Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.3 CVE-2011-2145 mount.vmhgfs in the VMware Host Guest File System (HGFS) in VMware Workstation 7.1.x before 7.1.4, VMware Player 3.1.x before 3.1.4, VMware Fusion 3.… Esx Patch available Fix from $1,6002011-06-06 MEDIUM 6.5 CVE-2011-2329 The rampart_timestamp_token_validate function in util/rampart_timestamp_token.c in Apache Rampart/C 1.3.0 does not properly calculate the expiration … Rampart\/c Patch available Fix from $1,6002011-06-02 HIGH 9.0 CVE-2011-2330 Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, w… Tivoli Management Framework No fix yet Fix from $1,9502011-06-02 MEDIUM 6.6 CVE-2011-1602 The su utility on Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.0.3 allows local users to gain privileges via unspecif… Unified Ip Phone 7906 Mitigation only Fix from $1,6002011-06-02 MEDIUM 6.6 CVE-2011-1603 Cisco Unified IP Phones 7900 devices (aka TNP phones) with software before 9.2.1 allow local users to gain privileges via unspecified vectors, aka Bu… Unified Ip Phone 7906 Mitigation only Fix from $1,6002011-06-02 HIGH 7.2 CVE-2011-2041 The Start Before Logon (SBL) functionality in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.254 on Windows, and… Anyconnect Secure Mobility Client after 2.3.2016 Fix from $1,9502011-06-02 MEDIUM 6.8 CVE-2011-1329 WalRack 1.x before 1.1.9 and 2.x before 2.0.7 does not properly restrict file uploads, which allows remote attackers to execute arbitrary PHP code vi… Walrack Patch available Fix from $1,6002011-05-31 HIGH 7.2 CVE-2011-2169 Google Chrome OS before R12 0.12.433.38 Beta allows local users to gain privileges by creating a /var/lib/chromeos-aliases.conf file and placing comm… Chrome Os after 0.12.433.35 Fix from $1,9502011-05-24 MEDIUM 5.1 CVE-2011-1926 The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to i… Cyrus Imap Server after 2.4.6 Fix from $1,6002011-05-23 MEDIUM 6.8 CVE-2011-2165EPSS 5% The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to inser… Xcs Mitigation only Fix from $1,6002011-05-23 MEDIUM 5.0 CVE-2011-2157 The (1) Admin/frmEmailReportSettings.aspx and (2) Admin/frmGeneralSettings.aspx components in the SmarterTools SmarterStats 6.0 web server generate w… Smarterstats Mitigation only Fix from $1,6002011-05-20 MEDIUM 6.8 CVE-2011-2143 IBM Datacap Taskmaster Capture 8.0.1 before FP1, when Windows Authentication is enabled, allows remote attackers to obtain login access by using an i… Datacap Taskmaster Capture Mitigation only Fix from $1,6002011-05-16 MEDIUM 6.5 CVE-2011-1402 Mahara before 1.3.6 allows remote authenticated users to bypass intended access restrictions, and suspend a user account, edit a view, visit a view, … Mahara after 1.3.5 Fix from $1,6002011-05-13 HIGH 7.2 CVE-2011-1738 HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by… Palm Webos Mitigation only Fix from $1,9502011-05-13 HIGH 7.7 CVE-2011-1271EPSS 20% The JIT compiler in Microsoft .NET Framework 3.5 Gold and SP1, 3.5.1, and 4.0, when IsJITOptimizerDisabled is false, does not properly handle express… .net Framework No fix yet Fix from $1,9502011-05-10 MEDIUM 6.5 CVE-2011-1846 IBM DB2 9.5 before FP7 and 9.7 before FP4 on Linux, UNIX, and Windows does not properly revoke role membership from groups, which allows remote authe… Db2 after 9.7 Fix from $1,6002011-05-03 HIGH 7.2 CVE-2011-0729 dbus_backend/ls-dbus-backend in the D-Bus backend in language-selector before 0.6.7 does not restrict access on the basis of a PolicyKit check result… Language Selector after 0.6.6 Fix from $1,9502011-04-29 MEDIUM 6.4 CVE-2010-3260 oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly rest… Forms after 3.8.1 Fix from $1,6002011-04-27 MEDIUM 6.9 CVE-2011-1421 EMC NetWorker 7.5.x before 7.5.4.3 and 7.6.x before 7.6.1.5, when the client push feature is enabled, uses weak permissions for an unspecified file, … Networker Mitigation only Fix from $1,6002011-04-22 HIGH 7.2 CVE-2011-1149 Android before 2.3 does not properly restrict access to the system property space, which allows local applications to bypass the application sandbox … Android after 2.2.2 Fix from $1,9502011-04-21 MEDIUM 5.5 CVE-2010-1171 Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary fi… Satellite Mitigation only Fix from $1,6002011-04-18 MEDIUM 5.8 CVE-2011-0989 The RuntimeHelpers.InitializeArray method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, does not properl… Mono Patch available Fix from $1,6002011-04-13 MEDIUM 6.8 CVE-2011-1683 IBM WebSphere Application Server (WAS) 6.0.x through 6.0.2.43, 6.1.x before 6.1.0.37, and 7.0.x before 7.0.0.17 on z/OS, when a Local OS user registr… Websphere Application Server Mitigation only Fix from $1,6002011-04-13 MEDIUM 5.0 CVE-2011-1487EPSS 9% The (1) lc, (2) lcfirst, (3) uc, and (4) ucfirst functions in Perl 5.10.x, 5.11.x, and 5.12.x through 5.12.3, and 5.13.x through 5.13.11, do not appl… Perl Patch available Fix from $1,6002011-04-11 MEDIUM 6.2 CVE-2011-1095 locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to … Glibc after 2.12.2 Fix from $1,6002011-04-10 MEDIUM 6.4 CVE-2011-0466 The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions … Opensuse Build Service Mitigation only Fix from $1,6002011-04-10 MEDIUM 5.0 CVE-2011-1661 The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intend… Node Quick Find Patch available Fix from $1,6002011-04-10 MEDIUM 5.0 CVE-2011-1665 PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain backup SQL fil… Phpboost No fix yet Fix from $1,6002011-04-10 MEDIUM 5.1 CVE-2011-1425EPSS 8% xslt.c in XML Security Library (aka xmlsec) before 1.2.17, as used in WebKit and other products, when XSLT is enabled, allows remote attackers to cre… Xml Security Library after 1.2.16 Fix from $1,6002011-04-04 MEDIUM 6.9 CVE-2011-1126 VMware vmrun, as used in VIX API 1.x before 1.10.3 and VMware Workstation 6.5.x and 7.x before 7.1.4 build 385536 on Linux, might allow local users t… Vix Api Mitigation only Fix from $1,6002011-04-04