Skip to main content

CWE archive

CWE-16 CVEs

Programmatic archive

318 CVEs tagged with CWE-1647 Critical, 77 High, 163 Medium, 31 Low, 0 Unrated.

CVE-2009-1072

Published Mar 25, 2009

nfsd in the Linux kernel before 2.6.28.9 does not drop the CAP_MKNOD capability before handling a user request in a thread, which allows local users to create device nodes, as dem…

CVSS 4.9 · Medium

CVE-2009-0621

Published Feb 26, 2009

Cisco ACE 4710 Application Control Engine Appliance before A1(8a) uses default (1) usernames and (2) passwords for (a) the administrator, (b) web management, and (c) device manage…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0507

Published Feb 26, 2009

IBM WebSphere Process Server (WPS) 6.1.2 before 6.1.2.3 and 6.2 before 6.2.0.1 does not properly restrict configuration data during an export of the cluster configuration file fro…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0641

Published Feb 20, 2009

sys_term.c in telnetd in FreeBSD 7.0-RELEASE and other 7.x versions deletes dangerous environment variables with a method that was valid only in older FreeBSD distributions, which…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-6171

Published Feb 19, 2009

includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arb…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-0432

Published Feb 10, 2009

The installation process for the File Transfer servlet in the System Management/Repository component in IBM WebSphere Application Server (WAS) 6.1.x before 6.1.0.19 does not enabl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0489

Published Feb 9, 2009

The DBus configuration file for Wicd before 1.5.9 allows arbitrary users to own org.wicd.daemon, which allows local users to receive messages that were intended for the Wicd daemo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2009-0399

Published Feb 3, 2009

Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.php. NOTE: this is only a vulnerability when the administra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1566

Published Jan 15, 2009

Microsoft Internet Information Services (IIS) 5.0 does not log requests that use the TRACK method, which allows remote attackers to obtain sensitive information without detection.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5844

Published Jan 5, 2009

PHP 5.2.7 contains an incorrect change to the FILTER_UNSAFE_RAW functionality, and unintentionally disables magic_quotes_gpc regardless of the actual magic_quotes_gpc setting, whi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5827

Published Jan 2, 2009

The Nokia 6131 Near Field Communication (NFC) phone with 05.12 firmware automatically installs software upon completing the download of a JAR file, which makes it easier for remot…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-5710

Published Dec 24, 2008

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers to read (1) configuration fil…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4311

Published Dec 10, 2008

The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restri…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5277

Published Dec 9, 2008

PowerDNS before 2.9.21.2 allows remote attackers to cause a denial of service (daemon crash) via a CH HINFO query.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5109

Published Nov 25, 2008

The default configuration of Adobe Flash Media Server (FMS) 3.0 does not enable SWF Verification for (1) RTMPE and (2) RTMPTE sessions, which makes it easier for remote attackers…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4212

Published Oct 10, 2008

Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which migh…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-3519

Published Sep 23, 2008

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a pro…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4126

Published Sep 18, 2008

PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4100

Published Sep 18, 2008

GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different v…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-4099

Published Sep 18, 2008

PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3459

Published Aug 4, 2008

Unspecified vulnerability in OpenVPN 2.1-beta14 through 2.1-rc8, when running on non-Windows systems, allows remote servers to execute arbitrary commands via crafted (1) lladdr an…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2008-1662

Published Aug 1, 2008

Unspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote attackers to read or modify ar…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 318 CVEsPage 9 of 13