Vulnerability index

Browse CVEs

1,826 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Race ConditionCWE-362 × clear
Linux Kernel MEDIUM 6.9
CVE-2008-1669

Linux kernel before 2.6.25.2 does not apply a certain protection mechanism for fcntl functionality, which allows local users to (1) execute code in p…

Patch available
Fix from $1,600 2008-05-08
Linux Kernel MEDIUM 6.9
CVE-2008-1375

Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local user…

Fix: 2.6.24.6+
Fix from $1,600 2008-05-02
Policyd Weight MEDIUM 6.9
CVE-2008-1570

Race condition in the create_lockpath function in policyd-weight 0.1.14 beta-16 allows local users to modify or delete arbitrary files by creating th…

Mitigation only
Fix from $1,600 2008-03-31
Mac Os X HIGH 7.2
CVE-2008-0055

Foundation in Apple Mac OS X 10.4.11 creates world-writable directories while NSFileManager copies files recursively and only modifies the permission…

Patch available
Fix from $1,950 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0058

Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbi…

Patch available
Fix from $1,600 2008-03-18
Mac Os X MEDIUM 5.8
CVE-2008-0059

Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file,…

Patch available
Fix from $1,600 2008-03-18
Crystal Reports Xi HIGH 9.3
CVE-2008-0379EPSS 9%

Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release 2 allows remote attackers to …

No fix yet
Fix from $1,950 2008-01-22
Evi HIGH 9.3
CVE-2007-6429

Multiple integer overflows in X.Org Xserver before 1.4.1 allow context-dependent attackers to execute arbitrary code via (1) a GetVisualInfo request …

Fix: after 1.4
Fix from $1,950 2008-01-18
Mac Os X MEDIUM 6.6
CVE-2007-5847

Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions,…

Mitigation only
Fix from $1,600 2007-12-19
Solaris HIGH 7.6
CVE-2007-6180

Race condition in the Remote Procedure Call kernel module (rpcmod) in Sun Solaris 8 through 10 allows local users to cause a denial of service (NULL …

Patch available
Fix from $1,950 2007-11-30
Rails MEDIUM 6.8
CVE-2007-6077

The session fixation protection mechanism in cgi_process.rb in Rails 1.2.4, as used in Ruby on Rails, removes the :cookie_only attribute from the DEF…

Patch available
Fix from $1,600 2007-11-21
Aipo MEDIUM 5.8
CVE-2007-5154

Session fixation vulnerability in Aipo and Aipo ASP 3.0.1.0 and earlier allows remote attackers to hijack web sessions via unspecified vectors.

Fix: after 3.0.1.0
Fix from $1,600 2007-10-01
Linux Kernel MEDIUM 6.9
CVE-2007-0997

Race condition in the tee (sys_tee) system call in the Linux kernel 2.6.17 through 2.6.17.6 might allow local users to cause a denial of service (sys…

Mitigation only
Fix from $1,600 2007-09-18
Nod32 Antivirus HIGH 7.6
CVE-2007-3970EPSS 6%

Race condition in ESET NOD32 Antivirus before 2.2289 allows remote attackers to execute arbitrary code via a crafted CAB file, which triggers heap co…

Fix: 2.2289+
Fix from $1,950 2007-07-25
Windows 2003 Server HIGH 7.1
CVE-2007-3091EPSS 28%

Race condition in Microsoft Internet Explorer 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vista Gold, SP1, and SP2;…

Patch available
Fix from $1,950 2007-06-06
HTTP Server MEDIUM 6.2
CVE-2007-1741

Multiple race conditions in suexec in Apache HTTP Server (httpd) 2.2.3 between directory and file validation, and their usage, allow local users to g…

Mitigation only
Fix from $1,600 2007-04-13
C1 Financial Services MEDIUM 6.8
CVE-2007-1249

MoveSortedContentAction in C1 Financial Services Contelligent 9.1.4 does not check "the additional environment security configuration," which allows …

Mitigation only
Fix from $1,600 2007-03-03
Xml Core Services HIGH 9.3
CVE-2007-0099EPSS 25%

Race condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attacker…

Patch available
Fix from $1,950 2007-01-08
Toast MEDIUM 6.2
CVE-2006-4801

Race condition in Deja Vu, as used in Roxio Toast Titanium 7 and possibly other products, allows local users to execute arbitrary code via temporary …

No fix yet
Fix from $1,600 2006-09-14
Ie MEDIUM 5.1
CVE-2006-2094EPSS 23%

Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, …

No fix yet
Fix from $1,600 2006-04-29
Ie MEDIUM 5.1
CVE-2005-3240EPSS 6%

Race condition in Microsoft Internet Explorer allows user-assisted attackers to overwrite arbitrary files and possibly execute code by tricking a use…

Mitigation only
Fix from $1,600 2005-12-31
Aix MEDIUM 6.9
CVE-2004-2697

The Inventory Scout daemon (invscoutd) 1.3.0.0 and 2.0.2 for AIX 4.3.3 and 5.1 allows local users to gain privileges via a symlink attack on a comman…

No fix yet
Fix from $1,600 2004-12-31
Imwheel MEDIUM 6.9
CVE-2004-2698

Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial of service (IMWheel crash) an…

Fix: after 1.0.0pre11
Fix from $1,600 2004-12-31
Openssh HIGH 7.6
CVE-2003-1562EPSS 6%

sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay afte…

Mitigation only
Fix from $1,950 2003-12-31
Patchpro HIGH 10.0
CVE-2002-2374

Unspecified vulnerability in pprosetup in Sun PatchPro 2.0 has unknown impact and attack vectors related to "unsafe use of temporary files."

Patch available
Fix from $1,950 2002-12-31
Esound MEDIUM 6.2
CVE-2000-0864

Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary …

Patch available
Fix from $1,600 2000-11-14