Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Content Management CRITICAL 9.8
CVE-2018-18941

In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the v…

No fix yet
Fix from $2,300 2019-01-31
Vignette Content Management HIGH 7.5
CVE-2008-6412

Unspecified vulnerability in Vignette Content Management 7.3.0.5, 7.3.1, 7.3.1.1, 7.4, and 7.5 allows "low privileged" users to gain administrator pr…

Patch available
Fix from $1,950 2009-03-06
Application Portal MEDIUM 5.0
CVE-2004-0917

The default installation of Vignette Application Portal installs the diagnostic utility without authentication requirements, which allows remote atta…

No fix yet
Fix from $1,600 2005-01-27
Storyserver MEDIUM 5.0
CVE-2002-0385

Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of '"' (double q…

Patch available
Fix from $1,600 2004-06-01
Content Suite HIGH 7.5
CVE-2003-0398

Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a te…

Patch available
Fix from $1,950 2003-07-02
Content Suite MEDIUM 6.4
CVE-2003-0399

Vignette StoryServer 4 and 5, Vignette V/5, and possibly other versions allows remote attackers to perform unauthorized SELECT queries by setting the…

Patch available
Fix from $1,600 2003-07-02
Content Suite HIGH 7.5
CVE-2003-0403

Vignette StoryServer 5 and Vignette V/5 allows remote attackers to read and modify license information, and cause a denial of service (service halt) …

Patch available
Fix from $1,950 2003-06-30
Content Suite MEDIUM 5.0
CVE-2003-0400

Vignette StoryServer and Vignette V/5 does not properly calculate the size of text variables, which causes Vignette to return unauthorized portions o…

Patch available
Fix from $1,600 2003-06-30
Content Suite MEDIUM 5.0
CVE-2003-0401

Vignette StoryServer and Vignette V/5 allows remote attackers to obtain sensitive information via a request for the /vgn/style template.

Mitigation only
Fix from $1,600 2003-06-30
Content Suite MEDIUM 5.0
CVE-2003-0402

The default login template (/vgn/login) in Vignette StoryServer 5 and Vignette V/5 generates different responses whether a user exists or not, which …

Patch available
Fix from $1,600 2003-06-30
Content Suite MEDIUM 5.0
CVE-2003-0405

Vignette StoryServer 5 and Vignette V/6 allows remote attackers to execute arbitrary TCL code via (1) an HTTP query or cookie which is processed in t…

Patch available
Fix from $1,600 2003-06-30