Search Results (67788 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2010-2061 1 Rpcbind Project 1 Rpcbind 2024-11-21 7.8 High
rpcbind 0.2.0 does not properly validate (1) /tmp/portmap.xdr and (2) /tmp/rpcbind.xdr, which can be created by an attacker before the daemon is started.
CVE-2010-1678 1 Osgeo 1 Mapserver 2024-11-21 7.5 High
Mapserver 5.2, 5.4 and 5.6 before 5.6.5-2 improperly validates symbol index values during Mapfile parsing.
CVE-2010-1434 1 Joomla 1 Joomla\! 2024-11-21 7.5 High
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to hijack an arbitrary session and gain access to sensitive information, which may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
CVE-2010-1432 1 Joomla 1 Joomla\! 2024-11-21 7.5 High
Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. Joomla! Core versions 1.5.x ranging from 1.5.0 and up to and including 1.5.15 are vulnerable.
CVE-2010-0747 2 Debian, Linbit 2 Debian Linux, Drbd8 2024-11-21 7.8 High
drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.
CVE-2010-0737 1 Redhat 1 Jboss Operations Network 2024-11-21 8.0 High
A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.
CVE-2009-5140 1 Linksys 2 Spa2102, Spa2102 Firmware 2024-11-21 8.8 High
The SIP implementation on the Linksys SPA2102 phone adapter provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.
CVE-2009-5139 1 Google 1 Gizmo5 2024-11-21 7.5 High
The SIP implementation on the Gizmo5 software phone provides hashed credentials in a response to an invalid authentication challenge, which makes it easier for remote attackers to obtain access via a brute-force attack, related to a "SIP Digest Leak" issue.
CVE-2009-5068 1 Simplemachines 1 Simple Machines Forum 2024-11-21 7.2 High
There is a file disclosure vulnerability in SMF (Simple Machines Forum) affecting versions through v2.0.3. On some configurations a SMF deployment is shared by several "co-admins" that are not trusted beyond the SMF deployment. This vulnerability allows them to read arbitrary files on the filesystem and therefore gain new privileges by reading the settings.php with the database passwords.
CVE-2009-5050 1 Konversation 1 Konversation 2024-11-21 7.5 High
konversation before 1.2.3 allows attackers to cause a denial of service.
CVE-2009-5045 2 Debian, Eclipse 2 Debian Linux, Jetty 2024-11-21 7.5 High
Dump Servlet information leak in jetty before 6.1.22.
CVE-2009-5025 1 Pyforum Project 1 Pyforum 2024-11-21 7.5 High
A backdoor (aka BMSA-2009-07) was found in PyForum v1.0.3 where an attacker who knows a valid user email could force a password reset on behalf of that user.
CVE-2009-4123 1 Jruby 1 Jruby-openssl 2024-11-21 7.5 High
The jruby-openssl gem before 0.6 for JRuby mishandles SSL certificate validation.
CVE-2009-4011 1 Dtc-xen Project 1 Dtc-xen 2024-11-21 8.1 High
dtc-xen 0.5.x before 0.5.4 suffers from a race condition where an attacker could potentially get a bash access as xenXX user on the dom0, and then access a potentially reuse an already opened VPS console.
CVE-2009-3723 2 Debian, Sangoma 2 Debian Linux, Asterisk 2024-11-21 7.5 High
asterisk allows calls on prohibited networks
CVE-2009-3721 2 Gnome, Ytnef Project 2 Evolution, Ytnef 2024-11-21 7.8 High
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
CVE-2009-20001 1 Mantisbt 1 Mantisbt 2024-11-21 8.1 High
An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a user's cookie to login as them.
CVE-2008-7314 1 Mirc 1 Mirc 2024-11-21 7.5 High
mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.
CVE-2008-7273 1 Getfiregpg 1 Iceweasel-firegpg 2024-11-21 7.8 High
A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.
CVE-2008-7272 1 Getfiregpg 1 Firegpg 2024-11-21 7.5 High
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.