Total
5251 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-2402 | 1 Sun | 1 Java Asp Server | 2025-04-09 | 5.0 MEDIUM | N/A |
The Admin Server in Sun Java Active Server Pages (ASP) Server before 4.0.3 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read password hashes and configuration data via direct requests for unspecified documents. | |||||
CVE-2008-3609 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2025-04-09 | 7.2 HIGH | N/A |
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file. | |||||
CVE-2008-6580 | 1 Funscripts | 1 Red Reservations | 2025-04-09 | 5.0 MEDIUM | N/A |
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database via a direct request to (1) makered.mdb and (2) makered97.mdb. | |||||
CVE-2009-4091 | 1 Simplog | 1 Simplog | 2025-04-09 | 5.0 MEDIUM | N/A |
comments.php in Simplog 0.9.3.2, and possibly earlier, does not properly restrict access, which allows remote attackers to edit or delete comments via the (1) edit or (2) del action. | |||||
CVE-2009-3369 | 1 Craig Barratt | 1 Backuppc | 2025-04-09 | 8.5 HIGH | N/A |
CgiUserConfigEdit in BackupPC 3.1.0, when SSH keys and Rsync are in use in a multi-user environment, does not restrict users from the ClientNameAlias function, which allows remote authenticated users to read and write sensitive files by modifying ClientNameAlias to match another system, then initiating a backup or restore. | |||||
CVE-2008-5773 | 1 Nukedit | 1 Nukedit | 2025-04-09 | 5.0 MEDIUM | N/A |
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for database/dbsite.mdb. | |||||
CVE-2008-0293 | 1 Freeseat | 1 Freeseat | 2025-04-09 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in cron.php in FreeSeat before 1.1.5d, when format.php has certain modifications, allows remote attackers to bypass authentication and gain privileges via unspecified vectors related to the show_foot function. | |||||
CVE-2008-2250 | 1 Microsoft | 5 Windows 2000, Windows Server 2003, Windows Server 2008 and 2 more | 2025-04-09 | 7.2 HIGH | N/A |
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 does not properly validate window properties sent from a parent window to a child window during creation of a new window, which allows local users to gain privileges via a crafted application, aka "Windows Kernel Window Creation Vulnerability." | |||||
CVE-2007-5777 | 1 Blue-collar Productions | 1 I-gallery | 2025-04-09 | 5.0 MEDIUM | N/A |
Blue-Collar Productions i-Gallery 3.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing a base64-encoded password via a direct request for igallery.mdb. | |||||
CVE-2007-5945 | 1 Usvn | 1 User-friendly Svn | 2025-04-09 | 5.0 MEDIUM | N/A |
USVN before 0.6.5 allows remote attackers to obtain a list of repository contents via unspecified vectors. | |||||
CVE-2008-6643 | 1 Lokicms | 1 Lokicms | 2025-04-09 | 5.0 MEDIUM | N/A |
LokiCMS 0.3.4 and possibly earlier versions does not properly restrict access to administrative functions, which allows remote attackers to bypass intended restrictions and modify configuration settings via the LokiACTION parameter in a direct request to admin.php. | |||||
CVE-2008-7056 | 1 Grayscalecms | 1 Bandsite Cms | 2025-04-09 | 5.0 MEDIUM | N/A |
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain copies of the database via a direct request. | |||||
CVE-2008-6613 | 1 Abweb | 1 Minimal-ablog | 2025-04-09 | 7.5 HIGH | N/A |
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. | |||||
CVE-2009-0342 | 2 Linux, Provos | 2 Linux Kernel, Systrace | 2025-04-09 | 7.2 HIGH | N/A |
Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall. | |||||
CVE-2008-1475 | 1 Roundup-tracker | 1 Roundup | 2025-04-09 | 6.4 MEDIUM | N/A |
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods. | |||||
CVE-2007-4669 | 1 Firebirdsql | 1 Firebird | 2025-04-09 | 4.0 MEDIUM | N/A |
The Services API in Firebird before 2.0.2 allows remote authenticated users without SYSDBA privileges to read the server log (firebird.log), aka CORE-1148. | |||||
CVE-2008-2936 | 1 Postfix | 1 Postfix | 2025-04-09 | 6.2 MEDIUM | N/A |
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system supports hard links to symlinks, allows local users to append e-mail messages to a file to which a root-owned symlink points, by creating a hard link to this symlink and then sending a message. NOTE: this can be leveraged to gain privileges if there is a symlink to an init script. | |||||
CVE-2007-6470 | 1 Phprpg | 1 Phprpg | 2025-04-09 | 6.4 MEDIUM | N/A |
phpRPG 0.8 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read session ID values in files under tmp/, and then hijack sessions via PHPSESSID cookies. | |||||
CVE-2008-7181 | 1 Butterflymedia | 1 Butterfly Organizer | 2025-04-09 | 7.5 HIGH | N/A |
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter to category-delete.php with the is_js_confirmed parameter set to 1, or (2) delete arbitrary accounts via the mytable parameter to delete.php. | |||||
CVE-2007-4390 | 1 Bluecat Networks | 1 Adonis | 2025-04-09 | 7.2 HIGH | N/A |
The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5.0.2.8 allows local admin users to gain root privileges on the underlying operating system via shell metacharacters in a command. |