Vulnerabilities (CVE)

Filtered by CWE-264
Total 5466 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-4435 1 Pivotal 1 Bosh Stemcell 2017-10-02 6.8 MEDIUM 9.0 CRITICAL
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
CVE-2016-5853 1 Google 1 Android 2017-09-29 7.6 HIGH 7.0 HIGH
In an audio driver in all Qualcomm products with Android releases from CAF using the Linux kernel, when a sanity check encounters a length value not in the correct range, an error message is printed, but code execution continues in the same way as for a correct length value.
CVE-2015-7875 1 Chaos Tool Suite Project 1 Ctools 2017-09-29 5.0 MEDIUM 7.5 HIGH
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.
CVE-2009-2080 1 Mrcgiguy 1 The Ticket System 2017-09-29 7.5 HIGH N/A
admin.php in MRCGIGUY The Ticket System 2.0 does not properly restrict access, which allows remote attackers to (1) obtain sensitive configuration information via the editconfig action or (2) change the administrator's password via the id parameter in an editop action.
CVE-2009-2025 1 Dutchmonkey 1 Dm Filemanager 2017-09-29 7.5 HIGH N/A
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values.
CVE-2009-2024 1 Vt.rovno 1 Asp Vt Auth 2017-09-29 5.0 MEDIUM N/A
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain usernames and passwords via a direct request for zHk8dEes3.txt.
CVE-2009-2022 1 Fipsasp 1 Fipscms Light 2017-09-29 5.0 MEDIUM N/A
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file and obtain sensitive information via a direct request for _fipsdb/db.mdb.
CVE-2009-1941 1 Phpeasycode 1 Pad Site Scripts 2017-09-29 5.0 MEDIUM N/A
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which allows remote attackers to download the database and obtain sensitive information via a direct request for dbbackup.txt.
CVE-2009-1883 1 Linux 1 Linux Kernel 2017-09-29 4.4 MEDIUM N/A
The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage.
CVE-2009-1863 1 Adobe 3 Air, Flash Player, Flex 2017-09-29 9.3 HIGH N/A
Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability."
CVE-2009-1840 1 Mozilla 3 Firefox, Seamonkey, Thunderbird 2017-09-29 9.3 HIGH N/A
Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.
CVE-2009-1839 1 Mozilla 1 Firefox 2017-09-29 5.4 MEDIUM N/A
Mozilla Firefox 3 before 3.0.11 associates an incorrect principal with a file: URL loaded through the location bar, which allows user-assisted remote attackers to bypass intended access restrictions and read files via a crafted HTML document, aka a "file-URL-to-file-URL scripting" attack.
CVE-2009-1821 1 Dmxready 1 Registration Manager 2017-09-29 5.0 MEDIUM N/A
DMXReady Registration Manager 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for databases/webblogmanager.mdb.
CVE-2009-1771 1 Flyspeck 1 Flyspeck Cms 2017-09-29 7.5 HIGH N/A
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which allows remote attackers to create or modify admin accounts via the (1) users[fullname], (2) users[email], (3) users[role_id], (4) users[username], and (5) users[password] parameters.
CVE-2009-1767 1 2daybiz 1 Template Monster Clone 2017-09-29 5.0 MEDIUM N/A
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote attackers to modify arbitrary accounts via the (1) loginname, (2) password, (3) email, (4) firstname, or (5) lastname parameter.
CVE-2009-1752 1 Exjune 1 Office Message System 2017-09-29 7.5 HIGH N/A
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which allows remote attackers to gain privileges a direct request. NOTE: some of these details are obtained from third party information.
CVE-2009-1665 1 Easy-scripts 1 Answer And Question Script 2017-09-29 6.4 MEDIUM N/A
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a modified userid parameter without specifying any additional fields.
CVE-2009-1652 1 2daybiz 1 Business Community Script 2017-09-29 7.5 HIGH N/A
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request.
CVE-2009-1637 1 Simplecustomer 1 Simple Customer 2017-09-29 6.4 MEDIUM N/A
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters.
CVE-2009-1610 1 Jobscript 1 Job Script Job Board Software 2017-09-29 7.5 HIGH N/A
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator password and gain administrator privileges via a direct request.