Total
5279 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2010-2099 | 1 E107 | 1 E107 | 2010-05-27 | 7.5 HIGH | N/A |
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the php bbcode tag, which allows remote attackers to execute arbitrary PHP code, as demonstrated using the toEmail method in contact.php, related to invocations of the toHTML method. | |||||
CVE-2009-4762 | 1 Moinmo | 1 Moinmoin | 2010-05-26 | 7.5 HIGH | N/A |
MoinMoin 1.7.x before 1.7.3 and 1.8.x before 1.8.3 checks parent ACLs in certain inappropriate circumstances during processing of hierarchical ACLs, which allows remote attackers to bypass intended access restrictions by requesting an item, a different vulnerability than CVE-2008-6603. | |||||
CVE-2010-0524 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-05-20 | 7.5 HIGH | N/A |
The default configuration of the FreeRADIUS server in Apple Mac OS X Server before 10.6.3 permits EAP-TLS authenticated connections on the basis of an arbitrary client certificate, which allows remote attackers to obtain network connectivity via a crafted RADIUS Access Request message. | |||||
CVE-2010-0512 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-05-20 | 9.3 HIGH | N/A |
The Accounts Preferences implementation in Apple Mac OS X 10.6 before 10.6.3, when a network account server is used, does not support Login Window access control that is based solely on group membership, which allows attackers to bypass intended access restrictions by entering login credentials. | |||||
CVE-2009-3289 | 1 Gnome | 1 Glib | 2010-05-19 | 4.4 MEDIUM | N/A |
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. | |||||
CVE-2010-1627 | 1 Phpbb | 1 Phpbb | 2010-05-19 | 4.3 MEDIUM | N/A |
feed.php in phpBB 3.0.7 before 3.0.7-PL1 does not properly check permissions for feeds, which allows remote attackers to bypass intended access restrictions via unspecified attack vectors related to permission settings on a private forum. | |||||
CVE-2009-4851 | 1 Xoops | 1 Xoops | 2010-05-12 | 5.0 MEDIUM | N/A |
The activation resend function in the Profiles module in XOOPS before 2.4.1 sends activation codes in response to arbitrary activation requests, which allows remote attackers to bypass administrative approval via a request involving activate.php. | |||||
CVE-2010-0401 | 1 Openttd | 1 Openttd | 2010-05-10 | 6.5 MEDIUM | N/A |
OpenTTD before 1.0.1 accepts a company password for authentication in response to a request for the server password, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (daemon crash) by sending a company password packet. | |||||
CVE-2008-7251 | 1 Phpmyadmin | 1 Phpmyadmin | 2010-05-05 | 10.0 HIGH | N/A |
libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors. | |||||
CVE-2010-1238 | 1 Moinmo | 1 Moinmoin | 2010-04-27 | 5.0 MEDIUM | N/A |
MoinMoin 1.7.1 allows remote attackers to bypass the textcha protection mechanism by modifying the textcha-question and textcha-answer fields to have empty values. | |||||
CVE-2009-4766 | 1 Yasirpro | 1 Ms-pro Portal Scripti | 2010-04-14 | 5.0 MEDIUM | N/A |
YP Portal MS-Pro Surumu (aka MS-Pro Portal Scripti) 1.0 and 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for galeri/database/db.mdb. | |||||
CVE-2009-4765 | 1 Cnr.somee | 1 Hikaye Portal | 2010-04-13 | 5.0 MEDIUM | N/A |
CNR Hikaye Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for db/hikaye.mdb. | |||||
CVE-2007-6735 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-06 | 7.5 HIGH | N/A |
NWFTPD.nlm before 5.08.06 in the FTP server in Novell NetWare does not properly handle partial matches for container names in the FTPREST.TXT file, which allows remote attackers to bypass intended access restrictions via an FTP session. | |||||
CVE-2007-6734 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 4.0 MEDIUM | N/A |
NWFTPD.nlm before 5.08.07 in the FTP server in Novell NetWare 6.5 SP7 does not properly implement the FTPREST.TXT NOREMOTE restriction, which allows remote authenticated users to access directories outside of the home server via unspecified vectors. | |||||
CVE-2004-2767 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 4.3 MEDIUM | N/A |
NWFTPD.nlm before 5.04.25 in the FTP server in Novell NetWare does not promptly close DS sessions, which allows remote attackers to cause a denial of service (connection slot exhaustion) by establishing many FTP sessions that persist for the lifetime of a DS session. | |||||
CVE-2003-1593 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 7.5 HIGH | N/A |
NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection. | |||||
CVE-2003-1594 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 7.5 HIGH | N/A |
NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly enforce FTPREST.TXT settings, which allows remote attackers to bypass intended access restrictions via an FTP session. | |||||
CVE-2003-1595 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 10.0 HIGH | N/A |
NWFTPD.nlm before 5.04.05 in the FTP server in Novell NetWare 6.5 does not properly perform "intruder detection," which has unspecified impact and attack vectors. | |||||
CVE-2000-1245 | 1 Novell | 2 Netware, Netware Ftp Server | 2010-04-05 | 7.5 HIGH | N/A |
Multiple unspecified vulnerabilities in NWFTPD.nlm before 5.01o in the FTP server in Novell NetWare 5.1 SP3 allow remote attackers to bypass intended restrictions on anonymous access via unknown vectors. | |||||
CVE-2010-0057 | 1 Apple | 2 Mac Os X, Mac Os X Server | 2010-03-30 | 7.5 HIGH | N/A |
AFP Server in Apple Mac OS X before 10.6.3 does not prevent guest use of AFP shares when guest access is disabled, which allows remote attackers to bypass intended access restrictions via a mount request. |