Vulnerability index

Browse CVEs

4,008 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Permissions, Privileges & Access ControlsCWE-264 × clear
MEDIUM 6.9 CVE-2011-0468 The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via she… Opensuse Mitigation only Fix from $1,6002011-04-04 MEDIUM 5.0 CVE-2011-0963 The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 a… Nac Guest Server after 2.0.2 Fix from $1,6002011-03-31 MEDIUM 6.3 CVE-2011-1548 The default configuration of logrotate on Debian GNU/Linux uses root privileges to process files in directories that permit non-root write access, wh… Logrotate Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.3 CVE-2011-1549 The default configuration of logrotate on Gentoo Linux uses root privileges to process files in directories that permit non-root write access, which … Logrotate Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.3 CVE-2011-1550 The default configuration of logrotate on SUSE openSUSE Factory uses root privileges to process files in directories that permit non-root write acces… Logrotate Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.9 CVE-2011-1551 SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gai… Opensuse Factory Mitigation only Fix from $1,6002011-03-30 MEDIUM 6.9 CVE-2009-5064 ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a… Glibc after 2.1.3 Fix from $1,6002011-03-30 HIGH 7.2 CVE-2011-1420 EMC Data Protection Advisor Collector 5.7 and 5.7.1 on Solaris SPARC platforms uses weak permissions for unspecified files, which allows local users … Data Protection Advisor Collector No fix yet Fix from $1,9502011-03-28 MEDIUM 6.5 CVE-2008-7277 Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization o… Otrs after 2.3.0 Fix from $1,6002011-03-18 MEDIUM 6.5 CVE-2008-7279 The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restric… Otrs after 2.2.7 Fix from $1,6002011-03-18 MEDIUM 6.0 CVE-2008-7283 Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access r… Otrs after 2.2.5 Fix from $1,6002011-03-18 MEDIUM 6.5 CVE-2010-4763 The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJA… Otrs after 2.4.10 Fix from $1,6002011-03-18 MEDIUM 6.0 CVE-2010-4768 Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intend… Otrs after 2.3.4 Fix from $1,6002011-03-18 MEDIUM 6.8 CVE-2011-0411EPSS 16% The STARTTLS implementation in Postfix 2.4.x before 2.4.16, 2.5.x before 2.5.12, 2.6.x before 2.6.9, and 2.7.x before 2.7.3 does not properly restric… Postfix No fix yet Fix from $1,6002011-03-16 MEDIUM 6.9 CVE-2011-1146 libvirt.c in the API in Red Hat libvirt 0.8.8 does not properly restrict operations in a read-only connection, which allows remote attackers to cause… Libvirt Patch available Fix from $1,6002011-03-15 MEDIUM 5.8 CVE-2011-0166 The HTML5 drag and drop functionality in WebKit in Apple Safari before 5.0.4 allows user-assisted remote attackers to bypass the Same Origin Policy a… Safari after 5.0.3 Fix from $1,6002011-03-11 MEDIUM 6.5 CVE-2011-1321 The AuthCache purge implementation in the Security component in IBM WebSphere Application Server (WAS) 6.1.0.x before 6.1.0.37 and 7.x before 7.0.0.1… Websphere Application Server Mitigation only Fix from $1,6002011-03-08 MEDIUM 6.0 CVE-2011-1311 The Security component in IBM WebSphere Application Server (WAS) before 7.0.0.15, when a J2EE 1.4 application is used, determines the security role m… Websphere Application Server after 7.0.0.13 Fix from $1,6002011-03-08 MEDIUM 5.0 CVE-2011-1005 The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings vi… Ruby Patch available Fix from $1,6002011-03-02 HIGH 7.8 CVE-2011-0396 Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.0 before 8.0(5.23), 8.1 before 8.1(2.49), 8.2 before 8.2(4.1), and 8.3 b… Adaptive Security Appliance Mitigation only Fix from $1,9502011-02-25 HIGH 8.0 CVE-2011-0387 The administrative web interface on Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote au… Telepresence Multipoint Switch Software Mitigation only Fix from $1,9502011-02-25 MEDIUM 6.9 CVE-2011-1011 The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterpr… Policycoreutils after 2.0.83 Fix from $1,6002011-02-24 MEDIUM 6.2 CVE-2011-0532 The (1) backup and restore scripts, (2) main initialization script, and (3) ldap-agent script in 389 Directory Server 1.2.x (aka Red Hat Directory Se… Directory Server Mitigation only Fix from $1,6002011-02-23 MEDIUM 6.2 CVE-2011-1056 The installer for Metasploit Framework 3.5.1, when running on Windows, uses weak inherited permissions for the Metasploit installation directory, whi… Metasploit Framework Mitigation only Fix from $1,6002011-02-21 MEDIUM 5.0 CVE-2011-0330 The Dell DellSystemLite.Scanner ActiveX control in DellSystemLite.ocx 1.0.0.0 does not properly restrict the values of the WMIAttributesOfInterest pr… Dellsystemlite.scanner Activex Control Mitigation only Fix from $1,6002011-02-21 HIGH 7.5 CVE-2011-0449 actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly im… Rails Patch available Fix from $1,9502011-02-21 MEDIUM 5.0 CVE-2011-1046 IBM FileNet P8 Content Engine (aka P8CE) 4.0.1 through 5.0.0, as used in FileNet P8 Content Manager (CM) and FileNet P8 Business Process Manager (BPM… Filenet P8 Content Engine Mitigation only Fix from $1,6002011-02-21 HIGH 7.5 CVE-2011-0706 The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via u… Icedtea Web Patch available Fix from $1,9502011-02-19 MEDIUM 6.8 CVE-2011-1032 IBM Lotus Connections 3.0, when IBM WebSphere Application Server 7.0.0.11 is used, does not properly restrict access to the internal login module, wh… Lotus Connections Mitigation only Fix from $1,6002011-02-15 HIGH 9.3 CVE-2011-0976EPSS 25% Microsoft PowerPoint 2002 SP3, 2003 SP3, and 2007 SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Compatibility Pac… Powerpoint Mitigation only Fix from $1,9502011-02-10