors related to a listing that shows nodes but lacks… Drupal Patch available Fix from $1,9502011-07-27 MEDIUM 6.5 CVE-2011-2745 upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploa… Chyrp after 2.0 Fix from $1,6002011-07-27 MEDIUM 6.8 CVE-2011-2196 jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss E… Jboss Enterprise Application Platform after 2.2.2 Fix from $1,6002011-07-27 MEDIUM 6.8 CVE-2011-1484 jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBos… Jboss Enterprise Application Platform after 2.2.2 Fix from $1,6002011-07-27 MEDIUM 5.8 CVE-2011-0219 Apple Safari before 5.0.6 allows remote attackers to bypass the Same Origin Policy, and modify the rendering of text from arbitrary web sites, via a … Safari after 5.0.5 Fix from $1,6002011-07-21 HIGH 7.2 CVE-2011-0227 The queueing primitives in IOMobileFrameBuffer in Apple iOS before 4.2.9 and 4.3.x before 4.3.4 do not properly perform type conversion, which allows… Iphone Os after 4.2.8 Fix from $1,9502011-07-19 MEDIUM 6.5 CVE-2011-2385 The iPhoneHandle package 0.9.x before 0.9.7 and 1.0.x before 1.0.3 in Open Ticket Request System (OTRS) does not properly restrict use of the iPhoneH… Iphonehandle Patch available Fix from $1,6002011-07-19 MEDIUM 5.0 CVE-2011-2760 Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet. Bigiron Rx Switch Mitigation only Fix from $1,6002011-07-17 HIGH 7.2 CVE-2011-1946 gnomesu-pam-backend in libgnomesu 1.0.0 prints an error message but proceeds with the non-error code path upon failure of the setgid or setuid functi… Libgnomesu Patch available Fix from $1,9502011-07-07 MEDIUM 5.0 CVE-2011-2362 Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that d… Firefox after 3.6.17 Fix from $1,6002011-06-30 MEDIUM 6.4 CVE-2011-2367 The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sen… Firefox Mitigation only Fix from $1,6002011-06-30 HIGH 10.0 CVE-2011-2368 The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict write operations, which allows remote attackers to execute a… Firefox Mitigation only Fix from $1,9502011-06-30 MEDIUM 5.0 CVE-2011-2370 Mozilla Firefox before 5.0 does not properly enforce the whitelist for the xpinstall functionality, which allows remote attackers to trigger an insta… Firefox after 4.0.1 Fix from $1,6002011-06-30 HIGH 7.1 CVE-2011-2601 The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desk… Mac Os X No fix yet Fix from $1,9502011-06-30 HIGH 10.0 CVE-2011-1127 SSI.php in Simple Machines Forum (SMF) before 1.1.13, and 2.x before 2.0 RC5, does not properly restrict guest access, which allows remote attackers … Smf after 1.1.12 Fix from $1,9502011-06-21 HIGH 7.2 CVE-2011-1249EPSS 8% The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Serve… Windows 2003 Server No fix yet Fix from $1,9502011-06-16 HIGH 7.2 CVE-2011-1709 GNOME Display Manager (gdm) before 2.32.2, when glib 2.28 is used, enables execution of a web browser with the uid of the gdm account, which allows l… Gdm Patch available Fix from $1,9502011-06-14 HIGH 7.2 CVE-2011-2471 utils/opcontrol in OProfile 0.9.6 and earlier might allow local users to gain privileges via shell metacharacters in the (1) --vmlinux, (2) --session… Oprofile after 0.9.6 Fix from $1,9502011-06-09 MEDIUM 6.5 CVE-2011-1584 The updateFile function in inc/core/class.dc.media.php in the Media Manager in Dotclear before 2.2.3 does not properly restrict pathnames, which allo… Dotclear after 2.2.2 Fix from $1,6002011-06-08 MEDIUM 5.5 CVE-2011-1950 plone.app.users in Plone 4.0 and 4.1 allows remote authenticated users to modify the properties of arbitrary accounts via unspecified vectors, as exp… Plone Patch available Fix from $1,6002011-06-06